Dec 28 2020 04:11 PM
We have windows 10 devices already AAD joined prior to configuring Intune.
When enrolling those devices into MDM, we get the following issues in MEM:
Registering a new device to the tenant works as expected, without the above issues.
How do we get our AAD joined devices to play along nicely with Intune MDM?
Dec 30 2020 06:05 AM
@roelheymansI think the best practice will be to enable the same user group to be able to join devices to Azure AD and also enroll them into intune...
I am not sure how you have done the setup is everyone allowed to join their devices to Azure AD and then what is the enrollment rule...
what I have done to make it easy have created a static Security group where I add manually users when they come on board... the same group is allowed on Azure that only this group can join devices to Azure, and in the Intune enrollment section the same group is allowed to enroll the devices into intune...
so this way once someone clicks on Add the devices to Azure Active Directory in the same process the device is joined to Azure AD and then enrolled into Intune...
Please let me know if you have anything else specific....
Dec 31 2020 06:02 AM
That is indeed the way we have set it up and it works for new devices.
However, devices already AAD joined before MDM was configured, end up partially configured with no apparent way to correct it.