Windows 10 device enrollment to MDM - please help

Virtual Tech 106 Reputation points
2022-06-24T19:06:03.487+00:00

Hi

My test windows 10 computer has not received the office application from Intune. What pushes those URLs to the computer? I know I can manually add them but I prefer to automate it.

When running dsregcmd /status, I am missing the URLs below.
MdmComplianceUrl
MdmEnrollmentUrl
MdmTermsOfUserUrl

Computers device management log error: Auto MDM Enroll: Device Credential (0x0), Failed (Unknown Win32 Error code: 0x8018002b)

Test computers are Hybrid AD joined
configured the Intune automatic enrollment for devices
manually set the GPO GPO and navigate to Computer Configuration > Administrate Templates > Windows Components > MDM > then set "Enable automatic MDM enrollment using default Azure AD Credentials" to enabled.

My environment in Hybrid, AAD syncing objects, SSO, password Hash.

Microsoft Security | Intune | Application management
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,911 Reputation points MVP
    2022-06-24T22:42:06.087+00:00

    Do you have mfa enabled for the enrolling account?


  2. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2022-06-27T06:54:00.427+00:00

    @Virtual Tech , For our enrollment, before going on, could you confirm if it is GPO enrollment.

    Research and find a similar issue, In this this link, it says when event id 76 with error ”0x80180002b“ comes, the value of AzureAdPrt is NO. Please check if it is the same as ours. If yes, try the solution in the following link to see if it helps.
    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/windows10-enroll-error-80180002b

    Meanwhile, please check if all the prerequisites are all met in our situation:
    https://learn.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy

    Please check the above information and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  3. Virtual Tech 106 Reputation points
    2022-06-27T17:07:27.4+00:00

    @Rahul Jindal [MVP]

    • The Office app will be pushed to a shared computer. Not to an individual user.

    @Crystal-MSFT

    • For the computer enrollment, I manually modified the local GPO on the machine.

    Computer Configuration > Administrate Templates > Windows Components > MDM > then set "Enable automatic MDM enrollment using default Azure AD Credentials" to enabled.

    Do you know how the URLs below are populated from O365?

    HKLM\SYSTEM\ControlSet001\Control\CloudDomainJoin\TenantInfo(Random Character String)

    Int here are three keys

    MdmComplianceUrl

    MdmEnrollmentUrl

    MdmTermsOfUserUrl


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.