Jan 21 2022 06:08 AM - edited Jan 21 2022 06:10 AM
Hi all,
Within our organization, we’re implementing Microsoft Endpoint Manager to manage devices like laptops.
The situation is as followed: laptops are currently unmanaged and we’re trying to find a user-friendly way to enroll these laptops in MEM. Options to add a ‘Work or School account’ aren’t an option as users only have a ‘user account’ without admin rights. On the other hand, we’d like to take this opportunity to enroll a new (clean install) image with configurations and software from MEM.
After installing the OS with MDT and the offline JSON profile the device boots with the expected OOBE screen, ready to enroll in MEM. After entering the credentials the device is enrolled in AAD. Based on some rules the device is added to a dynamic group that is assigned to the ESP and configurations… probably AAD detects the membership too late which returns in a half-baked configuration.
We prefer to enroll without any manual interactions such as installing a provisioning package or running a PS-script from the OOBE-screen.
Any suggestions so devices will get their ESP and configuration profiles that are assigned to the group as pre-provisioning isn’t an option with offline Autopilot profiles?
Used resources:
https://docs.microsoft.com/en-us/mem/autopilot/existing-devices
Thanks in advance!
Jan 22 2022 07:46 AM
Jan 23 2022 12:10 PM
Jan 23 2022 09:17 PM - edited Jan 23 2022 09:18 PM
Dynamic groups do take time to get Intune config applied, specially for new members. I’m not surprised with this behavior.
Moe
Jan 24 2022 12:40 AM
Jan 24 2022 12:57 AM
Jan 25 2022 06:58 AM
Jan 25 2022 07:01 AM
Feb 08 2022 10:18 PM