Event details
Get answers to your questions about adopting Windows 11 and managing the Windows devices used by remote, onsite, and hybrid workers across your organization. Get tips on keeping devices up to date ef...
Char_Cheesman
Updated Nov 19, 2024
reastman1966
Jun 19, 2024Brass Contributor
I am running into an issue where hybrid joined devices are stuck in the "in progress" for device enrolled in Windows Autopatch. The fix seems to be doing a manual sync from the device using the following steps
Click on the Start menu.
Select "Settings".
Click on "Accounts" in the left-hand menu.
Under "Accounts", you should see "Access work or school".
Click on domain.com or use the arrow if it is there
Click on Info
Scroll down to "Device sync status"
Send me an error that is present
Click on Sync
We use Zscaler for our VPN and it seems that it is blocking the device from checking into Intune. When doing the manual sync if it gets an error I am restarting the tunnel service on the device.
I am wondering if there is a way to do the sync remotely using something like PowerShell? Is there a log file that would document the issue with not being able to sync to Intune so I can work on it from that direction?
- EricMoeJun 20, 2024
Microsoft
It sounds like one or more Intune endpoints are not open through your network/VPN. Check out this page https://learn.microsoft.com/en-us/mem/intune/fundamentals/intune-endpoints?tabs=north-america where you can confirm that the endpoints for Intune are open. The sync can also be initiated from the Intune side (locate the device, select Sync Settings) but if the network destination is unreachable by the client, it won't be able to sync policy. Check your VPN configuration and verify the destination addresses are reachable.- DaveD-MS-CETSJun 20, 2024
Microsoft
Autopilot also has some networking endpoints of it's own, so building on Eric's response, it's worth checking that these are available during enrolment https://learn.microsoft.com/en-us/autopilot/requirements?tabs=networking#networking-requirements- DaveD-MS-CETSJun 20, 2024
Microsoft
This could also be a great time to revisit EntraID Join, rather than EntraID Hybrid Join. If you're using Hybrid Join to provide access to on-premises resources such as File and Print servers this is a good resource to review Use on-premises services with cloud-native endpoints - Microsoft Intune | Microsoft Learn