Intune enrollment via GPO

srinivas Pasupuleti100 60 Reputation points
2024-07-24T16:01:13.92+00:00

Hello,

We have Entra hybrid joined devices and i tried to enroll devices into intune via GPO,it is assigned to the OU in AD.It was successfully applied to users.It is enable for auto enrollment type is user credential.

User has intune license and Microsoft 365 business basic license.And my organization tenant has Entra ID p2 license.IS user require Entra ID p2 license or tenant Entra ID p2 license is enough.

And In Intune Automatic enrollment set to All

In task scheduler-->microsoft-->windows->Enterprisemgmt -->showing as above screenshot.It showing access denied.User's image

In Event viewer -->application logs-->microsoft-->windows->Task scheduler->operational-->it shows as error below screenshot

User's image

User's image

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal 10,911 Reputation points
    2024-07-24T16:18:57.5866667+00:00

    Is the device successfully hybrid joined? Any CA policy implemented requiring MFA in the background? Have you checked the user sign-in logs in Entra ID?


  2. Rahul Jindal 10,911 Reputation points
    2024-07-24T16:41:47.82+00:00

    That explains a lot. Did you delete the Intune enrolment for the device object showing as Entra registered first?


  3. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2024-07-25T01:34:30.59+00:00

    @srinivas Pasupuleti100, Thanks for posting in Q&A. From your description, I know the two affected users are with Microsoft Intune and Microsoft 365 business basic license. Based on my checking Microsoft 365 business basic doesn't include Microsoft Entra Premium license.

    https://learn.microsoft.com/en-us/entra/fundamentals/licensing#entra-licensing-options

    For GPO enrollment, auto-enrollment is needed to be enabled

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-enrollment/troubleshoot-windows-auto-enrollment#verify-the-configuration

    To enable auto-enrollment, Microsoft Entra ID P1 or P2 is needed.

    https://learn.microsoft.com/en-us/mem/intune/enrollment/quickstart-setup-auto-enrollment

    For the affected users, it misses this license. Then it can cause failure. Please assign the license to see if it can be working.

    Please try the above suggestion and if there's any update, feel free to let us know,


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.