02-24-2020 02:29 AM
Hi, we have some users who are unable to logon to their Intune Azure AD joined devices (Win 10). When entering password it says "Password Incorrect". Same password works fine when they logon to the Office 365 on different computer.
In Intune portal, Devices tab shows that device as
Enabled Yes
Azure AD Joined
MDM None
Not sure how, but the MDM normally says "Microsoft Intune" and these users/devices has "None".
These users cannot logon to the device and also it doesn't gives me an option to logon as other user. Not sure what to do beside wiping it OR Is there a way I can manually add this device as Intune managed from the Azure Portal ?
Any help would be much appreciated, thank you.
02-24-2020 07:25 AM
@Abinash RGS ICT - Hotmailif the MDM is none there's probably something wrong with the Intune Auto Enrollment. For this to work correctly, your MDM User scope should be configured correct - can you check this?
https://docs.microsoft.com/en-us/intune/enrollment/quickstart-setup-auto-enrollment
02-24-2020 07:52 AM
Not sure if it is related to the MDM User Scope because I have successfully enrolled few Windows devices today.
MDM none is happening on few devices. These devices appears on "Azure AD Devices" but not on "All Devices". Windows Enrolment >> Devices >> Serial number of device says Not Enrolled for the Enrolment State. Is there a way to re-enroll them without losing the data on the device ?
This is what we have for the MDM User Scope
screenshot: https://i.snipboard.io/7W3DUw.jpg
02-24-2020 07:59 AM
@Abinash RGS ICT - HotmailSince your MDM user scope is set to all it should be ok. There is something else you should check:
Intune Portal > Device Enrollment > Windows Enrollment > CNAME Validation.
enter your domain and test if it's successfull.
Sadly, there is no official way to re-enroll your device without losing your profile (remove from Azure AD & add again) - that I know off. You won't loose the data, you just start with a clean profile (you can copy it manually after re-enrolling). I'm not sure if this still works, but you can try downloading the Company Portal App and see what information this gives.
02-24-2020 12:00 PM
02-24-2020 06:19 PM
02-24-2020 11:55 PM
02-25-2020 12:11 AM - edited 02-25-2020 12:35 AM
I am unable to logon with global admin as well. It throws same error "The password is incorrect. Try again"
02-25-2020 12:13 AM
@Abinash RGS ICT - Hotmailhmm, weird. Hard to troubleshoot without access. I would reset the device, that would be your fastest solution.
02-25-2020 12:36 AM
I went through the Troubleshoot >> Advanced Options >> Command Prompt and managed to logon as local administrator. Restarted the device and it now let me logon as local admin >> tried dsregcmd /status which shows AzureAdJoined: No, EnterpriseJoined: No, however Azure AD portal says Azure AD Joined with MDM None. Went through Settings >> Accounts >> Access work or school >> Connect and entered the device owner username password >> restarted the device >> tried to logon as same user but it says "The password is incorrect. Try again". Tried logon with global admin account but with same error. dsregcmd /status now shows AzureAdJoined: Yes.
02-25-2020 01:27 AM
02-25-2020 11:35 PM
@Abinash RGS ICT - HotmailThank you for the information! Glad you fixed it.