SOLVED
Home

Hybrid Intune Migration for Apple DEP enabled Devices

%3CLINGO-SUB%20id%3D%22lingo-sub-277714%22%20slang%3D%22en-US%22%3EHybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277714%22%20slang%3D%22en-US%22%3E%3CP%3EIntune%20is%20currently%20configured%20in%20Hybrid%20mode%20with%20SCCM%20as%20a%20mgt%20authority%20for%20all%20devices.%20Intune%20Standalone%20configuration%20is%20in%20flight%20for%20pilot%20migration.%20Apple%20DEP%20has%20been%20integrated%20with%20Intune%20Standalone%20and%20Hybrid.%20However%2C%20Devices%20are%20not%20synchronised%20in%20standalone%20Intune%2C%20Sync%20option%20is%20disabled.%26nbsp%3B%20Enrollment%20Program%20Token%20is%20listed%20with%20warning%26nbsp%3B%3CA%20target%3D%22_blank%22%3E%3CSPAN%20class%3D%22fxs-blade-status-text%22%3EYou%20must%20configure%20these%20settings%20in%20the%20Configuration%20Manager%20console.%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%20style%3D%22width%3A%20622px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F58203i6BC9398B3F505DBA%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22image.png%22%20title%3D%22image.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22fxs-blade-status-text%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20451px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F58202i6A309407CDEA2384%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22image.png%22%20title%3D%22image.png%22%20%2F%3E%3C%2FSPAN%3E%5D%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22fxs-blade-status-text%22%3EIs%20there%20any%20way%20to%20force%20DEP%20sync%20prior%20to%20breaking%20Hybrid%20Intune%20setup%20%3F%20Idea%20is%20not%20test%20new%20user%2Fdevice%20migration%20before%20moving%20on%20existing%20users.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-277714%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281427%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281427%22%20slang%3D%22en-US%22%3E%3CP%3EConfirmed%20with%20MS%20Support%2C%20Microsoft%20have%20the%20design%20that%20DEP%20can%20only%20be%20managed%20by%20SCCM%20if%20the%20MDM%20authority%20is%20set%20as%20SCCM.%20MS%26nbsp%3B%20consider%20that%20if%20it%20can%20be%20managed%20by%20both%20SCCM%20and%20Intune%2C%20it%20will%20generate%20some%20conflicts%20and%20mis-operation.%20However%2C%20this%20is%20not%20the%20case%2C%20Apple%20DEP%20can%20have%20multiple%20MDM%20Server%20can%20run%20independently.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281346%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281346%22%20slang%3D%22en-US%22%3ECorrect.%20The%20tenant%20level%20settings%20are%20still%20managed%20by%20ConfigMgr%20until%20you%20switch%20the%20Authority%20to%20Intune.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278959%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278959%22%20slang%3D%22en-US%22%3E%3CP%3Ethanks%20for%20reply%2C%20It%20seems%20we%26nbsp%3B%20cannot%20sync%20DEP%20Devices%20in%20Intune%20standalone%20until%20MDM%20authority%20have%20been%20assigned%20to%20Intune.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278286%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278286%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EAs%20you%20are%20in%20Hybrid%20the%20DEP%20sync%20is%20initiated%20from%20Configuration%20Manager%20until%20you%20switch%20MDM%20authority.%20It%20is%20not%20a%20sync%20with%20ConfigMgr%20you%20are%20doing%20you%20are%20triggering%20a%20DEP%20Sync%20in%20Intune%20from%20SCCM%20as%20that%20is%20your%20MDM%20authority.%3C%2FP%3E%3CP%3ERegards%2C%3CBR%20%2F%3EJ%C3%B6rgen%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-277719%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277719%22%20slang%3D%22en-US%22%3E%3CP%3EConfigMgr%20Sync%20have%20no%20effect%20on%20Intune%20DEP%20sync%20!%26nbsp%3B%20as%20a%20result%20DEP%20devices%20will%20not%20be%20listed%20in%20Intune%20Standalone.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-277718%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277718%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EAs%20Configuration%20Manager%20is%20you%20MDM%20Authority%20you%20need%20to%20trigger%20the%20DEP%20Sync%20from%20there%2C%20here%20is%20an%20example%20on%20how%20to%20do%20just%20that%20%3CA%20href%3D%22https%3A%2F%2Fhiway65nblog.blogspot.com%2F2017%2F05%2Ftrigger-manual-dep-sync-with-powershell.html%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fhiway65nblog.blogspot.com%2F2017%2F05%2Ftrigger-manual-dep-sync-with-powershell.html%3C%2FA%3E%3C%2FP%3E%3CP%3ERegards%2C%3CBR%20%2F%3EJ%C3%B6rgen%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-706437%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-706437%22%20slang%3D%22en-US%22%3E%3CP%3EWhich%20one%20will%20be%20effective%2C%20in%20term%20of%20DEP%20program%20like%3A%20Intune%20or%20VMWare%20AirWatch..%3C%2FP%3E%3CP%3EAlso%20which%20are%20more%20effective%20like%3A%20Costing%2C%20Services%20etc..%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-709201%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-709201%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F323381%22%20target%3D%22_blank%22%3E%40Associate_Consultant%3C%2FA%3E%26nbsp%3BIntune%20or%20Airwatch%20are%20MDM%20solution%2C%20Apple%20Business%20Managed%20aka%20DEP%20is%20apple%20program%20for%20enterprises%20to%20deploy%20devices%20and%20apps.%20highly%20recommended%20to%20use%20Apple%20Business%20Manager%2FDEP%20not%20matter%20what%20MDM%20you%20use%20i.e.%20Intune%2FAirwatch%20to%20automatically%20add%20to%20MDM%20etc..%20Read%20more%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsupport.apple.com%2Fen-au%2Fguide%2Fapple-business-manager%2Fwelcome%2Fweb%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.apple.com%2Fen-au%2Fguide%2Fapple-business-manager%2Fwelcome%2Fweb%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-709581%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-709581%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F336519%22%20target%3D%22_blank%22%3E%40prtkdv%3C%2FA%3EThanks%20so%20much%20for%20information.%20If%20I%20asked%20help%20you%20about%20the%20architect%20design%20for%20the%20Intune%20DEP%20program%20for%2010K%20iPad%20devices%2C%20then%20could%20you%20help%20me%20with%20the%20details%20with%20design%20and%20contents%20please%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-720996%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-720996%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F323381%22%20target%3D%22_blank%22%3E%40Associate_Consultant%3C%2FA%3E%26nbsp%3Bplease%20send%20me%20private%20message%20to%20discuss%20further.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Pratik Dave
New Contributor

Intune is currently configured in Hybrid mode with SCCM as a mgt authority for all devices. Intune Standalone configuration is in flight for pilot migration. Apple DEP has been integrated with Intune Standalone and Hybrid. However, Devices are not synchronised in standalone Intune, Sync option is disabled.  Enrollment Program Token is listed with warning You must configure these settings in the Configuration Manager console. image.png

 

image.png]

 

Is there any way to force DEP sync prior to breaking Hybrid Intune setup ? Idea is not test new user/device migration before moving on existing users. 

10 Replies

Hi,

As Configuration Manager is you MDM Authority you need to trigger the DEP Sync from there, here is an example on how to do just that https://hiway65nblog.blogspot.com/2017/05/trigger-manual-dep-sync-with-powershell.html

Regards,
Jörgen

 

ConfigMgr Sync have no effect on Intune DEP sync !  as a result DEP devices will not be listed in Intune Standalone.

Hi,

As you are in Hybrid the DEP sync is initiated from Configuration Manager until you switch MDM authority. It is not a sync with ConfigMgr you are doing you are triggering a DEP Sync in Intune from SCCM as that is your MDM authority.

Regards,
Jörgen

thanks for reply, It seems we  cannot sync DEP Devices in Intune standalone until MDM authority have been assigned to Intune.

Correct. The tenant level settings are still managed by ConfigMgr until you switch the Authority to Intune.
Solution

Confirmed with MS Support, Microsoft have the design that DEP can only be managed by SCCM if the MDM authority is set as SCCM. MS  consider that if it can be managed by both SCCM and Intune, it will generate some conflicts and mis-operation. However, this is not the case, Apple DEP can have multiple MDM Server can run independently. 

Which one will be effective, in term of DEP program like: Intune or VMWare AirWatch..

Also which are more effective like: Costing, Services etc..

@Associate_Consultant Intune or Airwatch are MDM solution, Apple Business Managed aka DEP is apple program for enterprises to deploy devices and apps. highly recommended to use Apple Business Manager/DEP not matter what MDM you use i.e. Intune/Airwatch to automatically add to MDM etc.. Read more https://support.apple.com/en-au/guide/apple-business-manager/welcome/web

@prtkdvThanks so much for information. If I asked help you about the architect design for the Intune DEP program for 10K iPad devices, then could you help me with the details with design and contents please?

@Associate_Consultant please send me private message to discuss further.

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies