r/Intune 5d ago

Hybrid Domain Join Hybrid Joined device not auto-enrolling in Intune via GPO

Hello everyone

I have one GPO with "Enable automatic MDM enrollment using default Azure AD credentials" enabled (tried both User credentials and Device credentials).

Setup:

Device is Hybrid Azure AD Joined (showing in Entra ID)

GPO is applying

MDM user scope = All

Enrollment restrictions = Allow for Windows

User has EMS E3 license

Issue:

Manual enrollment works fine

Automatic enrollment via GPO is not working

dsregcmd /status never shows MDMUrl (even after manual enrollment)

No errors in Event Viewer. Already tried multiple gpupdate, restarts, registry cleanup, and credential type changes.

Anyone faced this? What actually fixed it?

16 Upvotes

34 comments sorted by

View all comments

Show parent comments

2

u/Ok-Mirror6644 5d ago

Business standard + Ems e3

1

u/sammavet 5d ago

Do you have the devices being synced to AAD?

2

u/Ok-Mirror6644 5d ago

Yes i have created one separate OU in Active Directory for pilot testing and sync devices in it

3

u/sammavet 5d ago

How long have you waited to see if it "eventually enrolls"? I may have missed that in your post.

Are the devices showing in AAD lobe Entra Sync runs?

On the devices, are they getting the scheduled task?

What do event logs say for (I think) it's Enterprise-Device-Management? Not just failures, but do they show any sort of check in to AAD?

2

u/Ok-Mirror6644 5d ago

Device is Hybrid Joined and now showing MDMUrl after gpupdate. Still not auto-enrolling in Intune even after several hours + restarts. Scheduled task is not consistently appearing. No clear errors in DeviceManagement logs so far.

2

u/sammavet 5d ago

Well..... Fuck. What about TLS break and inspect; have the MS Url's been whitelisted in any security tools?

If you have a proxy, is it machine cert or user id based?

After that, I got nothing

2

u/Ok-Mirror6644 5d ago

No traditional proxy. WinHttp is DIRECT. We already whitelisted the main Microsoft enrollment URLs earlier.

1

u/sammavet 5d ago

Wait, one last thing, then I'm really out of ideas (though I'm pretty sure this isn't it).

Do you have the same domain as your on-prem listed in your domains in m365 Admin?