PCs losing Microsoft M365 Login in AD Hybrid Environment

Frederik 0 Reputation points
2023-05-11T08:11:28.2166667+00:00

Hi everyone,

 

Has someone a tip for us what it could be?

We have the problem, that some of our user need to type in their password in the Microsoft login prompt, so they lose the connection to their M365 Account for example for Edge, Word, oneDrive.... .

 

All these Users using company PCs which are in local AD and synced one way to M365 over the MS Sync tool. At some User the needed to login to M365 Account, even more than once a day.

 

Some user got the error message:

“mddprov account has removed your workplace account(…)”

We don't use Intunes directly.

 

So what could it be ?

 

Best Regards

Frederik

 

 

 

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,563 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,067 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 16,921 Reputation points Microsoft Employee
    2023-05-15T07:52:08.0533333+00:00

    @Frederik

    Thank you for posting your query on Microsoft Q&A, From above description I could understand that your end users are getting "mddprov account has removed your workplace account" message, you have Intune (with limited settings enabled). Kindly try suggestion as per https://learn.microsoft.com/en-us/answers/questions/1191087/azure-mddprov-to-intune-question:

    1,Are MDM and MAM user scope both enabled for all users (or the same groups of users)? If yes, for Windows BYOD devices, the MAM user scope takes precedence, so the device will not be MDM enrolled and not be visible in Intune.

    User's image

    2,We can try to turn off MAM user scope, delete the device from Azure AD, disconnect the account on the device, then connect it again, and join to Azure AD and enroll to Intune.

    For more information, please refer to:

    Set up automatic enrollment for Windows devices

    The Battle Between AADJ and AADR

    Please do let me know if you have any queries in comments section.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.

    0 comments No comments