SOLVED

Windows 10 automatic enrollment on a new device

%3CLINGO-SUB%20id%3D%22lingo-sub-2101711%22%20slang%3D%22en-US%22%3EWindows%2010%20automatic%20enrollment%20on%20a%20new%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2101711%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%26nbsp%3BWindows%2010%20automatic%20enrollment%20for%20new%20computers%20that%20join%20the%20Domain.%20If%20i%20have%20a%20newly%20installed%20device%20and%20login%20to%20it%20after%20a%20while%20the%20join%20is%20completed%20and%20the%20device%20is%20now%20in%20Intune.%20What%20i%20wonder%20is%20if%20there%20is%20any%20way%20to%20force%20the%20join%20process%20with%20for%20example%20powershell%20without%20have%20to%20go%20trough%20the%20process%20of%20going%20into%20%22Settings%20%26gt%3B%20Accounts%22%20to%20login%20and%20registering%20the%20device%20that%20way%20with%20the%20users%20account%20as%20this%20process%20takes%20a%20but%20of%20time%20and%20wait.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2101711%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2102097%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20automatic%20enrollment%20on%20a%20new%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2102097%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F859864%22%20target%3D%22_blank%22%3E%40michaelsjodin%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAre%20these%20computers%20%3CEM%3EHybrid%20Azure%20AD%20Joined%3C%2FEM%3E%20(in%20your%20local%20Active%20Directory%20and%20Azure%20AD)%3F%26nbsp%3B%20If%20so%20the%20following%20article%20explains%20how%20to%20use%20a%20GPO%20to%20enroll%20existing%20devices%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fenroll-a-windows-10-device-automatically-using-group-policy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EEnroll%20a%20Windows%2010%20device%20automatically%20using%20Group%20Policy%20-%20Windows%20Client%20Management%20%7C%20Microsoft%20Docs.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20the%20devices%20are%20not%20in%20your%20local%20Active%20Directory%2C%20when%20the%20device%20is%20%3CSTRONG%3Ejoined%3C%2FSTRONG%3E%20to%20Azure%20AD%2C%20it%20will%20automatically%20enroll%2C%20and%20is%20considered%20a%20corporate-owned%20device.%3C%2FP%3E%0A%3CP%3EWhen%20a%20user%20adds%20a%20new%20work%20or%20school%20account%2C%20the%20device%20is%20not%20joined%20but%20%3CSTRONG%3Eregistered%3C%2FSTRONG%3E%20to%20Azure%20AD.%26nbsp%3B%20The%20enrollment%20considers%20this%20a%20personally-owned%20(BYOD)%20device.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20either%20of%20the%20second%20two%20scenarios%20are%20what%20you%20need%2C%20let%20me%20know%20if%20a%20reply.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EReference%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-enrollment-methods%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EIntune%20enrollment%20methods%20for%20Windows%20devices%20-%20Microsoft%20Intune%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi

 

I have Windows 10 automatic enrollment for new computers that join the Domain. If i have a newly installed device and login to it after a while the join is completed and the device is now in Intune. What i wonder is if there is any way to force the join process with for example powershell without have to go trough the process of going into "Settings > Accounts" to login and registering the device that way with the users account as this process takes a but of time and wait.

3 Replies

@michaelsjodin 

 

Are these computers Hybrid Azure AD Joined (in your local Active Directory and Azure AD)?  If so the following article explains how to use a GPO to enroll existing devices: Enroll a Windows 10 device automatically using Group Policy - Windows Client Management | Microsoft ...

 

If the devices are not in your local Active Directory, when the device is joined to Azure AD, it will automatically enroll, and is considered a corporate-owned device.

When a user adds a new work or school account, the device is not joined but registered to Azure AD.  The enrollment considers this a personally-owned (BYOD) device.

 

If either of the second two scenarios are what you need, let me know if a reply.

 

Reference: Intune enrollment methods for Windows devices - Microsoft Intune | Microsoft Docs

Hi

They are Hybrid Azure AD Joined with a GPO and i wonder if there is any faster way to make this happen then just wait or logging in with the users credentials under "accounts". running a gpupdate /force is not helping either.
Best Response confirmed by michaelsjodin (Contributor)
Solution

@michaelsjodin 

 

Aside from the troubleshooting steps in the article, make sure the account signing on to Windows is synchronized to Azure AD and has permissions to auto-enroll devices.  The scheduled task created by the GPO uses that account for authentication.

 

In my lab, I have had cases where a user did not sign on during the 24 hour period the scheduled task runs for and had to wait until the GPO refreshed and created the task again.  In those cases, a gpupdate /force worked so long as the user had local administrator permissions.

 

Other than that, you wait.