Share via

Automatic MDM Enrollment - Windows 10 Clients - Scenario

Veera Ragavan 56 Reputation points
2022-02-24T12:48:36.17+00:00

Hello Techie's,

Here is the Scenario, I Would like to take help

I have 3 Different Forest/Domain's

Domain 1 - ABC.COM
Domain 2 - XYZ.COM
Domain 3 - 123.COM

Domain 1 - ABC.COM - We have the Azure AD Connect, and Installed with MECM - With Co Management. All Management via Intune
Domain 1 - Azure AD Connect which Collect the Details of AD - All 3 Domains (Domain 1, 2 and 3)

Now, We want Domain 2 and Domain 3 has to be Controlled via Intune
So we have done the following..

XYZ.COM - Users are Assigned with Azure AD P1, Microsoft Intune Licenses
XYZ.COM - Users are Available in the Azure AD, Azure Portal
XYZ.COM - Devices are Available in the Azure AD, Azure Portal
XYZ.COM - Created the GPO, and Assigned the MDM Profile for Enrollment - User Credential

177457-image.png

Out Put, Event ID : 76 - Auto MDM Enroll: Device Credential (0x0), Failed (Unknown Win32 Error code: 0x8018002b)
177458-image.png

We cannot see the MDM URL, MDMTOUURL, MDM Compliance URL while running the DSREGCMD /Status
177516-image.png

From the Intune Side, We do not have any Restrictions. Enrollment

177497-image.png

Also no Restrictions with Device Type - As well.. Devices are Targeted to this Group

177498-image.png

Question:

  1. Is it Really Possible to Manage the Domain 2 (XYZ) Clients via Intune? which the Tenant belongs to Domain 1 (ABC)

Now the Current Status is Device is showing as Hybrid Azure AD Joined, along with Registered and Activity time

177517-image.png

Any Steps from your suggestion, Expertise can help... We need to Manage the Domain 2, Domain 3 Devices has to be Manage via Intune is the Goal

Little more Update from my side

I have mentioned the Domain Name as

XYZ.COM and it is more likely as XYZ.Local

Its Local Domain, and not registered/Purchased any where. Can you refer some link to register this Domain.

In late time, I Found that this Domains are not Registered yet with Azure Portal

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other

3 answers

Sort by: Most helpful
  1. Veera Ragavan 56 Reputation points
    2022-03-23T15:48:25.46+00:00

    Hello All,

    I Found the Answer...

    After Verifying the Domain, and made the UPN Rout-able to XYZ. Com for all Users with Azure AD P1 License, and Intune helped to On Board the Devices to Intune (Hyrbrid Join with GPO Settings)

    Was this answer helpful?

    0 comments No comments

  2. Rahul J 76 Reputation points
    2022-03-01T07:12:49.883+00:00

    Syncing multiple domains/forests using single Azure AD connect is going to be tricky. I hope you might have already checked https://learn.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies to confirm your scenario is supported even though it's syncing devices as well as users to Azure AD.

    Also, MDM Enrollment GP - User authentication can be tricky sometimes - I know Anoop reported a strange issue like this (https://www.anoopcnair.com/intune-enrollment-error-unknown-win32-error/), but I don't think that is the case in your scenario.

    Was this answer helpful?

    0 comments No comments

  3. KONETI ESWARARAJU 2,206 Reputation points MVP Volunteer Moderator
    2022-02-24T14:35:06.357+00:00

    is xyz and 123 domains are routable? check this Microsoft document for more information https://learn.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors#auto-mdm-enroll-failed

    Thanks,
    Eswar
    www.eskonr.com

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.