Automatic MDM Enrollment - Windows 10 Clients - Scenario

Veera Ragavan 51 Reputation points
2022-02-24T12:48:36.17+00:00

Hello Techie's,

Here is the Scenario, I Would like to take help

I have 3 Different Forest/Domain's

Domain 1 - ABC.COM
Domain 2 - XYZ.COM
Domain 3 - 123.COM

Domain 1 - ABC.COM - We have the Azure AD Connect, and Installed with MECM - With Co Management. All Management via Intune
Domain 1 - Azure AD Connect which Collect the Details of AD - All 3 Domains (Domain 1, 2 and 3)

Now, We want Domain 2 and Domain 3 has to be Controlled via Intune
So we have done the following..

XYZ.COM - Users are Assigned with Azure AD P1, Microsoft Intune Licenses
XYZ.COM - Users are Available in the Azure AD, Azure Portal
XYZ.COM - Devices are Available in the Azure AD, Azure Portal
XYZ.COM - Created the GPO, and Assigned the MDM Profile for Enrollment - User Credential

177457-image.png

Out Put, Event ID : 76 - Auto MDM Enroll: Device Credential (0x0), Failed (Unknown Win32 Error code: 0x8018002b)
177458-image.png

We cannot see the MDM URL, MDMTOUURL, MDM Compliance URL while running the DSREGCMD /Status
177516-image.png

From the Intune Side, We do not have any Restrictions. Enrollment

177497-image.png

Also no Restrictions with Device Type - As well.. Devices are Targeted to this Group

177498-image.png

Question:

  1. Is it Really Possible to Manage the Domain 2 (XYZ) Clients via Intune? which the Tenant belongs to Domain 1 (ABC)

Now the Current Status is Device is showing as Hybrid Azure AD Joined, along with Registered and Activity time

177517-image.png

Any Steps from your suggestion, Expertise can help... We need to Manage the Domain 2, Domain 3 Devices has to be Manage via Intune is the Goal

Little more Update from my side

I have mentioned the Domain Name as

XYZ.COM and it is more likely as XYZ.Local

Its Local Domain, and not registered/Purchased any where. Can you refer some link to register this Domain.

In late time, I Found that this Domains are not Registered yet with Azure Portal

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} votes

3 answers

Sort by: Most helpful
  1. ESWARARAJU KONETI 2,206 Reputation points MVP Volunteer Moderator
    2022-02-24T14:35:06.357+00:00

    is xyz and 123 domains are routable? check this Microsoft document for more information https://learn.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors#auto-mdm-enroll-failed

    Thanks,
    Eswar
    www.eskonr.com


  2. Rahul J 76 Reputation points
    2022-03-01T07:12:49.883+00:00

    Syncing multiple domains/forests using single Azure AD connect is going to be tricky. I hope you might have already checked https://learn.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies to confirm your scenario is supported even though it's syncing devices as well as users to Azure AD.

    Also, MDM Enrollment GP - User authentication can be tricky sometimes - I know Anoop reported a strange issue like this (https://www.anoopcnair.com/intune-enrollment-error-unknown-win32-error/), but I don't think that is the case in your scenario.

    0 comments No comments

  3. Veera Ragavan 51 Reputation points
    2022-03-23T15:48:25.46+00:00

    Hello All,

    I Found the Answer...

    After Verifying the Domain, and made the UPN Rout-able to XYZ. Com for all Users with Azure AD P1 License, and Intune helped to On Board the Devices to Intune (Hyrbrid Join with GPO Settings)

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.