Intune enrollment creates new Azure AD object

%3CLINGO-SUB%20id%3D%22lingo-sub-2603732%22%20slang%3D%22en-US%22%3EIntune%20enrollment%20creates%20new%20Azure%20AD%20object%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2603732%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20we%20have%20Azure%20AD%20Hybrid%20joined%20devices%2C%20we%20want%20to%20enroll%20them%20to%20Intune.%20Upon%20testing%20with%20a%20subset%20of%20devices%2C%20we%20observe%20that%20intune%20enrolled%20devices%20become%20duplicates%20with%20their%20own%2Fnew%20object%20ID.%20Is%20this%20by%20design%2C%20or%20some%20configuration%20issue%3F%20See%20sample%20screenshot%20belov.%20Ruslan%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22RNalivaika_0-1627987020031.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F300125i73E16D6ACCF0CA44%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22RNalivaika_0-1627987020031.png%22%20alt%3D%22RNalivaika_0-1627987020031.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2603732%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2604034%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20creates%20new%20Azure%20AD%20object%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2604034%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F366140%22%20target%3D%22_blank%22%3E%40RNalivaika%3C%2FA%3E%26nbsp%3Blaunch%20dsregcmd%20%2Fstatus%20on%20one%20of%20the%20clients%20and%20take%20a%20look%20for%20the%20PRT%20(primary%20refresh%20token).%20Also%2C%20are%20you%20scoping%20users%20for%20auto%20enrollment%3F%20As%20soon%20as%20you%20HAADJ%20devices%20and%20use%20the%20WPJ%20options%20for%20the%20intune%20enrollment%2C%20this%20issue%20may%20happen.%20We%20encountered%20the%20same.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2604735%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20creates%20new%20Azure%20AD%20object%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2604735%22%20slang%3D%22en-US%22%3EHi%2C%20how%20long%20did%20you%20wait%20after%20you%20have%20noticed%20this%3F%20I%20have%20seen%20it%20in%20the%20past%20a%20couple%20times%20but%20the%20next%20day%20the%20were%20somehow%20%22merged%22%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2606508%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20creates%20new%20Azure%20AD%20object%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2606508%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1007564%22%20target%3D%22_blank%22%3E%40Henrixx%3C%2FA%3E%26nbsp%3Bdo%20you%20mean%20this%20PRT%3F%3CBR%20%2F%3EAzureAdPrt%20%3A%20YES%3CBR%20%2F%3EAzureAdPrtUpdateTime%20%3A%202021-08-03%2018%3A25%3A21.000%20UTC%3CBR%20%2F%3EAzureAdPrtExpiryTime%20%3A%202021-08-17%2018%3A25%3A30.000%20UTC%3CBR%20%2F%3EAzureAdPrtAuthority%20%3A%20%3CA%20href%3D%22https%3A%2F%2Flogin.microsoftonline.com%2Ff4b9822c-3c52-41ba-85d0-c9fc9ef75aa9%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Flogin.microsoftonline.com%2Ff4b9822c-3c52-41ba-85d0-c9fc9ef75aa9%3C%2FA%3E%3CBR%20%2F%3EEnterprisePrt%20%3A%20NO%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20use%26nbsp%3BMDM%20user%20scope%20with%20a%20group%20containing%20the%20pilot%20users%20who%20use%20the%20machines%20we%20want%20to%20enroll.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi, we have Azure AD Hybrid joined devices, we want to enroll them to Intune. Upon testing with a subset of devices, we observe that intune enrolled devices become duplicates with their own/new object ID. Is this by design, or some configuration issue? See sample screenshot belov. Ruslan

 

RNalivaika_0-1627987020031.png

 

7 Replies

@RNalivaika launch dsregcmd /status on one of the clients and take a look for the PRT (primary refresh token). Also, are you scoping users for auto enrollment? As soon as you HAADJ devices and use the WPJ options for the intune enrollment, this issue may happen. We encountered the same.

Hi, how long did you wait after you have noticed this? I have seen it in the past a couple times but the next day the were somehow "merged"

@Henrixx do you mean this PRT?
AzureAdPrt : YES
AzureAdPrtUpdateTime : 2021-08-03 18:25:21.000 UTC
AzureAdPrtExpiryTime : 2021-08-17 18:25:30.000 UTC
AzureAdPrtAuthority : https://login.microsoftonline.com/f4b9822c-3c52-41ba-85d0-c9fc9ef75aa9
EnterprisePrt : NO

We use MDM user scope with a group containing the pilot users who use the machines we want to enroll.

we've waited for 6 days now, but the devices are still duplicate.. I've heard before about devices merging after a day or two, I wonder what triggers it or what can cause the merging fail...
Thanks, so you got the PRT - thats good.
Next, lets check some additional questions:
- how do you perform the HAADJ? Manually or using a GPO? -if a GPO is used, are you using MDM (Device Credentials or User Credentials)?
- I guess you are using mail as UPN?
- If you check Intune, do you see these devices as corp enrolled or personal enrolled?
- What OS are you on? especially the PCs you use for the pilot?

@Henrixx thanks for following up. Devices are HAAD joined using Azure AD Connect device sync.

Yes, UPN used for login to O365 is the same as primary SMTP.

In intune, these devices first appear as personal, I change them to corporate owned. This is probably because pilot users enrolled them using logon to work or school.

We are on Windows 10 20H2 and 21H1. BR- Ruslan

the AAD connect will only create the Object in AAD. Its sitting in a pending status until you tell the Computer to do the hybrid join. Through GPO or dsregcmd /join command.

The second info, is kinda what I referred to regarding mdm auto enrollment. Using Work or school account will just cause what you are experiencing right now. There is a chance that the objects in AAD will merge themselves over a couple days, but doesnt have to, and there is no way you can force that.