Microsoft Entra hybrid joined windows devices stopped getting MDM

Daniel Ronald 0 Reputation points
2024-03-05T16:27:27.9566667+00:00

Hi, I have Microsoft Entra hybrid joined windows device that have stopped getting a MDM. I was able to determine that Zoho EPC had assigned a MDM to my devices. I contacted EPC support and they gave me a script to remove the Zoho EPC MDM and that worked for a bit. As I started adding windows machines by enabling secure boot, verifying reagentc was enabled, and the local disk was not encrypted. I also ran the command dsregcmd.exe /debug /leave on these machines. I checked the reg on a couple of these machines for left over MDM information but there was non. I have looked over a couple of the windows machines event logs but nothing stuck out except for one had the message (CanEnroll Error: MDM enrollment is not allowed due to failed access check(administrator or allowed user, capability check) with HRESULT: (Access is denied.). I wasn't able to find anything online regarding this issue. When look at the windows device in azure the settings are: Enable = Yes, OS = Windows, Version = 10.0.19405.4046, Join Type = Microsoft Entra hybrid joined, Owner = n/a, user principal name = none, MDM = none, Compliant = n/a, registered = 2/28/24, activity = 2/28/24, group = none. I ran the command dsregcmd /status AzureADjoined = yes, Enterprised joined = no, domain joined = yes. The MDM and MAM are setup according to the documents. I just can't figure out why these machines are not getting a MDM enrolled. Any help would be greatly appreciated. Update - I did find the Event ID 98 on one of the windows devices, anyone know how to resolve it?
CanEnroll Error: MDM enrollment is not allowed due to failed access check(administrator or allowed user, capability check) with HRESULT: (Access is denied.).

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,307 questions
{count} votes

3 answers

Sort by: Most helpful
  1. glebgreenspan 1,450 Reputation points
    2024-03-05T21:11:36.6966667+00:00

    Hello Daniel

    It seems like you are facing some challenges in getting your Microsoft Entra hybrid joined Windows devices to enroll in the MDM (Mobile Device Management) system. Here are some troubleshooting steps you can take to resolve this issue:

    1.     Check MDM Configuration:

    o    Ensure that the MDM and MAM (Mobile Application Management) settings in Azure AD are correctly configured according to the documentation. Verify that the settings align with the requirements for your devices to enroll in the MDM system.

    2.     Verify Device Registration:

    o    Confirm that the Windows devices are properly registered with Azure AD and have the necessary permissions to enroll in the MDM system. Check the device registration status using the dsregcmd.exe /status command to ensure that AzureADjoined is set to "yes".

    3.     Check Device Compliance:

    o    Verify the compliance status of the devices in Azure AD. Ensure that the devices meet the compliance policies set in the MDM system. Check the compliance status in the Azure portal to see if there are any issues preventing enrollment.

    4.     Review Device Event Logs:

    o    Continue to review the event logs on the Windows devices for any error messages or warnings related to MDM enrollment. Look for any specific error codes or messages that may provide insight into why the devices are not enrolling in the MDM system.

    5.     Check Group Policies:

    o    Review any Group Policies that may be affecting MDM enrollment on the Windows devices. Ensure that there are no policies restricting MDM enrollment or conflicting with the MDM settings configured in Azure AD.


  2. Crystal-MSFT 45,746 Reputation points Microsoft Vendor
    2024-03-06T01:25:15.49+00:00

    @Daniel Ronald, Thanks for posting in Q&A. From your description, it seems you are enrolling Microsoft Entra hybrid joined windows devices into Intune. But some are failed. Please confirm if we enroll these devices via GPO enrollment.

    https://learn.microsoft.com/en-us/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy

    In your description, it seems there are other MDM enrollment information may exist on the affected devices. For these affected devices, please remove the registry keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments to see if the enroll can be successful.

    Meanwhile, for Microsoft Entra hybrid joined, I notice AzureADjoined and domainjoined are yes. Please also confirm the "AzureAdPrt" is also yes. If not, please follow the link below to troubleshoot.

    https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-hybrid-join-windows-current

    Meanwhile, please ensure MDM user scope under Automatic enrollment is set as all. And the device is login with the domain user which has both Microsoft Intune and Microsoft Entra ID license assigned.

    Please try the above suggestion and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Crystal-MSFT 45,746 Reputation points Microsoft Vendor
    2024-03-07T02:14:51.34+00:00

    @Daniel Ronald, Thanks for the reply. Based as I know, to apply Compliance policy, we need to enroll the devices into Intune. I notice you don't use GPO enrollment. Could you let us know what steps you are doing to enroll these devices into Intune?

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-windows

    I notice you mentioned 71 of the Windows devices have MDM. Could you let us know if the MDM is Microsoft Intune? Are these devices appearing in Intune portal ?https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/allDevices

    For the license, I notice it is not one which include Microsoft Intune Plan 1 license. Please go to double confirm on this.

    User's image

    User's image

    For the AzureADprt no, it means there was an error acquiring the PRT status from Microsoft Entra ID. And the Microsoft Entra hybrid joined not completed. Please follow the steps to troubleshoot to see if there's any finding.

    https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-hybrid-join-windows-current#step-1-retrieve-the-prt-status-by-using-dsregcmd-status

    or you can open case to contact Microsoft Entra support to firstly fix the Microsoft Entra hybrid joined issue.

    https://learn.microsoft.com/en-us/entra/fundamentals/how-to-get-support

    0 comments No comments