Intune enrollment via GPO

srinivas Pasupuleti100 60 Reputation points
2024-07-24T16:01:13.92+00:00

Hello,

We have Entra hybrid joined devices and i tried to enroll devices into intune via GPO,it is assigned to the OU in AD.It was successfully applied to users.It is enable for auto enrollment type is user credential.

User has intune license and Microsoft 365 business basic license.And my organization tenant has Entra ID p2 license.IS user require Entra ID p2 license or tenant Entra ID p2 license is enough.

And In Intune Automatic enrollment set to All

In task scheduler-->microsoft-->windows->Enterprisemgmt -->showing as above screenshot.It showing access denied.User's image

In Event viewer -->application logs-->microsoft-->windows->Task scheduler->operational-->it shows as error below screenshot

User's image

User's image

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,920 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,373 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,191 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-07-24T16:18:57.5866667+00:00

    Is the device successfully hybrid joined? Any CA policy implemented requiring MFA in the background? Have you checked the user sign-in logs in Entra ID?


  2. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-07-24T16:41:47.82+00:00

    That explains a lot. Did you delete the Intune enrolment for the device object showing as Entra registered first?


  3. Crystal-MSFT 49,346 Reputation points Microsoft Vendor
    2024-07-25T01:34:30.59+00:00

    @srinivas Pasupuleti100, Thanks for posting in Q&A. From your description, I know the two affected users are with Microsoft Intune and Microsoft 365 business basic license. Based on my checking Microsoft 365 business basic doesn't include Microsoft Entra Premium license.

    https://learn.microsoft.com/en-us/entra/fundamentals/licensing#entra-licensing-options

    For GPO enrollment, auto-enrollment is needed to be enabled

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-enrollment/troubleshoot-windows-auto-enrollment#verify-the-configuration

    To enable auto-enrollment, Microsoft Entra ID P1 or P2 is needed.

    https://learn.microsoft.com/en-us/mem/intune/enrollment/quickstart-setup-auto-enrollment

    For the affected users, it misses this license. Then it can cause failure. Please assign the license to see if it can be working.

    Please try the above suggestion and if there's any update, feel free to let us know,


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.