Forum Discussion

David-B's avatar
David-B
Copper Contributor
Nov 21, 2020
Solved

Trying to learn Intune - stuck at MDM "Your device is already being manged by an organization"

I'm trying to learn Intune and Endpoint manager so I'm going through the Pluralsight course Implementing Mobile Device Management (MDM) with Microsoft Intune by Greg Shields.

 

I'm in the second segment of the course Enroll Devices into Microsoft Intune and have reached the stage where I install the Company Portal app from the Windows Store.

 

Installing the app, I successfully sign into one of the user AAD accounts, then go into the MDM part.

 

Clicking next

Clicking Connect

Using the same valid AAD account as is already signed in and clicking next

 

In Windows Settings, Accounts, Access work or school, the test user account is listed. Clicking info shows that it is managed by mddprov account.

 

There are no errors in the DeviceManagement-Enterprise-Diagnostics-Provider event log section.

 

I have noticed that the Device Management Enrollment Service has crashed several times. This is a clean new install of windows 10 pro in eval mode. The crash occurs when I open Company Portal. Exception code 0xc0000005 in module windows.inernal.management.dll

 

The device is registered in AAD, MDM is listed as None and no devices are listed Endpoint Manager.

 

I'm lost as to a solution. If anyone has suggestions of how I can resolve this issue, I'd appreciate it.

  • The issue has been resolved. The default configuration was for MAM user scope to be set to All when it needs to be set to None.

     

    To get to the correct screen, go to Microsoft Endpoint Manager, click Devices, Enroll Devices, click Automatic Enrollment. Changing MAM from All to None, unmanaging the devices currently in AAD, then adding them again via the Company Portal store app.

     

     

24 Replies

  • Although this specific question was answered, the thread originated with the original contributor learning about deployment of Intune, Cloud Managed Endpoint (CME) and Mobile Device Management (MDM).

     

    If you are an IT Admin with access to the Microsoft 365 Admin Center, and you want step-by-step guidance on how to manage organization-owned or bring-your-own-device (BYOD) mobile devices and applications, be sure to review the Intune setup guide.

     

    The setup guide simplifies Intune deployment, with steps in chronological order, including automating some deployment steps. 

     

    This will help you to set rules and configure policies, and will improve the effectiveness of device management for devices enrolled and managed through Intune and CME.

    • MrThompson265's avatar
      MrThompson265
      Copper Contributor

      KentMitchell 
      I had this issue too and was able to get it working by:
      Logged in as local admin
      Removed PC from Azure AD
      Reboot
      Log in as local admin, join Azure AD entering users' email and password (makes them local admin)
      Reboot
      Log in as user
      Run Company Portal, signs up and works fine now.

  • bbrotschi2021's avatar
    bbrotschi2021
    Copper Contributor
    I ran into the identical issue, and have been banging my head against a wall, until reading your post. Thanks for sharing.
    • Brutus99's avatar
      Brutus99
      Copper Contributor
      Just to be clear, I should disconnect the workOrschool account, remove device from AAD and then run the Company Portal app, uncheck that box and re-register the device? thanks - this is driving me crazy.
  • Tic_Patrick's avatar
    Tic_Patrick
    Copper Contributor

    David-B

     

    Hi David,

     

    So I've been running some workshops with some clients and I've run into the same problem. It really sucked that it happend during a live demo but all assured I did some troubleshooting.

     

    Apparently the Company Portal App is bugged...

    Here are my settings:  MAM and MDM are set to all or can be set to some, it doesn't matter. They should work in tandem ...

    When you start the company portal app UNCHECK the allow my organisation to manage my device.

     

    Everything works smoothly afterwards. I don't even get why that option is there in the first place. Even if it's unchecked it still registers the device with Azure AD...

    I simply proceed then to the allow the organisation to manage my device. It worked.

     

    Hope it helps,

    Patrick

     

      • Tic_Patrick's avatar
        Tic_Patrick
        Copper Contributor
        Right, I completely missed that thing(as in I didn't know about the precedence of MAM over MDM for BYOD, thanks for that) but I was actually referring that having both those option applied shouldn't be the cause of the error "your device is already registered with another organisation". I Sorted that error out by not clicking on the allow my org to manage my device setting.
        Sheesh, I'm confused.. oh well, get your troubleshooting boots on!
  • David-B's avatar
    David-B
    Copper Contributor

    The issue has been resolved. The default configuration was for MAM user scope to be set to All when it needs to be set to None.

     

    To get to the correct screen, go to Microsoft Endpoint Manager, click Devices, Enroll Devices, click Automatic Enrollment. Changing MAM from All to None, unmanaging the devices currently in AAD, then adding them again via the Company Portal store app.

     

     

    • NickZz95's avatar
      NickZz95
      Copper Contributor

      David-B Hi David,

       

      Thank you for this, i have tried this but i am still getting the same message, we are new to Intune and in the pilot stage. 

       

      Can you assist any further?

       

      KR,

      Nick

      • thanatos8877's avatar
        thanatos8877
        Copper Contributor

        NickZz95 

         

        I stumbled on your post while trying to find an answer to a similar problem. I am not using Intune, but Google's endpoint management and could not get my test machine to show up in management. Since I found my answer, I thought I'd share what I found on the off chance that the issues are the same.

         

        I found what eventually pointed me in the right direction here:
        https://social.technet.microsoft.com/Forums/en-US/f2d29524-afce-42ab-9e48-673813c74c4e/unable-to-reenroll-windows-10-1803?forum=microsoftintuneprod

         

        I had to look in the Registry here:

        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments

         

        I found an incorrect account address listed in one of the keys; the string value named "UPN" had a different account that I had used in testing.  Since you mentioned that you are new and in the pilot stage, I thought perhaps you might have also attempted enrollment on this a time or two before.

         

        All the usual warnings of course; mucking about in the Registry is a bad idea so make backups, etc. I have no idea if my fix will translate to a fix for you. I hope that it does.

         

Resources