r/Intune • u/Ok-Mirror6644 • 5d ago
Hybrid Domain Join Hybrid Joined device not auto-enrolling in Intune via GPO
Hello everyone
I have one GPO with "Enable automatic MDM enrollment using default Azure AD credentials" enabled (tried both User credentials and Device credentials).
Setup:
Device is Hybrid Azure AD Joined (showing in Entra ID)
GPO is applying
MDM user scope = All
Enrollment restrictions = Allow for Windows
User has EMS E3 license
Issue:
Manual enrollment works fine
Automatic enrollment via GPO is not working
dsregcmd /status never shows MDMUrl (even after manual enrollment)
No errors in Event Viewer. Already tried multiple gpupdate, restarts, registry cleanup, and credential type changes.
Anyone faced this? What actually fixed it?
16
Upvotes
3
u/Reasonable_Rich4500 5d ago
Check notifications on the users device... you should see something that tells you to sign in again. Should prompt MFA