unable to logon to the Intune Device

%3CLINGO-SUB%20id%3D%22lingo-sub-1190378%22%20slang%3D%22en-US%22%3Eunable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1190378%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EHi%2C%20we%20have%20some%20users%20who%20are%20unable%20to%20logon%20to%20their%20Intune%20Azure%20AD%20joined%20devices%20(Win%2010).%20When%20entering%20password%20it%20says%20%22Password%20Incorrect%22.%20Same%20password%20works%20fine%20when%20they%20logon%20to%20the%20Office%20365%20on%20different%20computer.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EIn%20Intune%20portal%2C%20Devices%20tab%20shows%20that%20device%20as%3CBR%20%2F%3EEnabled%20Yes%3CBR%20%2F%3EAzure%20AD%20Joined%3CBR%20%2F%3EMDM%20None%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3ENot%20sure%20how%2C%20but%20the%20MDM%20normally%20says%20%22Microsoft%20Intune%22%20and%20these%20users%2Fdevices%20has%20%22None%22.%3CBR%20%2F%3EThese%20users%20cannot%20logon%20to%20the%20device%20and%20also%20it%20doesn't%20gives%20me%20an%20option%20to%20logon%20as%20other%20user.%20Not%20sure%20what%20to%20do%20beside%20wiping%20it%20OR%20Is%20there%20a%20way%20I%20can%20manually%20add%20this%20device%20as%20Intune%20managed%20from%20the%20Azure%20Portal%20%3F%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EAny%20help%20would%20be%20much%20appreciated%2C%20thank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1190378%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1191011%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1191011%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103721%22%20target%3D%22_blank%22%3E%40Abinash%20RGS%20ICT%20-%20Hotmail%3C%2FA%3Eif%20the%20MDM%20is%20%3CEM%3Enone%3C%2FEM%3E%20there's%20probably%20something%20wrong%20with%20the%20Intune%20Auto%20Enrollment.%20For%20this%20to%20work%20correctly%2C%20your%20MDM%20User%20scope%20should%20be%20configured%20correct%20-%20can%20you%20check%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fenrollment%2Fquickstart-setup-auto-enrollment%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fenrollment%2Fquickstart-setup-auto-enrollment%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1191053%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1191053%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F530025%22%20target%3D%22_blank%22%3E%40Jente_V%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20sure%20if%20it%20is%20related%20to%20the%20MDM%20User%20Scope%20because%20I%20have%20successfully%20enrolled%20few%20Windows%20devices%20today.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMDM%20none%20is%20happening%20on%20few%20devices.%26nbsp%3B%3CSPAN%3EThese%20devices%20appears%20on%20%22Azure%20AD%20Devices%22%20but%20not%20on%20%22All%20Devices%22.%26nbsp%3B%20Windows%20Enrolment%20%26gt%3B%26gt%3B%20Devices%20%26gt%3B%26gt%3B%20Serial%20number%20of%20device%20says%20Not%20Enrolled%20for%20the%20Enrolment%20State.%20Is%20there%20a%20way%20to%20re-enroll%20them%20without%20losing%20the%20data%20on%20the%20device%20%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20what%20we%20have%20for%20the%20MDM%20User%20Scope%3C%2FP%3E%3CP%3Escreenshot%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fi.snipboard.io%2F7W3DUw.jpg%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fi.snipboard.io%2F7W3DUw.jpg%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1191060%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1191060%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103721%22%20target%3D%22_blank%22%3E%40Abinash%20RGS%20ICT%20-%20Hotmail%3C%2FA%3ESince%20your%20MDM%20user%20scope%20is%20set%20to%20%3CEM%3Eall%3C%2FEM%3E%20it%20should%20be%20ok.%20There%20is%20something%20else%20you%20should%20check%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIntune%20Portal%20%26gt%3B%20Device%20Enrollment%20%26gt%3B%20Windows%20Enrollment%20%26gt%3B%20CNAME%20Validation.%3C%2FP%3E%3CP%3Eenter%20your%20domain%20and%20test%20if%20it's%20successfull.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESadly%2C%20there%20is%20no%20%3CEM%3Eofficial%3C%2FEM%3E%20way%20to%20re-enroll%20your%20device%20without%20losing%20your%20profile%20(remove%20from%20Azure%20AD%20%26amp%3B%20add%20again)%20-%20that%20I%20know%20off.%20You%20won't%20loose%20the%20data%2C%20you%20just%20start%20with%20a%20clean%20profile%20(you%20can%20copy%20it%20manually%20after%20re-enrolling).%20I'm%20not%20sure%20if%20this%20still%20works%2C%20but%20you%20can%20try%20downloading%20the%20Company%20Portal%20App%20and%20see%20what%20information%20this%20gives.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1191492%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1191492%22%20slang%3D%22en-US%22%3ECNAME%20test%20says%20it%20is%20configured%20successfully.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20I%20do%20Shift%2BRestart%20%26gt%3B%26gt%3B%20Troubleshoot%20%26gt%3B%26gt%3B%20Reset%20this%20PC%20%26gt%3B%26gt%3B%20Keep%20my%20files%20%26gt%3B%26gt%3B%20reboot%20then%20re-enrol%20with%20the%20same%20user%2C%20will%20this%20let%20me%20keep%20the%20existing%20files%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1192321%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1192321%22%20slang%3D%22en-US%22%3EHi%20Abinash%2C%3CBR%20%2F%3E%3CBR%20%2F%3ECould%20you%20login%20to%20the%20devices%20with%20your%20Global%20Admin%20account%3F%20Try%20to%20access%20the%20pc%20locally%20and%20check%20if%20the%20pc%20if%20enrolled%20correctly.%20I%E2%80%99m%20interest%20in%20going%20to%20Work%20and%20School%20account%20and%20force%20Sync%20to%20Intune.%3CBR%20%2F%3E%3CBR%20%2F%3EThanks!%3CBR%20%2F%3EMoe%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1192639%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1192639%22%20slang%3D%22en-US%22%3EHi%20Abinash%20-%20I'm%20not%20sure%20about%20this.%20The%20worst%20that%20could%20happen%20is%20that%20you%20manually%20need%20to%20copy%20all%20files%20to%20the%20new%20profile.%20As%20moe%20asked%2C%20are%20you%20able%20to%20logon%20with%20an%20Azure%20AD%20Admin%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1192668%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1192668%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103721%22%20target%3D%22_blank%22%3E%40Abinash%20RGS%20ICT%20-%20Hotmail%3C%2FA%3Ehmm%2C%20weird.%20Hard%20to%20troubleshoot%20without%20access.%20I%20would%20reset%20the%20device%2C%20that%20would%20be%20your%20fastest%20solution.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1192665%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1192665%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20unable%20to%20logon%20with%20global%20admin%20as%20well.%20It%20throws%20same%20error%20%22The%20password%20is%20incorrect.%20Try%20again%22%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1192699%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1192699%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EI%20went%20through%20the%20Troubleshoot%20%26gt%3B%26gt%3B%20Advanced%20Options%20%26gt%3B%26gt%3B%20Command%20Prompt%20and%20managed%20to%20logon%20as%20local%20administrator.%20Restarted%20the%20device%20and%20it%20now%20let%20me%20logon%20as%20local%20admin%20%26gt%3B%26gt%3B%20tried%20dsregcmd%20%2Fstatus%20which%20shows%20AzureAdJoined%3A%20No%2C%20EnterpriseJoined%3A%20No%2C%20however%20Azure%20AD%20portal%20says%20Azure%20AD%20Joined%20with%20MDM%20None.%20Went%20through%20Settings%20%26gt%3B%26gt%3B%20Accounts%20%26gt%3B%26gt%3B%20Access%20work%20or%20school%20%26gt%3B%26gt%3B%20Connect%20and%20entered%20the%20device%20owner%20username%20password%20%26gt%3B%26gt%3B%20restarted%20the%20device%20%26gt%3B%26gt%3B%20tried%20to%20logon%20as%20same%20user%20but%20it%20says%20%22The%20password%20is%20incorrect.%20Try%20again%22.%20Tried%20logon%20with%20global%20admin%20account%20but%20with%20same%20error.%20dsregcmd%20%2Fstatus%20now%20shows%20AzureAdJoined%3A%20Yes.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1192824%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1192824%22%20slang%3D%22en-US%22%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3ELogged%20on%20as%20local%20administrator%20%26gt%3B%26gt%3B%20Joined%20the%20device%20to%20the%20Azure%20AD%20with%20the%20same%20user%20credentials.%20After%20restart%2C%20user%20can%20now%20logon.%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1195168%22%20slang%3D%22en-US%22%3ERe%3A%20unable%20to%20logon%20to%20the%20Intune%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1195168%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103721%22%20target%3D%22_blank%22%3E%40Abinash%20RGS%20ICT%20-%20Hotmail%3C%2FA%3EThank%20you%20for%20the%20information!%20Glad%20you%20fixed%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi, we have some users who are unable to logon to their Intune Azure AD joined devices (Win 10). When entering password it says "Password Incorrect". Same password works fine when they logon to the Office 365 on different computer.

In Intune portal, Devices tab shows that device as
Enabled Yes
Azure AD Joined
MDM None

 

Not sure how, but the MDM normally says "Microsoft Intune" and these users/devices has "None".
These users cannot logon to the device and also it doesn't gives me an option to logon as other user. Not sure what to do beside wiping it OR Is there a way I can manually add this device as Intune managed from the Azure Portal ?

 

Any help would be much appreciated, thank you.

11 Replies
Highlighted

@Abinash RGS ICT - Hotmailif the MDM is none there's probably something wrong with the Intune Auto Enrollment. For this to work correctly, your MDM User scope should be configured correct - can you check this?

 

https://docs.microsoft.com/en-us/intune/enrollment/quickstart-setup-auto-enrollment

 

 

Highlighted

@Jente_V 

Not sure if it is related to the MDM User Scope because I have successfully enrolled few Windows devices today.

 

MDM none is happening on few devices. These devices appears on "Azure AD Devices" but not on "All Devices".  Windows Enrolment >> Devices >> Serial number of device says Not Enrolled for the Enrolment State. Is there a way to re-enroll them without losing the data on the device ?

 

This is what we have for the MDM User Scope

screenshot: https://i.snipboard.io/7W3DUw.jpg 

 

 

Highlighted

@Abinash RGS ICT - HotmailSince your MDM user scope is set to all it should be ok. There is something else you should check:

 

Intune Portal > Device Enrollment > Windows Enrollment > CNAME Validation.

enter your domain and test if it's successfull.

 

Sadly, there is no official way to re-enroll your device without losing your profile (remove from Azure AD & add again) - that I know off. You won't loose the data, you just start with a clean profile (you can copy it manually after re-enrolling). I'm not sure if this still works, but you can try downloading the Company Portal App and see what information this gives.

 

Highlighted
CNAME test says it is configured successfully.

If I do Shift+Restart >> Troubleshoot >> Reset this PC >> Keep my files >> reboot then re-enrol with the same user, will this let me keep the existing files ?
Highlighted
Hi Abinash,

Could you login to the devices with your Global Admin account? Try to access the pc locally and check if the pc if enrolled correctly. I’m interest in going to Work and School account and force Sync to Intune.

Thanks!
Moe
Highlighted
Hi Abinash - I'm not sure about this. The worst that could happen is that you manually need to copy all files to the new profile. As moe asked, are you able to logon with an Azure AD Admin?
Highlighted

I am unable to logon with global admin as well. It throws same error "The password is incorrect. Try again"

Highlighted

@Abinash RGS ICT - Hotmailhmm, weird. Hard to troubleshoot without access. I would reset the device, that would be your fastest solution.

Highlighted

I went through the Troubleshoot >> Advanced Options >> Command Prompt and managed to logon as local administrator. Restarted the device and it now let me logon as local admin >> tried dsregcmd /status which shows AzureAdJoined: No, EnterpriseJoined: No, however Azure AD portal says Azure AD Joined with MDM None. Went through Settings >> Accounts >> Access work or school >> Connect and entered the device owner username password >> restarted the device >> tried to logon as same user but it says "The password is incorrect. Try again". Tried logon with global admin account but with same error. dsregcmd /status now shows AzureAdJoined: Yes.

Highlighted
Logged on as local administrator >> Joined the device to the Azure AD with the same user credentials. After restart, user can now logon.
Highlighted

@Abinash RGS ICT - HotmailThank you for the information! Glad you fixed it.