【トラブルシューティング】SafetyNet のポリシーが適用されているユーザーで、企業のリソースへのアクセスが行えなくなる可能性のある SI(サービス インシデント)が発生【IT291049】【復旧済み】
- 2021/10/13
Microsoft が提供する Microsoft 365 のサービス正常性サービス正常性(IT291049)にて、SafetyNet のポリシーが適用されているユーザーでコンプラインス上の問題が発生し、企業のリソースへのアクセスが行えなくなる可能性のある SI(サービス インシデント)が発生していることを発表しています。
この問題は、Android Enterprise Dedicated、Android Enterprise Fully – Managed、Android Enterprise Fully – Corporate Owned with a Work Profile のユーザーに影響しているとのことです。
現在は、デバイスがサービスにチェック インするとアップデートが行われますが、手動で強制的にアップデートを行うこともできます。
既に影響を受けたデバイスの 99 % 異常が復旧したことを確認しているとのことです。
今後は、3 rd Party パートナーと協力して、今後のアップデートで同様の問題が発生しないようにする方法を検討するとのことです。
※ この問題は最近の 3 rd Party 製サービスのアップデートによって、SafetyNet が適用されたポリシーを持つユーザーのデバイスにコンプライアンス違反として認証違反の扱いとなり、企業リソースへのアクセスが行えなくなる問題となります。
なお、Android Enterprise Dedicated、Android Enterprise Fully – Managed、Android Enterprise Fully – Corporate Owned with a Work Profile の基準を満たしている一部の Android MDM デバイスにて SafetyNet の認証に失敗するユーザーにて発生しているとのことです。
Microsoft Intune 関連記事一覧
Microsoft Intune のメッセージ センター関連情報一覧
Microsoft Intune の SI(サービス インシデント)関連情報一覧
Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources. – IT291049
サービス:Microsoft Intune
状態:Service restored
ユーザーへの影響:Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
Microsoft 365 のサービス正常性(IT291049)にて、SafetyNet のポリシーが適用されているユーザーでコンプラインス上の問題が発生し、企業のリソースへのアクセスが行えなくなる可能性のある SI(サービス インシデント)が発生していることを発表しています。
この問題は、Android Enterprise Dedicated、Android Enterprise Fully – Managed、Android Enterprise Fully – Corporate Owned with a Work Profile のユーザーに影響しているとのことです。
現在は、デバイスがサービスにチェック インするとアップデートが行われますが、手動で強制的にアップデートを行うこともできます。
既に影響を受けたデバイスの 99 % 異常が復旧したことを確認しているとのことです。
今後は、3 rd Party パートナーと協力して、今後のアップデートで同様の問題が発生しないようにする方法を検討するとのことです。
※ この問題は最近の 3 rd Party 製サービスのアップデートによって、SafetyNet が適用されたポリシーを持つユーザーのデバイスにコンプライアンス違反として認証違反の扱いとなり、企業リソースへのアクセスが行えなくなる問題となります。
なお、Android Enterprise Dedicated、Android Enterprise Fully – Managed、Android Enterprise Fully – Corporate Owned with a Work Profile の基準を満たしている一部の Android MDM デバイスにて SafetyNet の認証に失敗するユーザーにて発生しているとのことです。
October 14, 2021 8:56 AM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User Impact : Users with SafetyNet enforced policies may have experienced compliance failures and lost access to corporate resources.
- ・More info : This issue affected Android Enterprise Dedicated, Android Enterprise Fully-Managed, or Corporate Owned with a Work Profile user.
- Devices were updated once they checked into the service.
- To manually force the update, a manual sync could have been triggered by going to Settings (Settings > Privacy > Your Work Policy info > Top menu > Sync policies).
- ・Final status : We’ve confirmed that over 99 percent of the affected devices have recovered and the issue is now mitigated.
- ・Scope of impact : Impact was specific to some Android MDM devices that met the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Start time: Thursday, October 14, 2021, 1:50 AM (10/13/2021, 4:50 PM UTC)
- ・End time : Thursday, October 14, 2021, 8:30 AM (10/13/2021, 11:30 PM UTC)
- ・Root cause : A recent third-party partner update was causing users with SafetyNet enforced policies to experience compliance failures and lose access to corporate resources.
- Next steps :
- – We’re working with our third-party partner to determine ways to prevent future updates from resulting in similar impact.
- This is the final update for the event.
October 14, 2021 3:16 AM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User Impact : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・More info : This issue affects Android Enterprise Dedicated, Android Enterprise Fully-Managed, or Corporate Owned with a Work Profile user.
- Devices are updated once they check into the service.
- To manually force the update, a manual sync can be triggered by going to Settings (Settings > Privacy > Your Work Policy info > Top menu > Sync policies).
- ・Current status : We’re continuing to monitor a small group of devices that remain affected following our third-party partner’s update reversion.
- We’re expecting for the remainder of impacted devices to see the remediation of impact by our next scheduled update, and if not, we’ll reassess our estimate for the process completing and the remediation of impact.
- ・Scope of impact : Impact is specific to some Android MDM devices that meet the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Start time : Thursday, October 14, 2021, 1:18 AM (10/13/2021, 4:18 PM UTC)
- ・Root cause : A recent third-party partner update is causing users with SafetyNet enforced policies to experience compliance failures and lose access to corporate resources.
- ・Next update by : Thursday, October 14, 2021, 10:30 AM (1:30 AM UTC)
October 13, 2021 11:00 PM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User Impact : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・More info : This issue affects Android Enterprise Dedicated, Android Enterprise Fully-Managed or Corporate Owned with a Work Profile users.
- Devices are updated once they check into the service. To manually force the update, a manual sync can be triggered by going to Settings (Settings > Privacy > Your Work Policy info > Top menu > Sync policies).
- ・Current status : Our third party partner has confirmed that impact is caused by a recent update.
- They’ve completed a roll back of the update and we have had confirmation that impact has been resolved on the majority of affected devices.
- We’re monitoring the remainder of devices until impact has been successfully mitigated.
- ・Scope of impact : Impact is specific to some Android MDM devices that meet the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Next update by : Thursday, October 14, 2021, 4:30 AM (10/13/2021, 7:30 PM UTC)
October 13, 2021 12:28 PM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User Impact : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・More info : This issue affects Android Enterprise Dedicated, Android Enterprise Fully-Managed or Corporate Owned with a Work Profile users.
- ・Current status : Our third party partner, has identified a potential issue with a recent update and are in the process of releasing a fix.
- We are actively collaborating to remediate the issue.
- ・Scope of impact : Impact is specific to some Android MDM devices that meet the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Next update by : Thursday, October 14, 2021, 12:00 AM (10/13/2021, 3:00 PM UTC)
October 13, 2021 9:37 AM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User impact : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・More info : This issue affects Android Enterprise Dedicated, Android Enterprise Fully-Managed or Corporate Owned with a Work Profile users.
- ・Current status : Our third party partner has confirmed that they are able to reproduce the issue.
- We’re actively collaborating to troubleshoot and remediate the impact.
- ・Scope of impact : Impact is specific to some Android MDM devices that meet the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Next update by : Wednesday, October 13, 2021, 2:00 PM (5:00 AM UTC)
October 13, 2021 7:53 AM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User impact: Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・More info : This issue affects Android Enterprise Dedicated, Android Enterprise Fully-Managed or Corporate Owned with a Work Profile users.
- ・Current status : We’re continuing our review of available diagnostic data and third party API logging to isolate the source of impact.
- Additionally, we’re working to gather additional reproduction data from our third party to assist in our investigation.
- ・Scope of impact : Impact is specific to some Android MDM devices that meet the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Next update by : Wednesday, October 13, 2021, 11:00 AM (2:00 AM UTC)
October 13, 2021 6:59 AM – Service restored
- ・Title : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・User impact : Users with SafetyNet enforced policies may experience compliance failures and lose access to corporate resources.
- ・More info : This issue affects Android Enterprise Dedicated, Android Enterprise Fully-Managed or Corporate Owned with a Work Profile users.
- ・Current status : We’re reviewing available diagnostic data and third party API logging to isolate the source of impact and identify mitigations actions.
- ・Scope of impact: Impact is specific to some Android MDM devices that meet the criteria outlined in the More info section that fail the SafetyNet attestation check.
- ・Next update by : Wednesday, October 13, 2021, 8:00 AM (10/12/2021, 11:00 PM UTC)
関連リンク
- ・クラウド コンピューティング サービス|Microsoft Azure:https://azure.microsoft.com/ja-jp/
- ・日本マイクロソフト – Official Home Page:https://www.microsoft.com/ja-jp