Forum Discussion
Intune Enrollment via GPO User eXperience
Hi All
I have successfully setup Hybrid Azure AD Join and I have implemented Auto-enrollment into Intune via GPO.
However, on my test user(s) I'm still getting MDM status = None.
Can anyone tell me what the User eXperience should be for this type of Intune Enrollment?
Does the User get prompted to sign in or anything?
Info appreciated
10 Replies
- almarlibetarioBrass Contributor
StuartK73 I have these problems every time. what I did is to run dsregcmd /status and see if the AzureADPRT value is NO. then if the value is NO, reboot the machine and login using the O365 account UPN (mailto:sample@contoso.com). It doesn't matter if it is the same with the on-premise AD UPN but you need to type the whole UPN name as login. It will create a new profile and then go to work or school account and click on info. Once all the progress is successful, run the dsregcmd /status command again and see if the AzureADPRT value has changed.
Note: do not run cmd as administrator if you are applying the policy per user basis not on per device.
Also check the task scheduler of the affected machine. A successful Hybrid-joined device will automatically create a scheduled task. Also, check the event viewer for errors.
Hope this helps.
- ambarishrhIron Contributor
StuartK73 Could you please share some more information about your setup?
- What GPO settings did you apply?
- Is this not working for any machines that's joined to local AD?
When you set the gpo for device enrollment, the end machine will need to reboot and login. Once logged in, if you go to windows settings, you should see an info button on the work or school account which confirms that your machine is joined to Hybrid Azure AD.
Another way to check is to run the command dsregcmd /status.
More troubleshooting steps: https://docs.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-hybrid-join-windows-current
- StuartK73Iron Contributor
Yes, the machines are showing as Hybrid Azure AD Join but not as enrolled in Intune.
Stuart
- ambarishrhIron Contributor
StuartK73 I had similar issues with on my tenant where devices will show in Azure AD Devices as Hybrid Azure AD Join but not in All Devices and the MDM state is shown as none. The fix for my case was to set 2 GPO policy settings (As per MS Support, the first device registration policy adds the device to Azure AD and MDM part enrolls the device to intune, and we need to have both to get the devices fully managed via intune/MDM)
If you do not see the policy, it may be because you don’t have the ADMX installed for Windows 10, version 1803 or version 1809. To fix the issue, follow these steps:
- Download:
1803 -->https://www.microsoft.com/en-us/download/details.aspx?id=56880 or
1809 --> https://www.microsoft.com/en-us/download/details.aspx?id=57576. - Install the package on the Primary Domain Controller (PDC).
- Navigate, depending on the version to the folder: 1803 --> C:\Program Files (x86)\Microsoft Group Policy\Windows 10 April 2018 Update (1803) v2, or
1809 --> C:\Program Files (x86)\Microsoft Group Policy\Windows 10 October 2018 Update (1809) v2 - Copy policy definitions folder to C:\Windows\SYSVOL\domain\Policies.
- Restart the Primary Domain Controller for the policy to be available. This procedure will work for any future version as well.
- Download: