SOLVED
Home

How does one build an Intune AutoPilot ready device, using SCCM, without it becoming Co-Managed?

%3CLINGO-SUB%20id%3D%22lingo-sub-268861%22%20slang%3D%22en-US%22%3EHow%20does%20one%20build%20an%20Intune%20AutoPilot%20ready%20device%2C%20using%20SCCM%2C%20without%20it%20becoming%20Co-Managed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268861%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22post-text%22%3E%3CP%3EI%20would%20like%20to%20build%20devices%20using%20SCCM%2C%20much%20like%20they%20arrive%20new%2C%20for%20Intune%20AutoPilot%20deployments.%20This%20seemed%20simple%20enough.%20I%20created%20a%20generic%20Task%20Sequence%2C%20Then%20wrote%20a%20script%20which%20uninstalls%20the%20SCCM%20Client%2C%20gathers%20the%20device's%20hardware%20ID%20and%20then%2C%20runs%20%22sysprep%20%2Foobe%20%2Fshutdown%22.%20This%20script%20runs%20after%20the%20Task%20Sequence%20completes%2C%20using%20the%20Task%20Sequence%20Variable%20%22SMSTSPostAction%22.%20All%20of%20this%20works%20beautifully%2C%20until%20the%20machine%20is%20joined%20to%20Azure%20AD%20via%20AutoPilot.%20My%20first%20sign%20of%20trouble%20was%20that%20the%20Intune%20Policies%20would%20not%20apply.%20I%20then%20found%20this%20message%20when%20looking%20at%20the%20device%20in%20Intune%3A%3C%2FP%3E%3CPRE%3ECo-management%0A%26lt%3BUserName%26gt%3B's%20Windows%20PC%20is%20being%20co-managed%20between%0AIntune%20and%20Configuration%20Manager.%20Configuration%20Manager%20agent%20state%20is%0Ashown%20below%2C%20if%20the%20state%20is%20anything%20other%20than%20%E2%80%9CHealthy%E2%80%9D%20there%20are%20a%0Afew%20steps%20that%20help%20with%20this.%20%0A%0AConfiguration%20Manager%20agent%20state%0ACould%20not%20connect%0A%0ADetails%0AThe%20Configuration%20Manager%20client%20is%20currently%20unable%20to%20reach%0Athe%20Configuration%20Manager%20management%20point.%20Make%20sure%20the%20client%20can%0Acommunicate%20with%20the%20server.%20For%20more%20information%20on%20client%0Acommunication%20issues%2C%20see%20the%20CcmMessaging.log%2C%20LocationServices.log%2C%0Aor%20ClientLocation.log%20files%20on%20the%20Configuration%20Manager%20client.%3C%2FPRE%3E%3CP%3E%3CSPAN%20class%3D%22comment-copy%22%3EWe%20did%20have%20Co-Management%20turned%20on%2C%20for%20a%20brief%20moment%2C%20in%20our%20AutoPilot%20journey.%20We%20quickly%20found%20that%20it%20complicated%20things%20and%20then%20followed%20instructions%20in%20someone's%20blog%20post%20to%20turn%20it%20off.%20Possibly%2C%20something%20went%20wrong%20turning%20it%20off%3F%20What%20I%20do%20not%20understand%20is%20why%20Intune%20thinks%20these%20devices%20are%20managed%20by%20SCCM.%20My%20best%20guess%20is%20that%20the%20SCCM%20client%20uninstall%20leaves%20behind%20cruft%20which%20the%20MDM%20system%20is%20reporting%20back%20to%20Intune.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20create%20devices%2C%20ready%20to%20be%20AutoPiloted%20and%20only%20managed%20by%20Intune%2C%20using%20SCCM%3F%20If%20so%2C%20how%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20also%20a%20%3CA%20href%3D%22https%3A%2F%2Fserverfault.com%2Fq%2F934565%2F6079%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3EServerFault%20Question%3C%2FA%3E.%3C%2FP%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-268861%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAutopilot%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECo-management%20with%20Microsoft%20Intune%20and%20System%20Center%20Configuration%20Manager%20AMA%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESCCM%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-282935%22%20slang%3D%22en-US%22%3ERe%3A%20How%20does%20one%20build%20an%20Intune%20AutoPilot%20ready%20device%2C%20using%20SCCM%2C%20without%20it%20becoming%20Co-Managed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-282935%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20looks%20like%20there%20will%20soon%20be%20a%20new%20SCCM%20Task%20Sequence%20Template%20for%20building%20AutoPilot%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsccm%2Fcore%2Fget-started%2Fcapabilities-in-technical-preview-1810%23bkmk_autopilot%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsccm%2Fcore%2Fget-started%2Fcapabilities-in-technical-preview-1810%23bkmk_autopilot%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-282928%22%20slang%3D%22en-US%22%3ERe%3A%20How%20does%20one%20build%20an%20Intune%20AutoPilot%20ready%20device%2C%20using%20SCCM%2C%20without%20it%20becoming%20Co-Managed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-282928%22%20slang%3D%22en-US%22%3E%3CP%3EHere%20is%20another%20blog%20article%2C%20this%20one%20with%20lots%20of%20pretty%20screenshots...%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FUpgrade-Windows-7-using-Windows-Autopilot-in-Configuration%2Fba-p%2F267747%22%20target%3D%22_blank%22%3EUpgrade%20Windows%207%20using%20Windows%20Autopilot%20in%20Configuration%20Manager%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20to%20my%20script%2C%20which%20removed%20the%20SCCM%20Client%20from%2C%26nbsp%3Bregistered%2C%20then%20OOBE%20reset%20the%20device%3B%20it%20will%20be%20invalidated%20by%20the%20ability%20to%20drop%20a%20configuration%20file%20on%20the%20device%2C%20which%20will%20cause%20it%20to%20automatically%20register%20the%20device.%20Besides%20the%20registration%20code%20was%20copied%20from%20someone%20else.%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-282229%22%20slang%3D%22en-US%22%3ERe%3A%20How%20does%20one%20build%20an%20Intune%20AutoPilot%20ready%20device%2C%20using%20SCCM%2C%20without%20it%20becoming%20Co-Managed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-282229%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EHi%20Nathan%2C%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3Ecould%20you%20share%20the%20script%20running%20after%20the%20TS%20to%20uninstall%20agent%20and%20gathering%20the%20hardware%20id%3F%3CBR%20%2F%3E%3CBR%20%2F%3EAnd%20Michael%20Niehaus%20also%20provides%20an%20example%20TS%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fmniehaus%2F2018%2F10%2F25%2Fspeeding-up-windows-autopilot-for-existing-devices%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fmniehaus%2F2018%2F10%2F25%2Fspeeding-up-windows-autopilot-for-existing-devices%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBR%2C%3CBR%20%2F%3E%3CBR%20%2F%3EChristian%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-269124%22%20slang%3D%22en-US%22%3ERe%3A%20How%20does%20one%20build%20an%20Intune%20AutoPilot%20ready%20device%2C%20using%20SCCM%2C%20without%20it%20becoming%20Co-Managed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-269124%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Nathan%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESteven%20McGirr%20has%20a%20nice%20blog%20post%20describing%20install%20of%20a%20device%20by%20finishing%20with%20running%20again%20through%20OOBE%20incl.%20Autopilot%20experience%20based%20on%201809%20devices.%20He%20describes%20the%20cloud%20managed%20scenario%20with%20AADJ%20%26amp%3B%20Intune%20(that's%20what%20you%20are%20looking%20for)%20and%20the%20co-managed%20scenario.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Esee%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fstevenmcgirr.wordpress.com%2F2018%2F10%2F09%2Fwindows-autopilot-for-existing-devices%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fstevenmcgirr.wordpress.com%2F2018%2F10%2F09%2Fwindows-autopilot-for-existing-devices%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Nathan Hartley
Occasional Contributor

I would like to build devices using SCCM, much like they arrive new, for Intune AutoPilot deployments. This seemed simple enough. I created a generic Task Sequence, Then wrote a script which uninstalls the SCCM Client, gathers the device's hardware ID and then, runs "sysprep /oobe /shutdown". This script runs after the Task Sequence completes, using the Task Sequence Variable "SMSTSPostAction". All of this works beautifully, until the machine is joined to Azure AD via AutoPilot. My first sign of trouble was that the Intune Policies would not apply. I then found this message when looking at the device in Intune:

Co-management
<UserName>'s Windows PC is being co-managed between
Intune and Configuration Manager. Configuration Manager agent state is
shown below, if the state is anything other than “Healthy” there are a
few steps that help with this. 

Configuration Manager agent state
Could not connect

Details
The Configuration Manager client is currently unable to reach
the Configuration Manager management point. Make sure the client can
communicate with the server. For more information on client
communication issues, see the CcmMessaging.log, LocationServices.log,
or ClientLocation.log files on the Configuration Manager client.

We did have Co-Management turned on, for a brief moment, in our AutoPilot journey. We quickly found that it complicated things and then followed instructions in someone's blog post to turn it off. Possibly, something went wrong turning it off? What I do not understand is why Intune thinks these devices are managed by SCCM. My best guess is that the SCCM client uninstall leaves behind cruft which the MDM system is reporting back to Intune.

 

Is it possible to create devices, ready to be AutoPiloted and only managed by Intune, using SCCM? If so, how?

 

Thanks.

 

This is also a ServerFault Question.

4 Replies
Solution

Hi Nathan,

 

Steven McGirr has a nice blog post describing install of a device by finishing with running again through OOBE incl. Autopilot experience based on 1809 devices. He describes the cloud managed scenario with AADJ & Intune (that's what you are looking for) and the co-managed scenario.

 

see here: https://stevenmcgirr.wordpress.com/2018/10/09/windows-autopilot-for-existing-devices/

 

best,

Oliver

Hi Nathan,

could you share the script running after the TS to uninstall agent and gathering the hardware id?

And Michael Niehaus also provides an example TS:

 

https://blogs.technet.microsoft.com/mniehaus/2018/10/25/speeding-up-windows-autopilot-for-existing-d...

BR,

Christian

Here is another blog article, this one with lots of pretty screenshots...

Upgrade Windows 7 using Windows Autopilot in Configuration Manager

 

 

As to my script, which removed the SCCM Client from, registered, then OOBE reset the device; it will be invalidated by the ability to drop a configuration file on the device, which will cause it to automatically register the device. Besides the registration code was copied from someone else. ;)