Intune Enrollment with Azure Hybrid AD not funtioning.

Eric Elkmann 1 Reputation point
2020-08-03T19:17:11.977+00:00

I am attempting to do some testing with Intune but so far have not even been able to get a single device to enroll properly.

I have followed the steps below to automatically enroll all Azure AD devices with Intune MDM but that does not seem to be happening.

https://learn.microsoft.com/en-us/microsoft-365/business/manage-windows-devices?view=o365-worldwide

The devices show up in Azure Active Directory admin center under Devices with a status of Hybrid Azure AD joined but the MDM status as None.

I cannot for the life of me figure out why it is not getting the MDM properly.

  • MDM scope is set to All
  • Users have Intune license applied
  • The GPO has been setup for automatic MDM enrollment
  • The device shows up under the user in Microsoft Endpoint Manager Admin center

What am I missing?

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,374 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,113 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. CiciWu-MSFT 1,206 Reputation points
    2020-08-04T02:16:48.18+00:00

    Please double confirm if the following requirements have met:

    • AD-joined PC running Windows 10, version 1709 or later
    • The enterprise has configured a mobile device management (MDM) service
    • The enterprise AD must be registered with Azure Active Directory (Azure AD)
    • The device should not already be enrolled in Intune using the classic agents (devices managed using agents will fail enrollment with error 0x80180026)
    • The minimum Windows Server version requirement is based on the Hybrid AAD join requirement. See How to plan your hybrid Azure Active Directory join implementation for more information.

    Also, how about using group policy to enroll hybrid AD joined device? It is recommended by Intune. Here is the steps:
    https://learn.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy

    If the methods still doesn’t help, investigate the log file if you have issues even after performing all the mandatory verification steps to see if there is any error message.
    https://learn.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#troubleshoot-auto-enrollment-of-devices

    0 comments No comments

  2. VipulSparsh-MSFT 16,271 Reputation points Microsoft Employee
    2020-08-04T08:56:53.67+00:00

    @Eric Elkmann I was recently engaged in an investigation around a similar scenario. If you confirm that the device is getting Hybrid AAD join and not just Intune enrolled, you need to start looking here first in order to track down, whats happening :

    Check for these event logs :

    15531-event-logs.jpg

    Check for any Auto Enroll failure logs and share those.
    Also share the output for dsregcmd /status from that machine.
    15502-dsregcmd.jpg

    If required we can take a look at that machine to figure out what is happening if the above two things dont help much. Let us know if you have any questions.

    -----------------------------------------------------------------------------------------------------------------

    If the suggested response helped you resolve your issue, do click on "Mark as Answer" and "Up-Vote" for the answer that helped you for benefit of the community.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.