This issue has been resolved since Deaddrop version 3.2, released on 2023-02-05. This post is kept for historical reasons.

Background

This is an article that describes a recent Deaddrop authentication issue with Intune-managed computers. In this article we describe the issue, we describe some workarounds and we describe our path forward with a new solution.

As more and more organisations start to manage their computers with Microsoft Intune, we have found out that there are some Sysctl customers that have problems with Deaddrop when they in turn have users that connect from computers that are managed with Microsoft Intune. In such organisations and computer environments, Windows clients that use Edge or Chrome may receive policy settings centrally that disable authentication methods, which are authentication methods used by Deaddrop. The result of this is that the user cannot authenticate against Deaddrop and instead receives a message that the password is incorrect. In reality, the actual result is that the password is never sent at all, since the client is disallowed to use basic auth by a central configuration setting.

The issue is amplified by the fact that this is a client issue, in the configuration of the web browser itself, and the client is often centrally managed by some IT staff on work computers. Hence there are few changes that an end-user can do.

Finding if this is an issue

If a user has connectivity issues when trying to reach Deaddrop, to see if this Intune configuration issue is the root cause, this can be verified by viewing the relevant Windows registry keys:

In the HKLM/HKCU hive, please verify the settings of the following two registry keys:

  • Software\Policies\Google\Chrome\AuthSchemes
  • Software\Policies\Microsoft\Edge\AuthSchemes

If the authscheme lacks the word “basic”, the browser will not work. If the authscheme contains “basic” but there are still problems reaching Deaddrop, there are most probably other issues like proxy settings or firewall issues.

Workaround

We describe three workarounds in this chapter:

  1. A quick workaround is to test another browser than Edge or Chrome, e.g. Firefox
  2. Another workaround is to test on a platform that is not centrally managed with Intune the same way, e.g. on a PDA or a smart phone
  3. A better workaround is to add the basic authentication to the registry keys. This can be performed by an administrator or by updating a GPO

Solution

Sysctl is currently working to get a more permanent solution in place which is not dependent on the “basic auth” authentication scheme. We have evaluated multiple different technical solutions that can resolve this issue, and have decided to go with one of these solutions. After performing some internal testing, a new version of Deaddrop that resolves this problem will be released to all customers with support contracts.

References

More background information on the changes to the security baseline can be found in this Microsoft description of Intune. More details related to the Microsoft Edge policies can be found in this Microsoft description of Microsoft Edge policies.

Contact

Contact us at Sysctl if you have any questions related to this issue or if you are in need of support.

Contact us at Sysctl if you are interested in knowing more on how Deaddrop can be used to help you protect your file transfers.