Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Microsoft Family Safety App #3277

Open
Dynamic5912 opened this issue Jul 25, 2024 · 19 comments
Open

Microsoft Family Safety App #3277

Dynamic5912 opened this issue Jul 25, 2024 · 19 comments
Assignees
Labels
question Further information is requested waiting for feedback Feedback is missing

Comments

@Dynamic5912
Copy link

Currently, Microsoft Family Safety app reports zero usage for Windows and Xbox devices that are linked to the parental account despite being in use - this doesn't prevent devices from working or going beyond their allocated daily time limits - but it does affect reporting to the app and occasional affects requests for time extensions from apps/devices.

My understanding and from Reddit is that allowing *. events.data.microsoft.com fixes this - but I don't want to allow all subdomains through - just the ones required for Family Safety.

Do you (or the community) know which domains are required for the app to function and report usage correctly?

I've looked online and on Microsofts forums/help pages and they say to allow the domain and all subdomains as a whole for "all Microsoft services to function correctly".

@Dynamic5912 Dynamic5912 added the question Further information is requested label Jul 25, 2024
@hagezi hagezi added the help wanted Extra attention is needed label Jul 25, 2024
@hagezi
Copy link
Owner

hagezi commented Jul 25, 2024

I don't know anyone who uses it and I don't know which telemetry domains Microsoft “misuses” for it. If it really is the telemetry events, my guess is:

mobile.events.data.microsoft.com

Depending on the region:

au-mobile.events.data.microsoft.com
eu-mobile.events.data.microsoft.com
in-mobile.events.data.microsoft.com
jp-mobile.events.data.microsoft.com
uk-mobile.events.data.microsoft.com
us-mobile.events.data.microsoft.com

These are used by almost everything that “smells” of Microsoft.

Which list version are you using?
Which event domains are blocked according to your log?
Have you unblocked *.events.data.microsoft.com to see if this is the cause?

@hagezi
Copy link
Owner

hagezi commented Jul 25, 2024

I can also think of the following:

vortex.data.microsoft.com - This subdomain is often used for collecting telemetry data and is probably also relevant for Microsoft Family Safety.

self.events.data.microsoft.com - This subdomain is specifically for collecting telemetry data and events triggered by user actions or system operations, which may also be important for tracking activity in Microsoft Family Safety.
Only blocked in Ultimate.

@hagezi hagezi added the waiting for feedback Feedback is missing label Jul 25, 2024
@Dynamic5912
Copy link
Author

Dynamic5912 commented Jul 25, 2024

Thanks for the hints.

I'm using the Ultimate List.

For now, i have whitelisted the domain in AGH as follows: @@||events.data.microsoft.com^

And will see if this yields any results then try to figure out which domains are being used.

Kids are on downtime this evening but they should be on their devices tomorrow so I can see what happens :)

@hagezi
Copy link
Owner

hagezi commented Jul 25, 2024

For Ultimate, I would unblock self.events.data.microsoft.com and see if that is enough.

@Dynamic5912
Copy link
Author

self.events.data.microsoft.com

OK. Will change my custom filter to that domain and see if it works tomorrow.

Will update as I know more...

@Dynamic5912
Copy link
Author

OK, so..

Allowing self.events.data.microsoft.com made no difference - no time used etc. was being reported to the Family Safety App.

So I whitelisted events.data.microsoft.com to allow all subdomains and within a couple of minutes, the app updated with usage time for the kids laptops as well as time spent in individual apps (previously this all said "not used today").

Now begins the game of figuring out which subdomain of events.data.microsoft.com is required for Family Safety to work - I'll need to trawl through the logs for the evening and see which whitelisted subdomains were used then take it step-by-step I guess..

@Dynamic5912
Copy link
Author

Dynamic5912 commented Jul 26, 2024

It might be functional.events.data.microsoft.com not 100% sure..

I have other Windows machines in the household and only the kids laptops are calling this subdomain when in use..

@Dynamic5912
Copy link
Author

It's not functional.events.data.microsoft.com so back to searching again.

I've whitelisted events.data.microsoft.com as a whole again so will see what crops up and if it starts working...

@hagezi
Copy link
Owner

hagezi commented Aug 1, 2024

@Dynamic5912 Anything new here?

@Dynamic5912
Copy link
Author

Still testing - whitelisting events.data.microsoft.com seems to work sporadically.

Disabling blocking/filtering altogether in AGH makes it work as it should - so something else is required to be whitelisted as well it seems.

I think it might be activity.windows.com but need to do more testing.

@xRuffKez
Copy link
Contributor

xRuffKez commented Aug 7, 2024

@Dynamic5912 new results?

@Dynamic5912
Copy link
Author

Been on holiday 😀

Will check again over the next few days

@paddyofurniture
Copy link

Wondering if there's been progress on this?

Also, where are you whitelisting? Windows Firewall, router, or..?

@hagezi
Copy link
Owner

hagezi commented Oct 18, 2024

@Dynamic5912 Is there anything new or can I close here?

@hagezi
Copy link
Owner

hagezi commented Oct 22, 2024

@Dynamic5912 If the problem still exists, or if you know what you need to unblock, just contact here in the topic again. I'll close it for now.

@hagezi hagezi closed this as completed Oct 22, 2024
@hagezi hagezi removed the help wanted Extra attention is needed label Oct 22, 2024
@Dynamic5912
Copy link
Author

Hey - sorry been busy with work and stuff so not gotten around to re-testing this again.

Will update the post again if there's any update.

@Dynamic5912
Copy link
Author

Revisiting this..

Allowing:

@@||events.data.microsoft.com

Lets reporting work again.

However, there are quite a few subdomains that get allows through with this filter, so it's now a case of narrowing down which one/s are required:

  • v10.events.data.microsoft.com
  • v20.events.data.microsoft.com
  • browser.events.data.microsoft.com
  • teams.events.data.microsoft.com
  • self.events.data.microsoft.com
  • mobile.events.data.microsoft.com
  • watson.events.data.microsoft.com
  • functional.events.data.microsoft.com

@hagezi hagezi reopened this Jan 29, 2025
@tschai-yim
Copy link

Hi, this isn't related to the same app but the same domains. Blocking the following domains completely breaks SSO sign-in for Microsoft apps on Android:

  • eu-mobile.events.data.microsoft.com
  • mobile.events.data.microsoft.com

I've tried Teams and Outlook with two different organizations, both of which use Microsoft AD SSO. My guess is, this probably also is the case in other regions listed here: #3277 (comment)

PS: concretely, it'll ask for the password but then show a network error after a while or after clicking "login".

@hagezi
Copy link
Owner

hagezi commented Feb 7, 2025

@tschai-yim #5118

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested waiting for feedback Feedback is missing
Projects
None yet
Development

No branches or pull requests

5 participants