Intune Automatic Enrollment not happned in Hybrid Azure AD joined scenario

Dilan Nanayakkara 1,111 Reputation points
2022-05-04T13:24:16.71+00:00

Hi All,

I have configured the HAAD joined + Automatic Intune enrollment for our on-premises devices, but whoever login with subdomain's UPN suffix, it won't enroll with Automatic Intune.

For example, let say our Azure AD primary UPN suffix is @jaswant .com, and if user xyz@jaswant .com logon to the device, it is working without an issue. the issue is that if user ******@sd.abc.com logon to their PC, it will registered as a Hybrid AAD joined device, but it won't enroll with Intune.

When I checked the device management logs in event viewer below is the error that I can see.

Device Credential (0x0), Failed (Mobile Device Management (MDM) is not configured.)

further, if I checked the dsregcmd /status, I have identified SSO state showing as NO. please refer the below screenshot.

198789-image.png

198749-image.png

appreciate the help!

Thanks,
Dilan

Microsoft Security | Intune | Enrollment
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2022-05-05T02:52:03.523+00:00

    @Dilan Nanayakkara , Thanks for posting in our Q&A. From your description, I know we are doing Intune enrollment for Hybrid Azure AD join device. But it seem s the AzureAdPrt is NO. If there's any misunderstanding, please let us know.

    Based on my researching, for AzureADprt, if it shows No, it means there's issue when acquiring the PRT status from Azure AD. And the user isn't authenticated to Azure Active Directory (Azure AD) when signing in to the device. As you mentioned, if the user is login with @jaswant .com, it is working. if the user is login with sd.abc,com, it is not. Given the situation, please go through the following article to check if our on-premise AD users UPN support for Hybrid Azure AD join.
    https://learn.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan#review-on-premises-ad-users-upn-support-for-hybrid-azure-ad-join

    From your picture, I notice the error code 0x80072ee7. It seems the server name or address couldn't be resolved. Please also check network connectivity to https://enterpriseregistration.windows.net.

    Here is a troubleshooting article with more details for the reference:
    https://learn.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-hybrid-join-windows-current#troubleshoot-post-join-authentication-issues

    As I am not familiar with Hybrid AAD join issue. I notice "azure-ad-hybrid-identity" is added in this thread. And I also add "azure-active-directory" tag to see if AAD or hybrid AAD support can be involved to help on this issue. Or as another method, you can open a new thread to only add the two tags to let the thread go to the right channel to find the support.

    For Intune enrollment, as AzureADPrt yes is one prerequisite of it. we need to firstly fix the AzureAdprt issue before we do Intune enrollment. If the Intune enrollment is still failed after the above issue is fixed, feel free to contact us to look into the enrollment issue.

    Thanks for the understanding and have a nice day!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Cédric Perion 171 Reputation points
    2022-05-06T21:39:05.89+00:00

    Hi @Dilan Nanayakkara ,

    As @Crystal-MSFT say your PRT is set to NO.
    With AADHJ you must have the prt to yes.

    • Check first that user connected is licence with Intune licence.
    • After that, connect to portal.office.com with the user in the windows session to force prt
    • after you can force the schedule task in Microsoft/aadjoin to start
    • check again with dsreg

    Normally prt is yes and if gpo is Configure for Intune, you should see you device in Intune.

    Thanks
    Cédric

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.