InTune Management Extension Service Problem!

%3CLINGO-SUB%20id%3D%22lingo-sub-968116%22%20slang%3D%22en-US%22%3EInTune%20Management%20Extension%20Service%20Problem!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-968116%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Community!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20currently%20working%20on%20an%20onboarding%20exercise%20for%20my%20Windows%2010%20device%20fleet%2C%20moving%20them%20away%20from%20an%20unmanaged%2C%20ad-hoc%20deployment%2C%20to%20an%20AAD%2FInTune%20managed%20deployment.%20My%20scenario%20is%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26gt%3B%20~1%2C000%20unmanaged%20Windows%2010%20devices%3C%2FP%3E%3CP%3E%26gt%3B%20Enrollment%20into%20InTune%20is%20done%20automatically%20once%20the%20user%20joins%20AAD%20(via%20Settings%20App%20%26gt%3B%20Accounts%26nbsp%3B%20Work%2FSchool%20Account)%3C%2FP%3E%3CP%3E%26gt%3B%20This%20is%20pure%20AAD%2FInTune%2C%20no%20hybrid%2Fon-prem%20AD%20involvement%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20my%20test%20machine%20(which%20is%20a%20brand%20new%20Windows%2010%201903%20install%2C%20I%20log%20in%20as%20the%20first%20admin%20user%20(local)%2C%20connect%20it%20to%20Azure%20AD%2C%20see%20it%20pop%20up%20in%20InTune%20(as%20managed%20by%20MDM)%20and%20my%20configuration%20profiles%20and%20applications%20that%20are%20scoped%20to%20the%20Azure%20AD%20security%20group%20-%20so%20that%20allworks%20fine.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20I%20cannot%20get%20my%20PowerShell%20script%20to%20deploy.%20After%20reading%20many%2C%20many%2C%20manyyyy%20blogs%2C%20forum%20posts%2C%20MS%20Docs%2C%20I%20am%20now%20very%20aware%20that%20for%20InTune%20to%20deploy%20PS%20scripts%2C%20that%20the%20InTune%20Management%20Extenstion%20needs%20to%20be%20present.%20So%20I%20started%20looking%20down%20that%20track.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20this%20machine%2C%20I%20cannot%20see%20any%20reference%20of%20the%20IME%20in%20Program%20Files%2C%20ProgramData%2C%20Start%20Menu%2C%20Programs%2FFeatures%20.....%20basically%20it%20seems%20as%20if%20it%20hasn't%20installed.%20However%2C%20looking%20in%20the%20registry%20(HKLM%5CSoftware%5CMicrosoft%5CEnterpriseDesktopAppManagement%5C%3CSID%3E%5CMSI%5C%3CGUID%3E%2C%20I%20am%20seeing%20Status%20as%2070%2C%20which%20according%20to%20other%20reading%2C%20imnplies%20that%20the%20agent%20is%20installed%20and%20enforcement%20is%20on.%20(Screenshot%201)%3C%2FGUID%3E%3C%2FSID%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20the%20same%20machine%2C%20I%20have%20tried%20to%20install%20the%20InTuneWindowsAgent.msi.%20The%20installation%20completes%2C%20but%20then%20uninstalls%20itself%20after%20a%20matter%20of%20seconds.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20few%20more%20side%20notes%3A%3C%2FP%3E%3CP%3E%26gt%3B%20The%20VM%20which%20I'm%20using%20to%20test%20on%20is%20Win%2010%201903%3C%2FP%3E%3CP%3E%26gt%3B%20It%20has%20been%20running%20for%20a%20few%20days%2C%20so%20should%20be%20plenty%20of%20time%20for%20InTune%20to%20do%20whatever%20it%20needs%20to%20do%3C%2FP%3E%3CP%3E%26gt%3B%20The%20PowerShell%20script%20runs%20fine%20when%20executed%20locally%3C%2FP%3E%3CP%3E%26gt%3B%20The%20script%20withi%20InTune%20is%20assigned%20to%20an%20AAD%20Security%20Group%20which%20contains%20users%3C%2FP%3E%3CP%3E%26gt%3B%20The%20are%20no%20installation%20errors%20within%20Event%20Log%20relating%20to%20WIndows%20being%20able%20to%20install%20the%20Extension%20(Screenshot%202).%20I%20do%20see%20successful%20MSI%20install%20logs%20(1901%2C%201904%2C%201905%2C%201906%2C%201920%20with%201922%20being%20the%20final%20success)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20would%20be%20greatly%20appreciated!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3EDave%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-968116%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-969884%22%20slang%3D%22en-US%22%3ERe%3A%20InTune%20Management%20Extension%20Service%20Problem!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-969884%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F437062%22%20target%3D%22_blank%22%3E%40chillidave19%3C%2FA%3E%26nbsp%3BDid%20you%20try%20to%20create%20CNAME%20in%20your%20DNS%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Visitor

Hello Community!

 

I am currently working on an onboarding exercise for my Windows 10 device fleet, moving them away from an unmanaged, ad-hoc deployment, to an AAD/InTune managed deployment. My scenario is:

 

> ~1,000 unmanaged Windows 10 devices

> Enrollment into InTune is done automatically once the user joins AAD (via Settings App > Accounts  Work/School Account)

> This is pure AAD/InTune, no hybrid/on-prem AD involvement

 

On my test machine (which is a brand new Windows 10 1903 install, I log in as the first admin user (local), connect it to Azure AD, see it pop up in InTune (as managed by MDM) and my configuration profiles and applications that are scoped to the Azure AD security group - so that allworks fine.

 

However, I cannot get my PowerShell script to deploy. After reading many, many, manyyyy blogs, forum posts, MS Docs, I am now very aware that for InTune to deploy PS scripts, that the InTune Management Extenstion needs to be present. So I started looking down that track.

 

On this machine, I cannot see any reference of the IME in Program Files, ProgramData, Start Menu, Programs/Features ..... basically it seems as if it hasn't installed. However, looking in the registry (HKLM\Software\Microsoft\EnterpriseDesktopAppManagement\<SID>\MSI\<GUID>, I am seeing Status as 70, which according to other reading, imnplies that the agent is installed and enforcement is on. (Screenshot 1)

 

On the same machine, I have tried to install the InTuneWindowsAgent.msi. The installation completes, but then uninstalls itself after a matter of seconds.

 

A few more side notes:

> The VM which I'm using to test on is Win 10 1903

> It has been running for a few days, so should be plenty of time for InTune to do whatever it needs to do

> The PowerShell script runs fine when executed locally

> The script withi InTune is assigned to an AAD Security Group which contains users

> The are no installation errors within Event Log relating to WIndows being able to install the Extension (Screenshot 2). I do see successful MSI install logs (1901, 1904, 1905, 1906, 1920 with 1922 being the final success)

 

Any help would be greatly appreciated!

 

Cheers,

Dave

 

1 Reply

@chillidave19 Did you try to create CNAME in your DNS ?