Home

Windows Autopilot Hybrid Azure AD join fails

%3CLINGO-SUB%20id%3D%22lingo-sub-360324%22%20slang%3D%22en-US%22%3EWindows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-360324%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20my%20fellow%20engineers%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAutopilot%20Hybrid%20Azure%20AD%20join%20used%20to%20work%20fine%20in%20our%20environment%20but%20since%2002%2F22%20we%20are%20unable%20to%20make%20it%20work%20consistently.%3C%2FP%3E%3CP%3EOnce%20the%20user%20provide%20its%20credentials%20the%20device%20gets%20stuck%20at%20%E2%80%9CPlease%20wait%20while%20we%20configure%20your%20device%E2%80%9D%20for%2025%20minutes%20then%20it%20displays%20an%20error%20code%2080070774%2C%20those%2025%20minutes%20mean%20the%20device%20was%20unable%20to%20join%20the%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20reboot%20we%20notice%20the%20device%20keeps%20its%20default%20name%2C%20instead%20of%20applying%20the%20one%20configured%20in%20our%20Intune%20Domain%20Join%20profile%2C%20and%20appears%20in%20the%20Intune%20console%20but%20neither%20in%20Azure%20AD%20nor%20in%20ADDS.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20checked%20the%20whole%20workflow%20provided%20by%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F21544%22%20target%3D%22_blank%22%3E%40Michael%20Niehaus%3C%2FA%3E%26nbsp%3Bin%20his%20%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fmniehaus%2F2018%2F11%2F22%2Ftrying-out-windows-autopilot-user-driven-hybrid-azure-ad-join%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eblog%20post%3C%2FA%3E%20and%20we%20deducted%20the%20Intune%20ODJ%20Connector%20service%20never%20gets%20the%20Intune%20request%20for%20the%20ODJ%20Blob%20as%20there%20are%20no%20other%20events%20than%2030121%20and%2030150%20within%20the%20ODJ%20Connector%20service%20event%20logs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20uninstalled%20and%20reinstalled%20our%20Intune%20Connector%20but%20Hybrid%20AAD%20join%20still%20does%20not%20work%20even%20if%20the%20service%20seems%20healthy.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20also%20checked%20our%20Intune%20Domain%20Join%20configuration%20profile%20and%20everything%20is%20OK%2C%20the%20delegation%20is%20correctly%20applied%20to%20the%20target%20OU.%3CBR%20%2F%3EOne%20more%20thing%20to%20notice%2C%20we%20don%E2%80%99t%20know%20if%20it%20is%20related%20but%20we%20set%20up%20an%20Express%20Route%20and%20created%20our%20first%20Server%202016%20DC%20in%20Azure%20(IaaS)%20on%2002%2F22.%20Our%20network%20team%20checked%20the%20route%20and%20firewall%20logs%20but%20didn't%20see%20anything.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20can%20provide%20the%20Autopilot%20and%20Device%20Management%20event%20logs%20from%20a%20failing%20device%20as%20well%20as%20the%20Intune%20Connector%20Service%20event%20logs%20from%20the%20server%20if%20needed.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20have%20a%20Premier%20ticket%20opened%20but%20if%20you%20have%20any%20idea...%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-360324%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-364687%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-364687%22%20slang%3D%22en-US%22%3EThose%20operations%20take%20time%2C%20we%20lose%20all%20the%20benefits%20of%20Autopilot%20deployment%20if%20we%20have%20to%20perform%20such%20actions%20every%20time%20we%20have%20to%20repurpose%20a%20device.%3CBR%20%2F%3EFor%20the%20moment%20it%20still%20works%20fine%2C%20the%20only%20thing%20I%20do%20is%20deleting%20computer%20object%20from%20ADDS%20during%20wipe.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-364657%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-364657%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3EI've%20observed%20this%20behaviour%20before%2C%20I%20found%20that%20if%20I%20rebuilt%20an%20existing%20device%20(already%20built%20by%20Autopilot)%20it%20would%20fail%20to%20get%20the%20Hybrid%20Join%20configuration%20policy%20(dynamic%20group%20membership%20issue%20I%20think).%26nbsp%3B%20I%20now%20completely%20delete%20the%20device%20from%20Intune%20and%20AAD%20every%20time%20I%20rebuild%2C%20including%20removing%20the%20HWID.%26nbsp%3B%20Then%20re-import%20the%20HWID.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-363941%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-363941%22%20slang%3D%22en-US%22%3E%3CP%3EStrange%2C%20let%20us%20know%20what%20it%20ended%20up%20being%20if%20you%20figure%20it%20out.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-363716%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-363716%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20turns%20out%20everything%20went%20back%20to%20normal.%20We%20don't%20know%20why%20yet%20but%20I'll%20update%20this%20thread%20with%20my%20findings.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-799819%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-799819%22%20slang%3D%22en-US%22%3E%3CP%3EUnfortunately%20it%20still%20does%20not%20work...%3C%2FP%3E%3CP%3EPremier%20support%20has%20no%20idea%20why%20it%20is%20failing%2C%20I'm%20going%20crazy!%3C%2FP%3E%3CP%3EThis%20week-end%20we%20found%20out%20if%20we%20launch%20an%20Hybrid%20Autopilot%20process%2C%20let%20it%20fail%20once%20the%2025%20minutes%20timeout%20happens%20(0x80070774)%20then%20wait%2024%20hours%20the%20machine%20becomes%20domain%20joined!%20But%20I%20still%20have%20to%20reset%20it%20since%20the%20autopilot%20process%20failed...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBoth%20ADDS%20computer%20object%20%22whencreated%22%20property%20and%20the%20ODJConnector%26nbsp%3Bevent%20IDs%20(30130%20%2B%26nbsp%3B%2030140)%20show%20that%20it%20happened%2024%20hours%20later%2C%2024%20hours%20too%20late...%20Why%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20can%20get%20rid%20of%20it%3F%20Any%20idea%3F%20%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F21544%22%20target%3D%22_blank%22%3E%40Michael%20Niehaus%3C%2FA%3E%26nbsp%3Bmaybe%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-811229%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-811229%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F200496%22%20target%3D%22_blank%22%3E%40Mathieu%20A%C3%AFt%20Azzouz%C3%A8ne%3C%2FA%3E%26nbsp%3BI%20believe%20I%20came%20across%20a%20similar%20issue%20that%20was%20resolved%20by%20updating%20the%20version%20of%20Windows%20I%20had%20on%20my%20USB%20stick.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDownloaded%20the%20latest%201903%20ISO%20and%20flashed%20to%20USB%20with%20the%20media%20creation%20tool%2C%20then%20reinstalled%20on%20the%20device%2C%20deleted%20HWID%20and%20reuploaded%2C%20then%20it%20seemed%20to%20work%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-814383%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-814383%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F329754%22%20target%3D%22_blank%22%3E%40nitvit610%3C%2FA%3Ethank%20you%20for%20your%20reply.%3C%2FP%3E%3CP%3EWe%20already%20tried%20to%20delete%20the%20HWID%20then%20reupload%20it%2C%20sometimes%20it%20works%2C%20sometimes%20not.%3C%2FP%3E%3CP%3EWe%20use%20the%20latest%201809%20ISO%20from%20MSDN%2C%20not%201903%2C%20and%20it%20used%20to%20work%20perfectly%20for%20months%20before%20it%20started%20to%20fail%20randomly.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-951793%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20fails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-951793%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20was%20all%20about%20the%20ping...%20a%20few%20DCs%20were%20implemented%20in%20Azure%20with%20ICMP%20echo%20blocked%20from%20our%20on-prem%20network.%20Hope%20this%20will%20help%20others%3C%2FP%3E%3C%2FLINGO-BODY%3E
Mathieu Aït Azzouzène
Occasional Contributor

Hi my fellow engineers,

 

Autopilot Hybrid Azure AD join used to work fine in our environment but since 02/22 we are unable to make it work consistently.

Once the user provide its credentials the device gets stuck at “Please wait while we configure your device” for 25 minutes then it displays an error code 80070774, those 25 minutes mean the device was unable to join the domain.

 

After reboot we notice the device keeps its default name, instead of applying the one configured in our Intune Domain Join profile, and appears in the Intune console but neither in Azure AD nor in ADDS.

 

We checked the whole workflow provided by @Michael Niehaus in his blog post and we deducted the Intune ODJ Connector service never gets the Intune request for the ODJ Blob as there are no other events than 30121 and 30150 within the ODJ Connector service event logs.

 

We uninstalled and reinstalled our Intune Connector but Hybrid AAD join still does not work even if the service seems healthy.

 

We also checked our Intune Domain Join configuration profile and everything is OK, the delegation is correctly applied to the target OU.
One more thing to notice, we don’t know if it is related but we set up an Express Route and created our first Server 2016 DC in Azure (IaaS) on 02/22. Our network team checked the route and firewall logs but didn't see anything.

 

I can provide the Autopilot and Device Management event logs from a failing device as well as the Intune Connector Service event logs from the server if needed.

 

I have a Premier ticket opened but if you have any idea...

 

Thanks

8 Replies

It turns out everything went back to normal. We don't know why yet but I'll update this thread with my findings.

Strange, let us know what it ended up being if you figure it out.

Hi

I've observed this behaviour before, I found that if I rebuilt an existing device (already built by Autopilot) it would fail to get the Hybrid Join configuration policy (dynamic group membership issue I think).  I now completely delete the device from Intune and AAD every time I rebuild, including removing the HWID.  Then re-import the HWID.  

 

Regards

 

 

 

Those operations take time, we lose all the benefits of Autopilot deployment if we have to perform such actions every time we have to repurpose a device.
For the moment it still works fine, the only thing I do is deleting computer object from ADDS during wipe.

Unfortunately it still does not work...

Premier support has no idea why it is failing, I'm going crazy!

This week-end we found out if we launch an Hybrid Autopilot process, let it fail once the 25 minutes timeout happens (0x80070774) then wait 24 hours the machine becomes domain joined! But I still have to reset it since the autopilot process failed...

 

Both ADDS computer object "whencreated" property and the ODJConnector event IDs (30130 +  30140) show that it happened 24 hours later, 24 hours too late... Why?

 

How can get rid of it? Any idea? @Michael Niehaus maybe?

@Mathieu Aït Azzouzène I believe I came across a similar issue that was resolved by updating the version of Windows I had on my USB stick.

 

Downloaded the latest 1903 ISO and flashed to USB with the media creation tool, then reinstalled on the device, deleted HWID and reuploaded, then it seemed to work 

@nitvit610thank you for your reply.

We already tried to delete the HWID then reupload it, sometimes it works, sometimes not.

We use the latest 1809 ISO from MSDN, not 1903, and it used to work perfectly for months before it started to fail randomly.

Hi all,

 

It was all about the ping... a few DCs were implemented in Azure with ICMP echo blocked from our on-prem network. Hope this will help others

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies