Forum Discussion
Orion-Skol
Mar 03, 2020Brass Contributor
Intune enrollment with Windows devices
We have every windows devices connected to Azure AD as shown below. I have AAD group (has test users for Intune test) enrolled in Intune as shown below. When i login as user (user is in use...
Thijs Lecomte
Mar 03, 2020Bronze Contributor
So the issue that automatic enrollment wasn't enabled when the computers AAD joined right?
Now you have enabled it and want to enroll.
I was thinking of deploying a provisioning package which might solve your issues. I am not 100% sure that would work, but as you don't have any way of mass deployment it, that's not an option.
I don't see any other way than re enrolling
Now you have enabled it and want to enroll.
I was thinking of deploying a provisioning package which might solve your issues. I am not 100% sure that would work, but as you don't have any way of mass deployment it, that's not an option.
I don't see any other way than re enrolling
Orion-Skol
Mar 03, 2020Brass Contributor
You might be right. But on my test, as soon as i disconnect and rejoined, it just works. What behavior changes? there got be something? Microsoft needs to invest some time here if they wants Intune to be management software for Cloud base company...
- Thijs LecomteMar 03, 2020Bronze ContributorHave you seen this?
https://docs.microsoft.com/en-us/windows/client-management/mdm/mdm-enrollment-of-windows-devices#connecting-to-mdm-using-a-deep-link- Orion-SkolMar 03, 2020Brass Contributor
correct me if i am wrong, doesn't it requires user to be local admin rights? we don't give local admin for users due to our compliance and security
- Thijs LecomteMar 03, 2020Bronze ContributorJup, that's right
So a manual action I required
- Thijs LecomteMar 03, 2020Bronze ContributorThat's because the user is added to the group for automatic enrollment now and that wasn't before.
It's the only explanation.
Automatic enrollment works really well and I haven't seen it malfunction- Orion-SkolMar 03, 2020Brass Contributor
i thought once you are already AAD joined and later you turn automatic enrollment on, devices should be in MDM...
- Thijs LecomteMar 03, 2020Bronze ContributorNo
That's not how it works
It only triggers it during AAD Join
So you need to manually MDM enroll
This can be done either through the deep links I posted above. Or through a registery edit: https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy
You should try creating a registery file, sending that to the users/helpdesk to execute