Windows 10 Login Issue

%3CLINGO-SUB%20id%3D%22lingo-sub-752166%22%20slang%3D%22en-US%22%3EWindows%2010%20Login%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-752166%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3BHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20strange%20one%20here.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20set%20up%20auto%20enrollment%20of%20Windows%2010%20devices%20as%20per%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fquickstart-setup-auto-enrollment%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fquickstart-setup-auto-enrollment%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20seems%20to%20be%20fine%2C%20user%20can%20join%20Azure%20AD%20from%20W10%20settings%20screen%2C%20device%20enrolls%20in%20MDM%20OK.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20the%20user%20just%20doesn't%20seem%20to%20be%20able%20to%20login.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere's%20NO%20other%20options%20screen%20at%20login%20or%20Azure%20AD%20upn%20%2Fpassword%20gets%20rejected.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-752166%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-753652%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Login%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753652%22%20slang%3D%22en-US%22%3ENever%20had%20any%20issues%20with%20that.%20I%20suppose%20you%20have%20also%20enabled%20Azure%20AD%20join%20under%20device%20settings%20in%20Azure%20AD%20for%20the%20same%20group%3F%3CBR%20%2F%3E%3CBR%20%2F%3EDo%20you%20get%20AzureADJoined%3A%20YES%20if%20you%20run%20%22dsregcmd%20%2Fstatus%22%20as%20admin%3F%3CBR%20%2F%3EDo%20the%20devices%20show%20under%20devices%20in%20Azure%20AD.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-754356%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Login%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-754356%22%20slang%3D%22en-US%22%3E%3CBLOCKQUOTE%3E%3CHR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F364308%22%20target%3D%22_blank%22%3E%40jenstf%3C%2FA%3E%26nbsp%3Bwrote%3A%3CBR%20%2F%3ENever%20had%20any%20issues%20with%20that.%20I%20suppose%20you%20have%20also%20enabled%20Azure%20AD%20join%20under%20device%20settings%20in%20Azure%20AD%20for%20the%20same%20group%3FDo%20you%20get%20AzureADJoined%3A%20YES%20if%20you%20run%20%22dsregcmd%20%2Fstatus%22%20as%20admin%3FDo%20the%20devices%20show%20under%20devices%20in%20Azure%20AD.%3CHR%20%2F%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F364308%22%20target%3D%22_blank%22%3E%40jenstf%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20to%20all%20the%20above.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWorks%20fine%20via%20OOBE%20but%20when%20done%20via%20a%20live%2C%20up%20and%20running%20system%2C%20there%20is%20NO%20option%20to%20login%20as%20the%20Azure%20AD%20user%2C%20only%20local%20admin.%20Weird.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EInfo%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-754416%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Login%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-754416%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Esimple%20question%2C%20I%20assume%20you%20have%20done%20this%20right%20but%20just%20to%20make%20sure.%20Did%20you%20actually%20AADJ%20or%20maybe%20just%20a%20Workplace%20Join.%20The%20AADJ%20is%20not%20the%20obvious%20way.%20As%20said%20you%20probably%20did%20it%20right%20but%20to%20make%20sure%20the%20problem%20is%20not%20based%20on%20this%20simple%20fact%2C%20I%20want%20to%20outline%20how%20to%20proper%20AADJ%20a%20live%20system%20via%20settings.%20You%20have%20to%20use%20the%20lower%20hyperlink%20and%20not%20the%20obvious%20input%20field%20in%20the%20first%20place%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20815px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F123276iC7D6C88C16B2D1D7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22SNAG-0003.png%22%20title%3D%22SNAG-0003.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-755794%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Login%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-755794%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CBLOCKQUOTE%3E%3CHR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F174439%22%20target%3D%22_blank%22%3E%40Oliver%20Kieselbach%3C%2FA%3E%26nbsp%3Bwrote%3A%3CBR%20%2F%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Esimple%20question%2C%20I%20assume%20you%20have%20done%20this%20right%20but%20just%20to%20make%20sure.%20Did%20you%20actually%20AADJ%20or%20maybe%20just%20a%20Workplace%20Join.%20The%20AADJ%20is%20not%20the%20obvious%20way.%20As%20said%20you%20probably%20did%20it%20right%20but%20to%20make%20sure%20the%20problem%20is%20not%20based%20on%20this%20simple%20fact%2C%20I%20want%20to%20outline%20how%20to%20proper%20AADJ%20a%20live%20system%20via%20settings.%20You%20have%20to%20use%20the%20lower%20hyperlink%20and%20not%20the%20obvious%20input%20field%20in%20the%20first%20place%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20815px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F123276iC7D6C88C16B2D1D7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22SNAG-0003.png%22%20title%3D%22SNAG-0003.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3Ebest%2C%3C%2FP%3E%3CP%3EOliver%3C%2FP%3E%3CHR%20%2F%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F174439%22%20target%3D%22_blank%22%3E%40Oliver%20Kieselbach%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%2C%20the%20Azure%20AD%20Join%20method%20was%20selected.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStuart%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-755814%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Login%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-755814%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eafter%20logging%20in%20with%20the%20admin%2C%20did%20you%20check%20the%20event%20logs.%20not%20only%20system%20and%20applications%20also%20under%20Applications%20and%20Services%20logs%20%26gt%3B%20Microsoft%20%26gt%3B%20Windows%20%26gt%3B%20...%20there%20I%20would%20check%20AAD%20and%20DeviceManagement-Enterprise-Diagnostics-Provider%3C%2FP%3E%0A%3CP%3EIs%20the%20device%20correctly%20registered%20under%20Azure%20AD%20and%20Intune%20and%20has%20device%20objects%20after%20you%20enrolled%20it%20via%20Windows%20%26gt%3B%20Settings%3F%3C%2FP%3E%0A%3CP%3EIt%20seem%20that%20the%20process%20failed%20somehow%20but%20doesn't%20provide%20any%20feedback%20in%20form%20of%20an%20error%20message%2C%20but%20event%20logs%20should%20reveal%20the%20issue%20probably.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

 Hi All

 

A strange one here.

 

I have set up auto enrollment of Windows 10 devices as per:

 

https://docs.microsoft.com/en-us/intune/quickstart-setup-auto-enrollment

 

All seems to be fine, user can join Azure AD from W10 settings screen, device enrolls in MDM OK.

 

However the user just doesn't seem to be able to login.

 

There's NO other options screen at login or Azure AD upn /password gets rejected.

 

Any ideas?

 

5 Replies
Never had any issues with that. I suppose you have also enabled Azure AD join under device settings in Azure AD for the same group?

Do you get AzureADJoined: YES if you run "dsregcmd /status" as admin?
Do the devices show under devices in Azure AD.

@jenstf wrote:
Never had any issues with that. I suppose you have also enabled Azure AD join under device settings in Azure AD for the same group?

Do you get AzureADJoined: YES if you run "dsregcmd /status" as admin?
Do the devices show under devices in Azure AD.

@jenstf 

 

Yes to all the above.

 

Works fine via OOBE but when done via a live, up and running system, there is NO option to login as the Azure AD user, only local admin. Weird.

 

Info appreciated

Hey @Stuart King,

 

simple question, I assume you have done this right but just to make sure. Did you actually AADJ or maybe just a Workplace Join. The AADJ is not the obvious way. As said you probably did it right but to make sure the problem is not based on this simple fact, I want to outline how to proper AADJ a live system via settings. You have to use the lower hyperlink and not the obvious input field in the first place:

SNAG-0003.png

best,

Oliver

 


@Oliver Kieselbach wrote:

Hey @Stuart King,

 

simple question, I assume you have done this right but just to make sure. Did you actually AADJ or maybe just a Workplace Join. The AADJ is not the obvious way. As said you probably did it right but to make sure the problem is not based on this simple fact, I want to outline how to proper AADJ a live system via settings. You have to use the lower hyperlink and not the obvious input field in the first place:

SNAG-0003.png

best,

Oliver


@Oliver Kieselbach 

 

Yes, the Azure AD Join method was selected.

 

Stuart

@Stuart King 

 

after logging in with the admin, did you check the event logs. not only system and applications also under Applications and Services logs > Microsoft > Windows > ... there I would check AAD and DeviceManagement-Enterprise-Diagnostics-Provider

Is the device correctly registered under Azure AD and Intune and has device objects after you enrolled it via Windows > Settings?

It seem that the process failed somehow but doesn't provide any feedback in form of an error message, but event logs should reveal the issue probably.

 

best,

Oliver

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies