Home

InTune MDM devices & Office 365 connectivity

%3CLINGO-SUB%20id%3D%22lingo-sub-298363%22%20slang%3D%22en-US%22%3EInTune%20MDM%20devices%20%26amp%3B%20Office%20365%20connectivity%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-298363%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20evening%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20question%20for%20all%20the%20brains%20out%20there%20that%20know%20InTune%20and%20o365%20better%20than%20I.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20moving%20from%20VMWare%20AirWatch%20to%20Microsoft%20InTune%2C%20for%20us%20the%20latter%20works%20considerably%20better.%20There%20is%20one%20issue%20that%20pertains%20to%20enrolled%20devices%20not%20being%20able%20to%20connect%20o365%20apps.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20what%20happens%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20device%20is%20enrolled%20and%20the%20pre-installed%20applications%20get%20pushed%20out.%26nbsp%3B%20This%20all%20works%20perfectly%20and%20by%20the%20time%20the%20user%20sees%20the%20screen%2C%20Teams%2C%20Office%20365%20Pro%20Plus%2C%20Chrome%20etc%20are%20all%20installed.%26nbsp%3B%20However%2C%20when%20the%20user%20goes%20to%20launch%20teams%20they%20are%20faced%20with%20an%20error%20stating%20they%20are%20not%20connected%20to%20the%20internet%20and%20that%20restarting%20the%20application%20might%20help%20(it%20doesn't).%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20complete%20error%3A%3C%2FP%3E%3CP%3E'Oh%20no%20...%20we%20can't%20connect%20to%20the%20internet.%26nbsp%3B%20Check%20your%20connection'%3C%2FP%3E%3CP%3EError%20Code%20-%200%3C%2FP%3E%3CP%3EFailed%20to%20connect%20to%20settings%20endpoint%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESkype%20for%20business%20installs%20but%20refuses%20to%20log%20on%20with%20a%20similar%20message%20but%20this%20time%20failing%20to%20see%20a%20valid%20certificate.%26nbsp%3B%20If%20you%20run%20the%20Skype%20for%20business%20network%20test%20tool%20it%20comes%20back%20that%20it%20can't%20connect%20to%20the%20endpoint.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOutlook%20is%20a%20little%20different%2C%20rather%20than%20immediately%20finding%20the%20users%20e-mail%20address%20(UPN)(AirWatch%20enrolled%20devices%20work%20without%20issue%20and%20automatically%20insert%20the%20UPN)%2C%20we%20have%20to%20type%20it%20in%20manually.%26nbsp%3B%20It%20then%20attempts%20to%20search%20for%20the%20account.%26nbsp%3B%202%20-%203%20minutes%20later%20it%20fails%20asking%20if%20we%20are%20sure%20this%20account%20exists%3B%20it%20does.%26nbsp%3B%20If%20you%20click%20retry%20we%20get%20prompted%20about%20allowing%20out%20autodiscover%20server%20but%20it%20still%20fails.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20to%20confirm%2C%20Outlook%2C%20Teams%20etc%20all%20work%20if%20you%20go%20to%20the%20browser%20based%20versions%3B%20the%20applications%20also%20work%20if%20signed%20in%20to%20a%20device%20enrolled%20via%20AirWatch%20and%20not%20InTune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20our%20users%20are%20assigned%20InTune%20Licenses%20via%20the%20E3%20mobility%20%26amp%3B%20security%20licensing.%26nbsp%3B%20Our%20setup%20is%20a%20Hybrid%20Azure%20AD%20%2F%20On-Prem%20with%20ADFS%203.0%20configured.%26nbsp%3B%20We%20also%20have%20password%20hash%20enabled%20and%20Seamless%20SSO.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20wiped%20our%20InTune%20environment%20and%20enrolled%20devices%20with%20the%20bare%20minimum%20interference%20to%20no%20avail.%26nbsp%3B%20I've%20refreshed%20our%20scheme%20on%20Azure%20AD%20Connect%20and%20also%20confirmed%20that%20even%20when%20connected%20with%20no%20proxy%20%2F%20firewall%20in%20place%20that%20the%20systems%20still%20don't%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'll%20also%20throw%20this%20in%20as%20I%20believe%20it%20might%20also%20be%20involved%2C%20Windows%20Hello%20allows%20us%20to%20configure%20it%20as%20normal%20but%20immediately%20throws%20up%20an%20error%20saying%20the%20credentials%20are%20required%2C%20please%20lock%20and%20login%20with%20the%20credentials.%26nbsp%3B%20This%20never%20goes%20away%2C%20even%20after%20logging%20back%20in%20with%20the%20correct%20credentials.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20would%20be%20greatly%20appreciated%20as%20MS%20have%20had%205%20days%20of%20continued%20conversations%20(8-9%20hours%20of%20phone%20calls%20by%20now)%20and%20they%20can't%20seem%20to%20suggest%20anything%20other%20than%20rebuild%20the%20laptop%20or%20re-install%20Teams.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-298363%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESoftware%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
BW_TJ
Visitor

Good evening all,

 

A question for all the brains out there that know InTune and o365 better than I.

 

We are moving from VMWare AirWatch to Microsoft InTune, for us the latter works considerably better. There is one issue that pertains to enrolled devices not being able to connect o365 apps.

 

So, what happens?

 

A device is enrolled and the pre-installed applications get pushed out.  This all works perfectly and by the time the user sees the screen, Teams, Office 365 Pro Plus, Chrome etc are all installed.  However, when the user goes to launch teams they are faced with an error stating they are not connected to the internet and that restarting the application might help (it doesn't).  

 

The complete error:

'Oh no ... we can't connect to the internet.  Check your connection'

Error Code - 0

Failed to connect to settings endpoint

 

Skype for business installs but refuses to log on with a similar message but this time failing to see a valid certificate.  If you run the Skype for business network test tool it comes back that it can't connect to the endpoint.

 

Outlook is a little different, rather than immediately finding the users e-mail address (UPN)(AirWatch enrolled devices work without issue and automatically insert the UPN), we have to type it in manually.  It then attempts to search for the account.  2 - 3 minutes later it fails asking if we are sure this account exists; it does.  If you click retry we get prompted about allowing out autodiscover server but it still fails.

 

Just to confirm, Outlook, Teams etc all work if you go to the browser based versions; the applications also work if signed in to a device enrolled via AirWatch and not InTune.

 

All our users are assigned InTune Licenses via the E3 mobility & security licensing.  Our setup is a Hybrid Azure AD / On-Prem with ADFS 3.0 configured.  We also have password hash enabled and Seamless SSO.

 

I've wiped our InTune environment and enrolled devices with the bare minimum interference to no avail.  I've refreshed our scheme on Azure AD Connect and also confirmed that even when connected with no proxy / firewall in place that the systems still don't work.

 

I'll also throw this in as I believe it might also be involved, Windows Hello allows us to configure it as normal but immediately throws up an error saying the credentials are required, please lock and login with the credentials.  This never goes away, even after logging back in with the correct credentials.

 

Any help would be greatly appreciated as MS have had 5 days of continued conversations (8-9 hours of phone calls by now) and they can't seem to suggest anything other than rebuild the laptop or re-install Teams.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies