Apple DEP with Intune

%3CLINGO-SUB%20id%3D%22lingo-sub-460575%22%20slang%3D%22en-US%22%3EApple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460575%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20setting%20up%20Apple%20DEP%20on%20a%20new%20Intune%20install.%20It's%20the%20first%20time%20in%20six%20months%20that%20I%20have%20setup%20Apple%20DEP%20with%20Intune%20and%20I%20am%20encountering%20a%20new%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDevices%20that%20enroll%20through%20DEP%20get%20stuck%20at%20the%20Confirming%20Device%20Settings%20stage%20(See%20attachment)%20in%20the%20Intune%20Company%20Portal.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20device%20appears%20in%20the%20Intune%20console%20as%20an%20enrolled%20device%20but%20the%20devices%20get%20stuck%20on%20the%20Confirming%20Device%20Settings%20stage.%20The%20device%20eventually%20becomes%20compliant%20but%20the%20user%20is%20stuck%20with%20a%20notification%20to%20complete%20setup.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20support%20call%20logged%20but%20I%20wanted%20to%20find%20out%20whether%20anyone%20else%20has%20seen%20this%20error.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-460575%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDEP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-460712%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460712%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F45079%22%20target%3D%22_blank%22%3E%40Andrew%20Matthews%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20just%20enrolled%20some%20devices%20through%20DEP%20with%20no%20issues.%3C%2FP%3E%3CP%3EWhich%20iOS%20version%20are%20you%20running%3F%3C%2FP%3E%3CP%3EAre%20you%20authenticating%20in%20the%20DEP%20flow%20or%20in%20Comp%20Portal%3F%3C%2FP%3E%3CP%3EWas%20the%20device%20enrolled%20earlier%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-460765%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460765%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310475%22%20target%3D%22_blank%22%3E%40almennn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20DEP%20profile%20is%20using%20the%20Company%20Portal%20Authentication%20DEP%20workflow%20rather%20than%20the%20Apple%20DEP%20workflow.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20install%20is%20a%20migration%20from%20IBM%20MaaS%20360%20to%20Intune.%20A%20new%20DEP%20enrollment%20token%20has%20been%20added%20for%20Intune%20and%20a%20few%20test%20devices%20have%20been%20migrated%20across.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20tried%20iOS%2011.3.1%2C%20iOS%2012.1.2%20and%20iOS%2012.2.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20BYOD%20enrollment%20of%20an%20iPhone%20works%20normally.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-460788%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460788%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F45079%22%20target%3D%22_blank%22%3E%40Andrew%20Matthews%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBasic%20question%20since%20it's%20a%20migration%20from%20one%20system%20to%20another%2C%20the%20device%20which%20is%20being%20migrated%20is%20factory%20reset%20I%20assume%3F%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-460826%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460826%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310475%22%20target%3D%22_blank%22%3E%40almennn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20the%20device%20is%20being%20factory%20reset%20to%20trigger%20DEP%20enrollment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhere%20we%20get%20to%20is%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EDevice%20resets%3C%2FLI%3E%3CLI%3EApple%20DEP%20guides%20the%20initial%20setup%3C%2FLI%3E%3CLI%3ELong%20wait%20while%20VPP%20pushes%20the%20Intune%20company%20portal%3C%2FLI%3E%3CLI%3ESign-in%20to%20the%20Company%20Portal%3C%2FLI%3E%3CLI%3EEnroll%20the%20device%3C%2FLI%3E%3CLI%3EDevice%20compliance%20check%20starts%3C%2FLI%3E%3CLI%3EThe%20setup%20halts%20at%20that%20point.%3C%2FLI%3E%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-460939%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460939%22%20slang%3D%22en-US%22%3E%3CP%3EAlmost%20sounds%20like%20it's%20timing%20out.%3C%2FP%3E%3CP%3EWhat%20compliance%20checks%20are%20you%20running%3F%3C%2FP%3E%3CP%3EWhat%20config%20profiles%20are%20being%20installed%3F%3C%2FP%3E%3CP%3ENo%20difference%20between%20networks%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsually%20when%20I%20use%20the%20Single%20App%20option%20it%20can%20take%20a%20LONG%20time%20before%20it%20gets%20released.%3C%2FP%3E%3CP%3EIf%20you%20are%20using%20Single%20App%20option%20I%20would%20suggest%20to%20stay%20away%20from%20it.%20I've%20seen%20this%20process%20take%20up%20to%2030-40%20mins%20and%20varies%20extremely.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-461127%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-461127%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20single%20app%20option%20is%20a%20non%20starter%20because%20it%20bricks%20the%20devices%20if%20DEP%20enrollment%20fails.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20compliance%20checks%20are%20fairly%20basic.%20Just%20block%20Jailbroken%20devices%20and%20confirm%20a%20minimum%20pass%20code.%20Similar%20with%20the%20device%20config%20profiles%2C%20Device%20restrictions%20with%20basic%20restrictions%2C%20mainly%20passcode%20and%20a%20WiFi%20profile.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20tried%204G%2C%20several%20different%20WiFi's%20and%20no%20difference.%20There%20is%20definitely%20something%20that%20is%20not%20quite%20right%20with%20this%20customer's%20tenant.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-462811%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-462811%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20not%20sure%20if%20this%20is%20related%20or%20not%20but%20we%20also%20had%20a%20few%20devices%20stuck%20on%20%22Confirming%20Device%20Settings%22%20today.%20Eventually%20we%20disabled%20Single%20App%20Mode%20and%20it%20started%20working%20again%20but%20that%20may%20have%20been%20a%20coincidence.%20Now%20we%20have%20multiple%20devices%20stuck%20on%20the%20%22Awaiting%20final%20configuration%22%20screen.%20Also%2C%20I've%20had%20trouble%20loading%20admin.microsoft.com%20to%20view%20any%20service%20advisories%20and%20%3CA%20href%3D%22https%3A%2F%2Fportal.office.com%2FServiceStatus%2FServiceStatus.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fportal.office.com%2FServiceStatus%2FServiceStatus.aspx%3C%2FA%3E%20won't%20load%20at%20all%20(maybe%20it's%20gone%20now%3F).%20Anyway%2C%20I'm%20beginning%20to%20think%20there's%20some%20issues%20with%20Microsoft%20today.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-462821%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-462821%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYour%20experience%20matches%20mine.%20There%20have%20been%20other%20issues%20today%2C%20like%20App%20Protection%20failing%20to%20apply%20to%20new%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESomething%20has%20gone%20wrong.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-465647%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-465647%22%20slang%3D%22en-US%22%3E%3CP%3EAny%20luck%20today%3F%20My%20devices%20have%20been%20sitting%20at%20the%20%22Awaiting%20final%20configuration%20from%20COMPANY%20NAME%22%20for%20almost%20an%20hour.%20I've%20opened%20a%20ticket%20with%20Microsoft.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-465839%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-465839%22%20slang%3D%22en-US%22%3E%3CP%3EApple%20Dep%20with%20Company%20Portal%20enrollment%20works%20this%20morning%20on%20the%20tenant%20that%20I%20am%20working%20on.%20But%20Apple%20DEP%20authentication%20only%20(not%20with%20the%20company%20portal)%20completely%20fails%2C%20we%20don't%20even%20get%20to%20the%20Awaiting%20final%20configuration%20stage.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20tenant%20that%20I%20am%20working%20on%20is%20on%20Europe%200301%20so%20it%20might%20be%20fixed%20in%20some%20tenants%20and%20not%20others.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-467175%22%20slang%3D%22en-US%22%3ERe%3A%20Apple%20DEP%20with%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-467175%22%20slang%3D%22en-US%22%3EFYI%2C%20Within%20InTune%20under%20Tenant%20Status%2C%20there's%20now%20an%20alert%20indicating%20%22Users%20are%20experiencing%20delays%20of%20up%20to%2030%20minutes%20when%20attempting%20to%20perform%20compliance%20check-ins%22.%20I%20believe%20this%20was%20likely%20related%20to%20my%20Awaiting%20Final%20Configuration%20issue%20I%20was%20having%20which%20I%20since%20resolved%20by%20erasing%20the%20devices%20and%20starting%20again.%3C%2FLINGO-BODY%3E
Andrew Matthews
Contributor

I am setting up Apple DEP on a new Intune install. It's the first time in six months that I have setup Apple DEP with Intune and I am encountering a new issue.

 

Devices that enroll through DEP get stuck at the Confirming Device Settings stage (See attachment) in the Intune Company Portal.

 

The device appears in the Intune console as an enrolled device but the devices get stuck on the Confirming Device Settings stage. The device eventually becomes compliant but the user is stuck with a notification to complete setup.

 

I have a support call logged but I wanted to find out whether anyone else has seen this error.

11 Replies

Hi @Andrew Matthews 

 

I just enrolled some devices through DEP with no issues.

Which iOS version are you running?

Are you authenticating in the DEP flow or in Comp Portal?

Was the device enrolled earlier?

@almennn 

 

The DEP profile is using the Company Portal Authentication DEP workflow rather than the Apple DEP workflow.

 

This install is a migration from IBM MaaS 360 to Intune. A new DEP enrollment token has been added for Intune and a few test devices have been migrated across.

 

We have tried iOS 11.3.1, iOS 12.1.2 and iOS 12.2.

 

A BYOD enrollment of an iPhone works normally.

@Andrew Matthews 

 

Basic question since it's a migration from one system to another, the device which is being migrated is factory reset I assume? :)

@almennn 

 

Yes the device is being factory reset to trigger DEP enrollment.

 

Where we get to is

 

  • Device resets
  • Apple DEP guides the initial setup
  • Long wait while VPP pushes the Intune company portal
  • Sign-in to the Company Portal
  • Enroll the device
  • Device compliance check starts
  • The setup halts at that point.

Almost sounds like it's timing out.

What compliance checks are you running?

What config profiles are being installed?

No difference between networks?

 

Usually when I use the Single App option it can take a LONG time before it gets released.

If you are using Single App option I would suggest to stay away from it. I've seen this process take up to 30-40 mins and varies extremely.

The single app option is a non starter because it bricks the devices if DEP enrollment fails.

 

The compliance checks are fairly basic. Just block Jailbroken devices and confirm a minimum pass code. Similar with the device config profiles, Device restrictions with basic restrictions, mainly passcode and a WiFi profile.

 

We have tried 4G, several different WiFi's and no difference. There is definitely something that is not quite right with this customer's tenant.

I'm not sure if this is related or not but we also had a few devices stuck on "Confirming Device Settings" today. Eventually we disabled Single App Mode and it started working again but that may have been a coincidence. Now we have multiple devices stuck on the "Awaiting final configuration" screen. Also, I've had trouble loading admin.microsoft.com to view any service advisories and https://portal.office.com/ServiceStatus/ServiceStatus.aspx won't load at all (maybe it's gone now?). Anyway, I'm beginning to think there's some issues with Microsoft today.

Thanks

 

Your experience matches mine. There have been other issues today, like App Protection failing to apply to new devices.

 

Something has gone wrong.

Any luck today? My devices have been sitting at the "Awaiting final configuration from COMPANY NAME" for almost an hour. I've opened a ticket with Microsoft. 

Apple Dep with Company Portal enrollment works this morning on the tenant that I am working on. But Apple DEP authentication only (not with the company portal) completely fails, we don't even get to the Awaiting final configuration stage.

 

The tenant that I am working on is on Europe 0301 so it might be fixed in some tenants and not others.

FYI, Within InTune under Tenant Status, there's now an alert indicating "Users are experiencing delays of up to 30 minutes when attempting to perform compliance check-ins". I believe this was likely related to my Awaiting Final Configuration issue I was having which I since resolved by erasing the devices and starting again.
Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies