conditional access
465 TopicsError 80180014 due to device restrictions for Windows Autopilot devices
Hello, We've encountered an issue due to device restrictions. We wanted to block personal devices to register in AAD. Due to this policy we are unable to deploy Windows Autopilot devices because When we blocked personal devices it also blocks AAD join during Windows Autopilot (error code 80180014). Is there a way to set the device as corporate device when importing hardware ID in order to by pass this issue or with conditional access block personal device without affecting Windows Autopilot ? Thanks for your help.Solved453KViews0likes7CommentsMultiple Tenants on One Device
Hello, I have a scenario that I am not sure if it would work or not and wanted to get some clarification: 2 companies, each setup with Intune and MAM policies for mobile. Would I be able to setup both emails on a BYOD device? I don't think it is possible, because the device will need to be registered in Intune Company Portal app to retrieve the policies and check security etc. When you try to add the other address, it will require you to register in Company Portal again, but as far as I know, you can only have 1 company registered at a time?Solved141KViews1like12CommentsHybrid Azure AD join devices MDM set to "none"?
Good afternoon, We have recently upgraded all of our servers and as part of that I'm re-configuring Azure AD Connect for the hybrid environment. Users are syncing properly. Devices, however, seem to fail to be picked up by Intune and thus, MDM. IT is set to "none" and on top of that is not replacing the existing record for the device, so currently there's a Hybrid Azure AD join device and a Azure AD registered record assigned to the user that uses it (myself). I'm trying to use auto-enrollment via GPO, the specific GPO is "Enable Automatic MDM enrollment using default Azure AD credentials". Something I've noticed (and if memory servers me well), is the fact that the generated task in task scheduler is named differently. If I remember correct, the name should match or be similar to that of the GPO, it is now called "Schedule created by enrollment client for automatically enrolling in MDM from AAD". So I'm not too sure if the policy is, for whatever reason, generating the wrong task? At any rate, below is the information of one of the devices: | Device State | +----------------------------------------------------------------------+ AzureAdJoined : YES EnterpriseJoined : NO DomainJoined : YES DomainName : DOMAIN SSO State | +----------------------------------------------------------------------+ AzureAdPrt : NO AzureAdPrtAuthority : EnterprisePrt : NO EnterprisePrtAuthority : I'm aware that AzureAdPrt is set to NO, but I understand that isn't an issue if you are trying to enroll via default user credentials? (Correct me if I'm wrong). As for Intune, auto-enrollment is activated for everyone and anyone with the correct license. It has been a while since I last worked with this and perhaps I'm missing something obvious, but having look at Microsoft's docs and following some of the trouble shooting advice, I cannot see anything wrong with my setup. Please, if you need any more information do let me know. Thank you63KViews1like21CommentsCreating a folder containing multiple files and sending to devices via intune
Hi all, I desperately need some help! And just thought Id post on here to see if someone can help! I need to create a folder on client machines in the c drive (Folder name: Spanish Games) which I then deploy a bunch of files to this folder I create I have had a look and seems like I need to create a win32 app container with all in, script and files. What would I need to include in the script to get this to work? I have had a look at docs online but cant find one that deploys a folder and files too. I have found this: https://pariswells.com/blog/intune/copy-file-to-workstations-with-windows-intune but dont really understand some of it. Any help would be great!! Thanks in advanceSolved62KViews0likes22CommentsCompany portal failing to install error 0x87D1041C
Hello Everyone, I have added company portal (offline version) from Microsoft store for Business and deployed it to 6 autopilot enrolled windows 10 laptops. All laptops are with same hardware & configurations. Out of all laptop, company portal application is getting failed in one windows 10 laptop. I have tried to uninstall and re-install it but it's showing same error every time in that particular laptop. However apps are getting published in company portal in that laptop. then why in Endpoint manager it's showing failed to install with error code 0x87D1041C.57KViews0likes17Comments-2016281111 error Intune windows 10 update rings Using deadline settings
[Edited] Hello everyone, hoping you all are having a good day. I need some inputs on my current Windows 10 update rings policy. I set the deadline settings as shown below to multiple pilot devices. These devices are identical in all hardware but has different windows 10 builds (1909, 1709, 1903, 20H1, 21H2). Devices with Windows 10 1709 builds has been successful but I got this error "-2016281111 (Not applicable for this device)" on other versions. Policy Applied : User group User License : M365 Business premium and Windows 10 Enterprise E357KViews0likes7CommentsiOS Profile installation fails on corporate owned devices. Resolution to allow personal ones?
Hi community We are trying to protect our tenant from users enrolling their personal devices. This works up to the point where we are enrolling iOS devices. When trying to install the management profile on the Apple device, we receive the following error: Profile Installation Failed. Connection to the server could not be established. https://docs.microsoft.com/en-gb/intune/enrollment/troubleshoot-ios-enrollment-errors Why would they give us the option to block personally owned devices, yet not allow iOS to make contact with the server to install the management profile? At the moment, our workaround is to temporarily allow personal iOS devices when enrolling one, then disabling it. This works, but feels like we need to work around their contradictive setup. We have added the device serial to Corporate device identifiers. It is marked as enrolled status after the above workaround. It's status is "not contacted" if personal devices is blocked. This is not an issue with Android devices. Am I missing something or does Microsoft need to find a way to fix this? Do they even care seeing as it's an issue related to Apple devices?Solved54KViews0likes6Comments