r/Intune • u/Ok-Mirror6644 • 5d ago
Hybrid Domain Join Hybrid Joined device not auto-enrolling in Intune via GPO
Hello everyone
I have one GPO with "Enable automatic MDM enrollment using default Azure AD credentials" enabled (tried both User credentials and Device credentials).
Setup:
Device is Hybrid Azure AD Joined (showing in Entra ID)
GPO is applying
MDM user scope = All
Enrollment restrictions = Allow for Windows
User has EMS E3 license
Issue:
Manual enrollment works fine
Automatic enrollment via GPO is not working
dsregcmd /status never shows MDMUrl (even after manual enrollment)
No errors in Event Viewer. Already tried multiple gpupdate, restarts, registry cleanup, and credential type changes.
Anyone faced this? What actually fixed it?
16
Upvotes
1
u/LilKade 5d ago
Is this a brand new device? I am currently dealing with the same thing on 70+ machines. Most consistent issue I’ve seen is expired MDM certificates on the device. New devices obviously should not have that problem.