Hello Intune team,
After deploying the new Intune Connector for Active Directory based on an sMSA, we have encountered an operational constraint.
Most of our customers operate a single forest with multiple child domains. With a single connector in the root domain, Autopilot devices enroll successfully in root domain OUs, yet fail to complete enrollment in the child domains. Documentation states that one connector is required per domain or child domain, which forces us to deploy and maintain several machines for a service that consumes minimal resources. This requirement increases licensing, infrastructure, and support costs—especially for small-sized organizations.
We would appreciate clarification on whether any supported method allows a single connector (or a single gMSA) to serve multiple child domains within the same forest, and whether there are short-term plans to introduce support for multi-host gMSAs or traditional service accounts.
Any official guidance you can provide will greatly assist us in planning service continuity and optimizing resources for our customers.
Thank you for your attention.