Aug 21 2019 06:46 AM
Hi All
I have successfully setup Hybrid Azure AD Join and I have implemented Auto-enrollment into Intune via GPO.
However, on my test user(s) I'm still getting MDM status = None.
Can anyone tell me what the User eXperience should be for this type of Intune Enrollment?
Does the User get prompted to sign in or anything?
Info appreciated
Sep 05 2019 05:09 AM
@Stuart King Could you please share some more information about your setup?
When you set the gpo for device enrollment, the end machine will need to reboot and login. Once logged in, if you go to windows settings, you should see an info button on the work or school account which confirms that your machine is joined to Hybrid Azure AD.
Another way to check is to run the command dsregcmd /status.
More troubleshooting steps: https://docs.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-hybrid-join-windows-cur...
Sep 08 2019 01:53 PM
Yes, the machines are showing as Hybrid Azure AD Join but not as enrolled in Intune.
Stuart
Sep 09 2019 10:46 AM - edited Sep 09 2019 10:49 AM
@Stuart King I had similar issues with on my tenant where devices will show in Azure AD Devices as Hybrid Azure AD Join but not in All Devices and the MDM state is shown as none. The fix for my case was to set 2 GPO policy settings (As per MS Support, the first device registration policy adds the device to Azure AD and MDM part enrolls the device to intune, and we need to have both to get the devices fully managed via intune/MDM)
If you do not see the policy, it may be because you don’t have the ADMX installed for Windows 10, version 1803 or version 1809. To fix the issue, follow these steps:
Sep 09 2019 11:06 AM
That's very interesting, using the 2 GPO's.
I had that setup already, then removed the Device Registration one as I was advised that this was NOT needed for Hybrid Azure AD Join, as all domain devices register as Hybrid Azure AD Join once AADC has been configured this way.
I will re-implement the Device Registration policy and keep you posted.
Thanks again
Sep 11 2020 02:20 AM
My environment is as follows:-
On Premise AD
Hybrid Azure AD Joined devices using AD Connect
I was also facing the same situation where the status of the MDM was None rather than Microsoft Intune for my Windows 10 devices.
Ambarish I followed that extra step to Register domain joined computers as devices and now it seem to work. I would why this setting is needed given the device is already Hybrid Azure AD Joined?
Previously I did get this to work but only when the device was line of sight to my on premise AD. i.e. in the office. So I thought that was just the limitation of auto enrolment.
Because all my users are now WFH due for COVID I will need to try this with some other devices but it now looks more positive.
Sep 11 2020 03:13 AM - edited Sep 11 2020 03:18 AM
@Stuart King I have these problems every time. what I did is to run dsregcmd /status and see if the AzureADPRT value is NO. then if the value is NO, reboot the machine and login using the O365 account UPN (sample@contoso.com). It doesn't matter if it is the same with the on-premise AD UPN but you need to type the whole UPN name as login. It will create a new profile and then go to work or school account and click on info. Once all the progress is successful, run the dsregcmd /status command again and see if the AzureADPRT value has changed.
Note: do not run cmd as administrator if you are applying the policy per user basis not on per device.
Also check the task scheduler of the affected machine. A successful Hybrid-joined device will automatically create a scheduled task. Also, check the event viewer for errors.
Hope this helps.
Sep 11 2020 03:25 AM
@Chris Yue It is actually required as part of the GPO Policy for Hybrid-joined devices. It should be worth noting that when configuring GPO for devices, you only need to change Computer Config policies and never duplicate the same policy on the User Config.
Here's a preview of mine.
Sep 11 2020 04:28 AM
Thanks for the tip.
On the articles I have seen, I saw reference to Enable automatic MDM enrolment using default Azure Ad but not the device registration one.
Another thing I have noticed is the following.
Where a user picture has been assigned to Office 365, which is visible in office.com and mobile apps, should this appear on Windows 10 devices at the login screen?
I got this once, but since retiring the device and re-enrolling again, I don't see it anymore.
Sep 11 2020 04:39 PM
Sep 17 2020 12:40 PM
I recently had another instance where the AzureAdPrt was NO, an MS support agent gave me the following steps:
1) whoami /upn Run the command in commad prompt UPN should be same in cloud .
2) Add the URL in IE
· https://enterpriseregistration.windows.net
· https://login.microsoftonline.com
· https://device.login.microsoftonline.com
· https://autologon.microsoftazuread-sso.com
3) Open task scheduler(AS admin )> Microsoft>Windows> Work place join>right click on “Auto work place join” and make sure it is in “running” state.
4) Then re-start machine and run dsregcmd /status , check for Azure prt status.
5) dsregcmd /debug /leave in admin mode.
6) Once machine up run dsregcmd /debug /join in admin mode.