Windows Autopilot intermittent issue-4/5 failure

svjs-0437 201 Reputation points
2020-09-08T17:18:24.463+00:00

Hi,

We are facing intermittent issue were 4 out of 5 attempts made to do Windows Autopilot hybrid AD join fails. When new devices assigned with Hybrid AAD join profile are initiated, the setup fails for the device after user enter the credential. The user credentials are validated and device is enrolled in Intune, however the device does not initiate the domain join activity and there are no event for the device joining activity on the Intune AD connector. And the setup fails with the error code 80070774. We have also noticed that when we connect three devices at the same time, two among them fails with this case and one goes through. Devices ending up in this error never seems to have picked up the domain join profile and no ODJ blob events were created for this devices on the Intune AD connector server. Also noiced we dont have any issue when doing this outside client network using VPN configuration.

Any help or advise on any fix for the issue is appreciated.

PS: all MS URL mentioned on both links below are already whitelisted in firewall appliance.

https://learn.microsoft.com/en-us/mem/intune/fundamentals/intune-endpoints
https://learn.microsoft.com/en-us/mem/autopilot/windows-autopilot-requirements

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,767 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Nick Hogarth 3,436 Reputation points
    2020-09-08T22:38:25.92+00:00

    I would suggest reviewing this link and checking the event logs to see what is going on - https://oofhours.com/2020/07/19/troubleshooting-windows-autopilot-hybrid-azure-ad-join/

    0 comments No comments

  2. CiciWu-MSFT 1,206 Reputation points
    2020-09-09T02:28:01.993+00:00

    Error 0x80070774: Something went wrong. Confirm you are using the correct sign-in information and that your organization uses this feature. You can try to do this again or contact your system administrator with the error code 80070774.
    This issue typically occurs before the device is restarted in a Hybrid Azure AD Autopilot scenario, when the device times out during the initial Sign in screen. It means that the domain controller can't be found or successfully reached because of connectivity issues. Or that the device has entered a state which can't join the domain.

    Cause: The most common cause is that Hybrid Azure AD Join is being used and the Assign user feature is configured in the Autopilot profile. Using the Assign user feature performs an Azure AD join on the device during the initial sign-in screen which puts the device in a state where it can't join your on-premises domain. Therefore, the Assign user feature should only be used in standard Azure AD Join Autopilot scenarios. The feature should be not used in Hybrid Azure AD Join scenarios.
    Another possible cause for this error is that the Autopilot object's associated AzureAD device has been deleted. To resolve this, delete the Autopilot object and reimport the hash to generate a new one.

    Refer the solutions and check if it works : https://learn.microsoft.com/en-us/mem/intune/enrollment/troubleshoot-windows-enrollment-errors#resolution-16


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.