Conditional access blocking\interfering with device enrollment? Should be logged in Entra sign-in logs.
Intune enrollment via GPO
Hello,I tried to enroll entra hybid joined devices to intune via GPO .user has intune license.Configured GPO correctly it was applied to the device.but enrollment not successfull.Please find the event viewer logs attached.any answer should be appreciated.
2 answers
Sort by: Most helpful
-
Rahul Jindal [MVP] 10,196 Reputation points MVP
2024-07-22T16:28:43.6133333+00:00 -
ZhoumingDuan-MSFT 13,735 Reputation points Microsoft Vendor
2024-07-23T05:33:34.5333333+00:00 @srinivas Pasupuleti100, Thanks for posting in Q&A.
From your description, I know you want to do hybrid AAD join but failed.
To clarify this issue, please check the following.
1.Could you share us what kind of credential have you configure? Device credential or User credential?
2.Check if there exist CA policies that may block enrollment.
3.Check the task under Task schedule.
4.Check on-premise UPN to whether match the Azure AD UPN so they can login with the correct credentials.
5.Run dsregcmd/status in cmd to check whether it shows device joined to azure ad joined,domain joined.
And here is a link with the similar issue you can refer.
https://www.reddit.com/r/Intune/comments/le1tqd/auto_mdm_enroll_device_credential_failed_error/
Please try above information, if there is any update, feel free to let me know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.