Windows Autopilot Hybrid Domain Join multiple logins

Copper Contributor

It seems the Windows Autopilot process workflow is not completing due to the group policy security configuration. I have been experiancing following behaviour, any advice suggestion is greatly appreciated.

1. Intune is configured with AutoPilot White glove profile with Hybrid Domain join using connector.

2. ESP is enabled with quite a few mandatory application.

2. Devices are build using white glove, ESP is showing Device Prepration and Device setup phases are completed and reseal completed without any issues.

3. User sign in using domain credentails first time, then soon asked Azure credentials to complete login. Use setup ESP is not shown (disable ESP is not enabled).

4. Device will restart and asked to sign in again using domain credentials. Use setup ESP is not shown (disable ESP is not enabled).

5. Device will apply final setup GPO with prompt of legal warning etc, then login succesfully.

6. Another user sign in to device User ESP is disabled and setup completed without any issues.

 

We are trying to fix multiple login issues so devices can be handed over users for completing user setup phase.

The issue does not occur if we remove all security GPOs. 

Tried to remove GPO settings or Intune policies listed in this article but does not resolve the issues.

 

Any help is greatly appreciated. 

2 Replies
Hi,

I guess knowing what's in the security gpo would help us to troubleshoot the problem as you already know it has something to do with one of those settings
It seems the mulitple policies can cause this issue. In our case, issue was caused by
MSS: (AutoAdminLogon) Enable Automatic Logon policy. Microsoft recommands to disable this settings but it breaks the Autopilot process, disables the ESP and user have to logon multiple times.
techcommunity.microsoft.com/t5/microsoft-security-baselines/the-mss-settings/ba-p/701055