MDM Hybrid AD - PRT

karthik palani 1,016 Reputation points
2022-09-29T12:01:47.747+00:00

Hi All,

We are trying to enroll machines in to Intune using auto enrollment. The devices are Hybrid but for some reason the PRT status is No which is blocking the enrollment to Intune. Below is the event, please advice

Error: 0xCAA90056 Renew token by the primary refresh token failed.
Logged at RefreshTokenRequest.cpp, line: 150, method: RefreshTokenRequest::AcquireToken.

Request: authority: https://login.microsoftonline.com/d7b73558-73e6-4d99-aea1-2240e5bd1c65, client: ab9b8c07-8f02-4f72-87fa-80105867a763, redirect URI: ms-appx-web://Microsoft.AAD.BrokerPlugin/ab9b8c07-8f02-4f72-87fa-80105867a763, resource: , correlation ID (request): e55ff6cd-4717-4d5a-b459-7f0e320b7c60

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,473 questions
{count} votes

2 answers

Sort by: Most helpful
  1. JimmySalian-2011 41,916 Reputation points
    2022-09-29T12:10:16.303+00:00

    Hi Karthik,

    Do you have MFA enabled on the environment and to understand the issue a complete log will be required and also the setup of the environment, meanwhile please go through this detailed workflow and config of how PRT token works in the background.

    concept-primary-refresh-token

    Hope this helps.

    ---
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

  2. Akshay-MSFT 16,026 Reputation points Microsoft Employee
    2022-10-10T12:15:15.037+00:00

    Hello @karthik palani ,

    Kindly try the following:

    Start fiddler trace

    Launch CMD and run "dsregcmd /join"

    A window with AAD credentials should pop up, try to signin with impacted user/aad/EMS license holding account.

    See if the join completes, if yes. Then capture fiddler while running the enrollment task manually.

    • On comparing the two fiddler you should be able to confirm what endpoint is not reachable during autoenrollment.

    Thanks,
    Akshay Kaushik

    Please "Accept the answer" and "Upvote" if the above-mentioned suggestion works as per your business need. This will help us and others in the community as well. https://learn.microsoft.com/en-us/answers/support/accepted-answers