Jump to content

Recommended Posts

Posted

We have bought some Intune licenses and i'm falling at the first hurdle and that is getting the devices onboarded to Intune.

 

The laptops are running windows 10 pro x64.

 

Currently we have a test account which has the intune license allocated to the user. When try to enroll the device by going to Settings > Accounts > Access work or School > Connect > enter the details of the test user, we get an error as shown below.

 

ErrorwithIntune.png

 

Have i missed something or is there something else i need to do?

Posted
Do you have a CNAME record on your domain name that points to EnterpriseEnrollment-s.manage.microsoft.com & EnterpriseRegistration.windows.net?
  • Thanks 1
Posted
Do you have a CNAME record on your domain name that points to EnterpriseEnrollment-s.manage.microsoft.com & EnterpriseRegistration.windows.net?
..... nope. We have a sub domain of a MAT. The other schools aren't using Azure at all from what i know, it's only me and our school that is doing it.

 

So i guess i ask someone at the MAT to create sub.matdomain.uk CNAME >

EnterpriseEnrollment-s.manage.microsoft.com

EnterpriseRegisitration.windows.net

Posted (edited)

Microsoft have the required CNAME values near the bottom of this article: https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enroll

 

Although it does say its not required. If you dont have the CNAME values users must enter the Intune URL during enrolment, although I'm not sure how to do that?

 

 

Edit: Just had a look at my DNS CNAME records and can confirm thats how we have it setup.

Edited by aicrd
  • Thanks 1
Posted (edited)

Adding the CNAME worked a charm. I got confused about MAM and MDM until i read the following:

 

In simple terms, MDM is about control of devices like smartphones and tablets, whereas MAM is focused on specific corporate applications and their related data. It’s very important to establish what you want to achieve with your mobile strategy, or you may find that you make the wrong decision.

 

from this site: https://www.finextra.com/blogposting/14056/mdm-vs-mam-is-managing-apps-or-devices-right-for-your-business#:~:text=In%20simple%20terms%2C%20MDM%20is%20about%20control%20of,may%20find%20that%20you%20make%20the%20wrong%20decision.

 

5097de9b69bedd0b2e000029

 

Being a predominantly Google school with Azure AD setup from our OnPrem AD, the MDM option seems like the best option.

Edited by timbo343
  • Thanks 1
Posted

All i want to do is to get the device enrolled into Intune and use Intune as a MDM. I'm not bothered about the MAM.

 

The device never shows up in Intune for Education.

 

Here is what i am doing to give someone an insight into where i might be going wrong.

 

In the MS365 admin centre, i go to All Admin Centres > Intune for Education > Devices.

- In here there are no enrolled devices that i think have set up

 

In the MS365 admin centre i go to Azure Active Directory > Mobility (MDM & MAM) > Intune

- MDM user scope is set to Some (Group Staff)

- MAM user scope is set to None

 

In the MS365 admin centre i got to Azure Active Directory > Devices > All Devices.

- In here there are devices but these are devices that i have not enrolled. Looks like these are devices that users are using at home.

 

With the above settings set, i pick a device up and go to Settings > Accounts > Access work or School.

- I add a teststaff user by entering email address and password. Here i get an error message "Something went wrong"

 

I go back to the MDM and MAM settings and change these to say:

- MDM user scope: Some (Group Staff)

- MAM user scope: ALL

 

Try adding the teststaff account back to the device and i am able to add the user account to the device. I get a 2fa confirmation > enter the code from the SMS.

When asked about Windows Hello, i cancel the ability to use this. I see the "You're All Ready" screen and click Done.

 

I load up Company Portal. It shows - "This device has't been setup for corporate use yet. Select this message to setup".

1. Add corporate account to this device - TICKED

2. Connect this device to work - !

 

Click next > click connect.

 

I get a MS Account login and click next. I'm presented with "Your device is already being managed by an organisation".

There is a spinning circle that says "waiting for your device to connect to work." It never stops spinning.

 

Is there something that i have missed or am i doing this wrong? Surely it shouldn't be this hard.

Posted (edited)

Update to this...

 

I *think* i have got this working from trail and error.

 

A few pre-reqs required:

1. A cloud AAD enrollment user with only Intune License added to the account. Set it with a strong password.

 

2. Add this AAD enrollment user to a newly created cloud group called AAD Device Enrollment

 

3. From the M365 admin center go to Azure Active Directory > Azure Active Directory > Devices > Device Settings.

"Users may join devices to Azure AD" select "Selected" and choose the newly created group "AAD Device enrollment".

 

4. Click back to the Azure Active Directory menu > Mobility (MDM & MAM) > Microsoft Intune.

MDM User scope set to Some. The group AAD Device Enrollment is chosen.

MAM user scope is set to None.

 

5. Go back to the M365 admin center screen > All admin centers > Intune for Education > enrollment managers > Add enrollment manager.

Add the newly created enrollment manager to this area.

 

Now on the laptop log on as local administrator and go to Settings > Accounts > Access work or School. In here, click Connect and choose Join this device to Azure Active Directory. Enter the AAD Enrollment user details when prompted.

It will give a summary of what it will create.

Connecting to *your domain*

Username: *the username of your AAD enrollment user*

User type: Administrator

Click Join.

 

You will now see a You're all ready message.

 

This means that the device is now enrolled in to your Azure Active Directory and you can manage the device.

 

Users are able to login with their email address and OnPrem password or you can configure local accounts for the users to use.

 

I'm not sure which to setup as all our stuff is in Google Cloud. Maybe local admin accounts for our staff users might be the best way to go for us.

 

Policies are now pushed out via the Endpoint Manager under M365 Admin center > All Admin Centers > Endpoint Manager.

Edited by timbo343
Posted

What are people doing about AAD joined devices and having users as Local Admins so they can install applications and printers at home?

 

I've gone to test a staff member logged in with their AAD details and they cannot install Office 365 onto the device due to permissions.

 

How have you got round this?

Posted
What are people doing about AAD joined devices and having users as Local Admins so they can install applications and printers at home?

 

I've gone to test a staff member logged in with their AAD details and they cannot install Office 365 onto the device due to permissions.

 

How have you got round this?

 

Use Intune to deploy these apps.

 

No difference really to how you manage devices on a domain

  • Thanks 1
Posted
Yep. Intune has a built in deployment tool for Office 365. You can get it setup in just a few mins. No need to upload MSIs or anything like that.
  • Thanks 1
Posted

Is there a way i can push out a single file to a specific folder on the devices in Intune?

 

We have a Smoothwall VPN application and if the configuration file changes for any reason, i would like to push out a new one to devices and tell staff how and where to pick the new configuration file from.

 

I do not want to deploy the Smoothwall application as this will already be done on the devices, i just want to push out a configuration file to a folder on the C Drive (C:\xxxxxx\ )

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...