Home

Intune Management Extension missing after AutoPilot Reset

%3CLINGO-SUB%20id%3D%22lingo-sub-806844%22%20slang%3D%22en-US%22%3EIntune%20Management%20Extension%20missing%20after%20AutoPilot%20Reset%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-806844%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20testing%20the%20AutoPilot%20Reset%20as%20an%20easy%20way%20to%20reset%20devices%20between%20users%20as%20simply%20as%20possible.%20The%20reset%20itself%20is%20working%2C%20but%20after%20resetting%20and%20logging%20in%2C%20the%20Intune%20Maganament%20Extension%20%2F%20Engine%20service%20is%20missing%20from%20services.%20Configuration%20profiles%20still%20get%20applied%20(power%20settings%2C%20bitlocker%2C%20lock%20screen%20image%20etc)%2C%20but%20powershell%20scripts%20don't%20run%20and%20Win32%20apps%20don't%20get%20reinstalled%20after%20the%20reset.%20The%20apps%20and%20scripts%20are%20assigned%20to%20the%20same%20device%20groups%20as%20the%20configuration%20profiles%20that%20work%20and%20the%20device%20is%20autopilot%20registered%20with%20the%20self-deploying%20scenario.%20If%20I%20do%20a%20clean%20installation%20from%20Windows%2010%20Education%20ISO%20with%20autopilot%20enrollment%20the%20extension%20works%20properly%20and%20apps%20get%20installed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20advanced%20diagnostic%20MDM%20report%20lists%20under%20Managed%20applications%20ONLY%20Modern%20Apps%20and%20the%20status%20of%20all%20of%20them%20is%20Failed.%20The%20Win32%20apps%20are%20not%20listed%20in%20the%20report.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'd%20like%20to%20be%20able%20to%20use%20the%20AutoPilot%20reset%20since%20compared%20to%20installing%20from%20ISO%2C%20wiping%20or%20fresh%20starting%2C%20it'll%20retain%20the%20Computer%20name%20which%20is%20a%20huge%20help%20not%20having%20to%20rename%20them%20by%20hand%20after%20resetting%20(I'm%20working%20at%20a%20university%20and%20we%20might%20reset%20300%20shared%20devices%20at%20a%20time%20before%20the%20new%20semester%20starts).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20problem%20only%20seems%20to%20affect%20the%20AutoPilot%20Reset.%20Doing%20a%20fresh%20start%20doesn't%20break%20the%20Intune%20Management%20Extension%20and%20everything%20works%2C%20BUT%20I%20have%20to%20rename%20the%20computers.%20It's%20also%20important%20for%20our%20dynamic%20groups%20that%20the%20devices%20have%20specific%20names%2C%20so%20using%20the%20serial%2Frandom%20name%20templates%20don't%20do%20for%20us.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F21544%22%20target%3D%22_blank%22%3E%40Michael%20Niehaus%3C%2FA%3E%26nbsp%3Bhere%20I%20have%20to%20give%20a%20suggestion%20to%20Microsoft%3A%20Add%20the%20ability%20to%20force%20the%20device%20names%20from%20Intune%20or%20Azure%20AD%20in%20a%20way%20that%20reinstalled%20computers%20with%20the%20same%20serial%20number%20automatically%20get%20the%20old%20name%20if%20they%20have%20been%20registered%20in%20AAD%2FIntune%20earlier%20and%20have%20not%20been%20deleted.%20This%20should%20be%20possible%20since%20AutoPilot%20registered%20devices%20retain%20the%20AAD%20Device%20Object%20through%20clean%20installs%20and%20resets%2C%20once%20the%20hardware%20hashes%20have%20been%20imported.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnother%20suggestion%3A%20Automatically%20merge%2Freplace%20Intune%20device%20objects%20with%20the%20same%20serial%20number%20at%20re-enrollment.%20Currently%20if%20I%20reinstall%20a%20computer%2C%20let's%20say%2C%2010%20times%20and%20it's%20autopilot%20registered%2C%20It'll%20appear%20in%20Intune%2010%20times%20even%20though%20it'll%20only%20appear%20in%20Azure%20AD%20once.%20I%20don't%20see%20the%20point%20having%20the%20device's%20old%20copies%20in%20Intune%20as%20they%20have%20no%20more%20effect%20after%20the%20AutoPilot%20enrollment%20creates%20a%20new%20device%20in%20Intune%20and%20attaches%20the%20computer%20to%20it.%20Currently%20I%20use%20the%20automatic%20deletion%20of%20devices%20not%20used%20in%20a%20while%2C%20but%20that%20still%20leaves%20the%20300%20duplicate%20laptops%20for%20at%20least%20three%20months%20lying%20around%20our%20MDM%20unless%20I%20manually%20delete%20them%20with%20PowerShell.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20Regards%2C%3C%2FP%3E%3CP%3EBenjamin%20Pettinen%3C%2FP%3E%3CP%3EUniversity%20of%20Helsinki%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-806844%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
bepettinen
Occasional Visitor

We're testing the AutoPilot Reset as an easy way to reset devices between users as simply as possible. The reset itself is working, but after resetting and logging in, the Intune Maganament Extension / Engine service is missing from services. Configuration profiles still get applied (power settings, bitlocker, lock screen image etc), but powershell scripts don't run and Win32 apps don't get reinstalled after the reset. The apps and scripts are assigned to the same device groups as the configuration profiles that work and the device is autopilot registered with the self-deploying scenario. If I do a clean installation from Windows 10 Education ISO with autopilot enrollment the extension works properly and apps get installed.

 

The advanced diagnostic MDM report lists under Managed applications ONLY Modern Apps and the status of all of them is Failed. The Win32 apps are not listed in the report.

 

I'd like to be able to use the AutoPilot reset since compared to installing from ISO, wiping or fresh starting, it'll retain the Computer name which is a huge help not having to rename them by hand after resetting (I'm working at a university and we might reset 300 shared devices at a time before the new semester starts).

 

This problem only seems to affect the AutoPilot Reset. Doing a fresh start doesn't break the Intune Management Extension and everything works, BUT I have to rename the computers. It's also important for our dynamic groups that the devices have specific names, so using the serial/random name templates don't do for us.

 

@Michael Niehaus here I have to give a suggestion to Microsoft: Add the ability to force the device names from Intune or Azure AD in a way that reinstalled computers with the same serial number automatically get the old name if they have been registered in AAD/Intune earlier and have not been deleted. This should be possible since AutoPilot registered devices retain the AAD Device Object through clean installs and resets, once the hardware hashes have been imported.

 

Another suggestion: Automatically merge/replace Intune device objects with the same serial number at re-enrollment. Currently if I reinstall a computer, let's say, 10 times and it's autopilot registered, It'll appear in Intune 10 times even though it'll only appear in Azure AD once. I don't see the point having the device's old copies in Intune as they have no more effect after the AutoPilot enrollment creates a new device in Intune and attaches the computer to it. Currently I use the automatic deletion of devices not used in a while, but that still leaves the 300 duplicate laptops for at least three months lying around our MDM unless I manually delete them with PowerShell.

 

Kind Regards,

Benjamin Pettinen

University of Helsinki

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies