SOLVED

Hybrid Intune Migration for Apple DEP enabled Devices

%3CLINGO-SUB%20id%3D%22lingo-sub-277714%22%20slang%3D%22en-US%22%3EHybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277714%22%20slang%3D%22en-US%22%3E%3CP%3EIntune%20is%20currently%20configured%20in%20Hybrid%20mode%20with%20SCCM%20as%20a%20mgt%20authority%20for%20all%20devices.%20Intune%20Standalone%20configuration%20is%20in%20flight%20for%20pilot%20migration.%20Apple%20DEP%20has%20been%20integrated%20with%20Intune%20Standalone%20and%20Hybrid.%20However%2C%20Devices%20are%20not%20synchronised%20in%20standalone%20Intune%2C%20Sync%20option%20is%20disabled.%26nbsp%3B%20Enrollment%20Program%20Token%20is%20listed%20with%20warning%26nbsp%3B%3CA%20target%3D%22_blank%22%3E%3CSPAN%20class%3D%22fxs-blade-status-text%22%3EYou%20must%20configure%20these%20settings%20in%20the%20Configuration%20Manager%20console.%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%20style%3D%22width%3A%20622px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F58203i6BC9398B3F505DBA%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22image.png%22%20title%3D%22image.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22fxs-blade-status-text%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20451px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F58202i6A309407CDEA2384%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22image.png%22%20title%3D%22image.png%22%20%2F%3E%3C%2FSPAN%3E%5D%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22fxs-blade-status-text%22%3EIs%20there%20any%20way%20to%20force%20DEP%20sync%20prior%20to%20breaking%20Hybrid%20Intune%20setup%20%3F%20Idea%20is%20not%20test%20new%20user%2Fdevice%20migration%20before%20moving%20on%20existing%20users.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-277714%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281427%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281427%22%20slang%3D%22en-US%22%3E%3CP%3EConfirmed%20with%20MS%20Support%2C%20Microsoft%20have%20the%20design%20that%20DEP%20can%20only%20be%20managed%20by%20SCCM%20if%20the%20MDM%20authority%20is%20set%20as%20SCCM.%20MS%26nbsp%3B%20consider%20that%20if%20it%20can%20be%20managed%20by%20both%20SCCM%20and%20Intune%2C%20it%20will%20generate%20some%20conflicts%20and%20mis-operation.%20However%2C%20this%20is%20not%20the%20case%2C%20Apple%20DEP%20can%20have%20multiple%20MDM%20Server%20can%20run%20independently.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-281346%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-281346%22%20slang%3D%22en-US%22%3ECorrect.%20The%20tenant%20level%20settings%20are%20still%20managed%20by%20ConfigMgr%20until%20you%20switch%20the%20Authority%20to%20Intune.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278959%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278959%22%20slang%3D%22en-US%22%3E%3CP%3Ethanks%20for%20reply%2C%20It%20seems%20we%26nbsp%3B%20cannot%20sync%20DEP%20Devices%20in%20Intune%20standalone%20until%20MDM%20authority%20have%20been%20assigned%20to%20Intune.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278286%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278286%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EAs%20you%20are%20in%20Hybrid%20the%20DEP%20sync%20is%20initiated%20from%20Configuration%20Manager%20until%20you%20switch%20MDM%20authority.%20It%20is%20not%20a%20sync%20with%20ConfigMgr%20you%20are%20doing%20you%20are%20triggering%20a%20DEP%20Sync%20in%20Intune%20from%20SCCM%20as%20that%20is%20your%20MDM%20authority.%3C%2FP%3E%3CP%3ERegards%2C%3CBR%20%2F%3EJ%C3%B6rgen%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-277719%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277719%22%20slang%3D%22en-US%22%3E%3CP%3EConfigMgr%20Sync%20have%20no%20effect%20on%20Intune%20DEP%20sync%20!%26nbsp%3B%20as%20a%20result%20DEP%20devices%20will%20not%20be%20listed%20in%20Intune%20Standalone.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-277718%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277718%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EAs%20Configuration%20Manager%20is%20you%20MDM%20Authority%20you%20need%20to%20trigger%20the%20DEP%20Sync%20from%20there%2C%20here%20is%20an%20example%20on%20how%20to%20do%20just%20that%20%3CA%20href%3D%22https%3A%2F%2Fhiway65nblog.blogspot.com%2F2017%2F05%2Ftrigger-manual-dep-sync-with-powershell.html%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fhiway65nblog.blogspot.com%2F2017%2F05%2Ftrigger-manual-dep-sync-with-powershell.html%3C%2FA%3E%3C%2FP%3E%3CP%3ERegards%2C%3CBR%20%2F%3EJ%C3%B6rgen%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-706437%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-706437%22%20slang%3D%22en-US%22%3E%3CP%3EWhich%20one%20will%20be%20effective%2C%20in%20term%20of%20DEP%20program%20like%3A%20Intune%20or%20VMWare%20AirWatch..%3C%2FP%3E%3CP%3EAlso%20which%20are%20more%20effective%20like%3A%20Costing%2C%20Services%20etc..%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-709201%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-709201%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F323381%22%20target%3D%22_blank%22%3E%40Associate_Consultant%3C%2FA%3E%26nbsp%3BIntune%20or%20Airwatch%20are%20MDM%20solution%2C%20Apple%20Business%20Managed%20aka%20DEP%20is%20apple%20program%20for%20enterprises%20to%20deploy%20devices%20and%20apps.%20highly%20recommended%20to%20use%20Apple%20Business%20Manager%2FDEP%20not%20matter%20what%20MDM%20you%20use%20i.e.%20Intune%2FAirwatch%20to%20automatically%20add%20to%20MDM%20etc..%20Read%20more%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsupport.apple.com%2Fen-au%2Fguide%2Fapple-business-manager%2Fwelcome%2Fweb%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.apple.com%2Fen-au%2Fguide%2Fapple-business-manager%2Fwelcome%2Fweb%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-709581%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-709581%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F336519%22%20target%3D%22_blank%22%3E%40prtkdv%3C%2FA%3EThanks%20so%20much%20for%20information.%20If%20I%20asked%20help%20you%20about%20the%20architect%20design%20for%20the%20Intune%20DEP%20program%20for%2010K%20iPad%20devices%2C%20then%20could%20you%20help%20me%20with%20the%20details%20with%20design%20and%20contents%20please%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-720996%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Intune%20Migration%20for%20Apple%20DEP%20enabled%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-720996%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F323381%22%20target%3D%22_blank%22%3E%40Associate_Consultant%3C%2FA%3E%26nbsp%3Bplease%20send%20me%20private%20message%20to%20discuss%20further.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Intune is currently configured in Hybrid mode with SCCM as a mgt authority for all devices. Intune Standalone configuration is in flight for pilot migration. Apple DEP has been integrated with Intune Standalone and Hybrid. However, Devices are not synchronised in standalone Intune, Sync option is disabled.  Enrollment Program Token is listed with warning You must configure these settings in the Configuration Manager console. image.png

 

image.png]

 

Is there any way to force DEP sync prior to breaking Hybrid Intune setup ? Idea is not test new user/device migration before moving on existing users. 

10 Replies
Highlighted

Hi,

As Configuration Manager is you MDM Authority you need to trigger the DEP Sync from there, here is an example on how to do just that https://hiway65nblog.blogspot.com/2017/05/trigger-manual-dep-sync-with-powershell.html

Regards,
Jörgen

 

Highlighted

ConfigMgr Sync have no effect on Intune DEP sync !  as a result DEP devices will not be listed in Intune Standalone.

Highlighted

Hi,

As you are in Hybrid the DEP sync is initiated from Configuration Manager until you switch MDM authority. It is not a sync with ConfigMgr you are doing you are triggering a DEP Sync in Intune from SCCM as that is your MDM authority.

Regards,
Jörgen

Highlighted

thanks for reply, It seems we  cannot sync DEP Devices in Intune standalone until MDM authority have been assigned to Intune.

Highlighted
Correct. The tenant level settings are still managed by ConfigMgr until you switch the Authority to Intune.
Highlighted
Best Response confirmed by Pratik Dave (New Contributor)
Solution

Confirmed with MS Support, Microsoft have the design that DEP can only be managed by SCCM if the MDM authority is set as SCCM. MS  consider that if it can be managed by both SCCM and Intune, it will generate some conflicts and mis-operation. However, this is not the case, Apple DEP can have multiple MDM Server can run independently. 

Highlighted

Which one will be effective, in term of DEP program like: Intune or VMWare AirWatch..

Also which are more effective like: Costing, Services etc..

Highlighted

@Associate_Consultant Intune or Airwatch are MDM solution, Apple Business Managed aka DEP is apple program for enterprises to deploy devices and apps. highly recommended to use Apple Business Manager/DEP not matter what MDM you use i.e. Intune/Airwatch to automatically add to MDM etc.. Read more https://support.apple.com/en-au/guide/apple-business-manager/welcome/web

Highlighted

@prtkdvThanks so much for information. If I asked help you about the architect design for the Intune DEP program for 10K iPad devices, then could you help me with the details with design and contents please?

Highlighted

@Associate_Consultant please send me private message to discuss further.