Change Enrolled User

%3CLINGO-SUB%20id%3D%22lingo-sub-364166%22%20slang%3D%22en-US%22%3EChange%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-364166%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20currently%20have%20a%26nbsp%3B%20Windows%2010%20Desktop%20Device%26nbsp%3BEnrolled%20in%20Intune%20that%20was%20enrolled%20by%20a%20user%20that%20is%20not%20exists%20anymore.%20Therefore%20the%20device%20is%20now%20marked%20as%20non-compliant%20by%20the%20built-in%20compliancy%20policy%20because%20of%20the%20%22Enrolled%20user%20exists%22%20check.%20How%20can%20we%20change%20the%20Enrolled%20User%20without%20re-installing%20the%20device%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tried%20to%20change%20the%20Registered%20User%20and%20Owner%20with%26nbsp%3BAdd-AzureADDeviceRegisteredOwner%26nbsp%3Band%26nbsp%3BAdd-AzureADDeviceRegisteredUser%2C%20but%20this%20is%20not%20working%20as%20expected.%20Is%20there%20another%20way%20to%20achieve%20this%20or%20do%20we%20need%20to%20re-enroll%20the%20device%3F%20If%20the%20answer%20is%20yes%2C%20what%20is%20the%20best%20way%3F%20Initiate%20a%20Fresh%20Start%20or%20AutoPilot%20Reset%20(Preview)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-364166%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-401019%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-401019%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F31473%22%20target%3D%22_blank%22%3E%40Angelo%20Lelieveld%3C%2FA%3E%26nbsp%3BThe%20enrollment%20user%20is%20the%20device%20owner%20in%20intune.%20AAD%20owner%20doesn't%20have%20any%20impact%20on%20the%20Intune%20side.%20Intune%20device%20belongs%20to%20the%20enrollment%20owner.%20If%20you%20want%20to%20change%20that%20you%20must%20do%20a%20factory%20reset.%20Fresh%20start%20is%20not%20necessary%20as%20this%20will%20try%20to%20remove%20bloatware%20as%20well.%20as%20long%20as%20you%20have%20signature%20edition%20or%20provisioning%20ready%20Windows%2010%20devices%20you%20shuld%20be%20fine%20with%20a%20factory%20reset%20and%20the%20new%20user%20enroll's%20the%20device%20and%20will%20be%20the%20new%20onwer%20in%20Intune.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-397259%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-397259%22%20slang%3D%22en-US%22%3EFor%20Remote_%20You%20can%20use%20Autopilot%20Reset%20(preview)%3CBR%20%2F%3EOn-site%3A%20You%20find%20the%20device%20inside%20intune%20press%20%22delete%22%20and%20use%20following%20with%20%22other%20user%22%20inside%20windows%20%26gt%3B%20Settings%20%26gt%3B%20Recovery%20%26gt%3B%20Remove%20Everything.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1125770%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1125770%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F439394%22%20target%3D%22_blank%22%3E%40Dartey_Banahene%3C%2FA%3E%26nbsp%3B%20Does%20the%20user%20account%20still%20have%20the%20same%20AAD%20ObjectID%20it%20had%20before%20it%20was%20restored%3F%20If%20it's%20different%2C%20this%20is%20probably%20the%20cause%20of%20the%20issue.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1125275%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1125275%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F174439%22%20target%3D%22_blank%22%3E%40Oliver%20Kieselbach%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20if%20it%20shows%20that%20the%20user%20does%20exist%3F%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20for%20some%20reason%2C%20the%20users%200365%20account%20was%20deleted%20last%20night.%20I%20restored%20it%20this%20morning.%20But%20after%20running%20a%20sync%20in%20InTune%20the%20device%20is%20still%20coming%20back%20as%20Not%20Compliant%20even%20though%20the%20user%20who%20registered%20the%20device%20is%20active%20and%20the%20one%20logged%20into%20the%20device.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1125780%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1125780%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F254026%22%20target%3D%22_blank%22%3E%40eglockling%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20that%2C%20I'll%20check%20that!%20That%20makes%20perfect%20sense%20if%20that%20is%20the%20case.%20Just%20curious%20how%20would%20I%20know%20what%20the%20old%20one%20was%3F%20Is%20there%20some%20type%20of%20log%20file%20I%20can%20pull%20up%3F%3C%2FP%3E%3CP%3EThanks%20again%20for%20the%20quick%20response.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1125855%22%20slang%3D%22en-US%22%3ERe%3A%20Change%20Enrolled%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1125855%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F439394%22%20target%3D%22_blank%22%3E%40Dartey_Banahene%3C%2FA%3E%26nbsp%3B%20I've%20never%20had%20to%20do%20this%2C%20solely%20being%20an%20Intune%20administrator%2C%20but%20check%20out%20this%20support%20article%20from%20Microsoft.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-ca%2Fhelp%2F2619308%2Fhow-to-troubleshoot-deleted-user-accounts-in-office-365-azure-and-intu%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-ca%2Fhelp%2F2619308%2Fhow-to-troubleshoot-deleted-user-accounts-in-office-365-azure-and-intu%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

 

We currently have a  Windows 10 Desktop Device Enrolled in Intune that was enrolled by a user that is not exists anymore. Therefore the device is now marked as non-compliant by the built-in compliancy policy because of the "Enrolled user exists" check. How can we change the Enrolled User without re-installing the device?

 

I tried to change the Registered User and Owner with Add-AzureADDeviceRegisteredOwner and Add-AzureADDeviceRegisteredUser, but this is not working as expected. Is there another way to achieve this or do we need to re-enroll the device? If the answer is yes, what is the best way? Initiate a Fresh Start or AutoPilot Reset (Preview)?

 

Thanks

 

7 Replies
For Remote_ You can use Autopilot Reset (preview)
On-site: You find the device inside intune press "delete" and use following with "other user" inside windows > Settings > Recovery > Remove Everything.

@Angelo Lelieveld The enrollment user is the device owner in intune. AAD owner doesn't have any impact on the Intune side. Intune device belongs to the enrollment owner. If you want to change that you must do a factory reset. Fresh start is not necessary as this will try to remove bloatware as well. as long as you have signature edition or provisioning ready Windows 10 devices you shuld be fine with a factory reset and the new user enroll's the device and will be the new onwer in Intune.

@Oliver Kieselbach 

What if it shows that the user does exist? 

So for some reason, the users 0365 account was deleted last night. I restored it this morning. But after running a sync in InTune the device is still coming back as Not Compliant even though the user who registered the device is active and the one logged into the device.

@Dartey_Banahene  Does the user account still have the same AAD ObjectID it had before it was restored? If it's different, this is probably the cause of the issue.

@eglockling 

Thank you for that, I'll check that! That makes perfect sense if that is the case. Just curious how would I know what the old one was? Is there some type of log file I can pull up?

Thanks again for the quick response. 

@Dartey_Banahene  I've never had to do this, solely being an Intune administrator, but check out this support article from Microsoft. https://support.microsoft.com/en-ca/help/2619308/how-to-troubleshoot-deleted-user-accounts-in-office...

@eglockling 

You rock! Again thank you for all of your help. I'm just kicking off a project to get rid of our environments Physical Domain Controller. Very exciting stuff, but I'll give the docs a gander and see what happens. I'll update the thread with what I find.