HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID
The recent update to HP OneAgent has led to the disconnection of Windows devices from Microsoft Entra ID, preventing users from accessing their corporate identities.
The recent update to HP OneAgent has led to the disconnection of Windows devices from Microsoft Entra ID, preventing users from accessing their corporate identities.
Version 1.2.50.9581 of the agent was silently deployed to HP’s Next Gen AI systems, such as the EliteBook X Flip G1i. This update inadvertently deleted critical certificates, causing devices to lose their Entra join status.
The issue was identified as stemming from HP's OneAgent, a tool used for telemetry and device management. It registers devices with HP's AWS IoT Core for automated updates. The affected systems received the update automatically, while non-AI HP models with older versions were not impacted.
The update included the SoftPaq SP161710 package, which executed an install.cmd script designed to remove the obsolete HP 1E Performance Assist component. However, the PowerShell logic within the script mistakenly targeted certificates related to Entra ID, specifically affecting the MS-Organization-Access certificate and, in some cases, the Microsoft Intune MDM Device CA certificate.
Version 1.2.50.9581 of the agent was silently deployed to HP’s Next Gen AI systems, such as the EliteBook X Flip G1i.
The issue was traced back to a "job-hponeagent-update" command from HP's AWS IoT backend, which executed the package without sufficient testing. This led to unintended certificate deletions, isolating devices from their Azure ecosystem.
HP has withdrawn the problematic SoftPaq to prevent further distribution. Administrators need to manually repair affected devices. This involves logging in locally via LAPS, executing a cleanup script to remove stale registry keys, and reconnecting to Entra ID through the settings. For remote resolution, Microsoft Defender for Endpoint's Live Response can be used to upload a PowerShell script for device reset, provided WinRE is enabled.
Organizations are advised to audit HP agents and implement stricter update controls to avoid similar occurrences. While Microsoft Intune may recover some MDM certificates, a full rejoin is necessary for MS-Organization-Access recovery.
Based on reporting by Cyber Security News.
