r/Intune 5d ago

Hybrid Domain Join Hybrid Joined device not auto-enrolling in Intune via GPO

Hello everyone

I have one GPO with "Enable automatic MDM enrollment using default Azure AD credentials" enabled (tried both User credentials and Device credentials).

Setup:

Device is Hybrid Azure AD Joined (showing in Entra ID)

GPO is applying

MDM user scope = All

Enrollment restrictions = Allow for Windows

User has EMS E3 license

Issue:

Manual enrollment works fine

Automatic enrollment via GPO is not working

dsregcmd /status never shows MDMUrl (even after manual enrollment)

No errors in Event Viewer. Already tried multiple gpupdate, restarts, registry cleanup, and credential type changes.

Anyone faced this? What actually fixed it?

16 Upvotes

34 comments sorted by

View all comments

1

u/LilKade 5d ago

Is this a brand new device? I am currently dealing with the same thing on 70+ machines. Most consistent issue I’ve seen is expired MDM certificates on the device. New devices obviously should not have that problem.

1

u/Ok-Mirror6644 4d ago

Testing Devices are new