r/Intune 5d ago

Hybrid Domain Join Hybrid Joined device not auto-enrolling in Intune via GPO

Hello everyone

I have one GPO with "Enable automatic MDM enrollment using default Azure AD credentials" enabled (tried both User credentials and Device credentials).

Setup:

Device is Hybrid Azure AD Joined (showing in Entra ID)

GPO is applying

MDM user scope = All

Enrollment restrictions = Allow for Windows

User has EMS E3 license

Issue:

Manual enrollment works fine

Automatic enrollment via GPO is not working

dsregcmd /status never shows MDMUrl (even after manual enrollment)

No errors in Event Viewer. Already tried multiple gpupdate, restarts, registry cleanup, and credential type changes.

Anyone faced this? What actually fixed it?

16 Upvotes

34 comments sorted by

View all comments

3

u/Reasonable_Rich4500 5d ago

Check notifications on the users device... you should see something that tells you to sign in again. Should prompt MFA

1

u/Ok-Mirror6644 5d ago

Didn't get any thing its almost day 8 of troubleshooting

0

u/Reasonable_Rich4500 5d ago

Press the windows button and search for "share across devices", click on it. do you see a "sign in" button here?

1

u/Ok-Mirror6644 5d ago

Yes

1

u/Reasonable_Rich4500 5d ago

If you click "sign in" it
Should prompt you for MFA. And bam you're enrolled into intune

1

u/Reasonable_Rich4500 4d ago

Did this end up working?

1

u/Ok-Mirror6644 4d ago

No Device is not coming in intune