mdrabble Posted December 1, 2020 Posted December 1, 2020 Created a User Driven AutoPilot join and think this to be too complicated for some users, so I created an AutoPilot Deployment Profile for a Device Driven join. I've downloaded the profile as a JSON file and saved and named in the correct locations. laptop meets requirements - UEFI boot and TMP 2.0 etc Run sysprep /oobe /reboot and laptop reboots and begins the Intune signup but fails on the Device Preperation stage (error code 0x800705b4) with the message Installation exceeded the time limit set by your organisation. Anyone use Device Driven profiles? Cheers
snagrat Posted December 1, 2020 Posted December 1, 2020 I did then moved back to User Driven as some features are missing. Not sure why it is too complicated for end user? They simply get presented with a login screen for your Org and sign in, then it passes these credentials to the first Windows login as well. I never had to download a JSON file. Just imported devices into AutoPilot and ran the OOBE sysprep. On reboot they joined Intune automatically.
mdrabble Posted December 1, 2020 Author Posted December 1, 2020 I did then moved back to User Driven as some features are missing. Not sure why it is too complicated for end user? They simply get presented with a login screen for your Org and sign in, then it passes these credentials to the first Windows login as well. I never had to download a JSON file. Just imported devices into AutoPilot and ran the OOBE sysprep. On reboot they joined Intune automatically. Sign up was asking for mobile number for text messages etc. Will strip things back and try again on the user join option just incase I added some odd settings. @snagrat do you use user join option for students?
snagrat Posted December 1, 2020 Posted December 1, 2020 Yes we use it for Students, although sometimes we just do it with an Admin account to get it enrolled. You can disable Windows Hello for Business, this is causing the prompt for text/2FA etc 1
mdrabble Posted December 1, 2020 Author Posted December 1, 2020 So I could enroll as me and then hand to student to then login and away they go?
BenLycett Posted December 1, 2020 Posted December 1, 2020 We have a number of laptops given to us from the DfE. We're currently using Intune to manage them. We've configured ours using the user driven option to make it easier for students to set up. If you go to Devices > Enroll Devices > Windows Enrollment > Devices. You can import your devices using your device serial numbers and hardware hash. If you know who you're devices are going to, you can assign a user to a device. All they will need to do is enter their Office365 password. This might make things easier for you. It should look like the image below. 1
snagrat Posted December 1, 2020 Posted December 1, 2020 So I could enroll as me and then hand to student to then login and away they go? Yes you can, although my accounts seem to hit a limit of 100 and won’t allow anymore. Even though it should be unlimited for Admins. I have several accounts. Only problem with do it this way is that the device is then assigned to you and not to e Student. That just means the Company Portal does not work 1
mdrabble Posted December 1, 2020 Author Posted December 1, 2020 Originally thought intune would be a pain but I am actually quite liking it! Deploying apps is straight forward Just fighting with Smoothwall Cloud Filter Once happy with that I can then need to look how to lock the laptops down
BenLycett Posted December 1, 2020 Posted December 1, 2020 You could create a self deploying deployment profile which will enroll the device into Azure AD without a user. They will just have to enter their log in details when they log into the device.
newpersn Posted December 2, 2020 Posted December 2, 2020 (edited) I'm Jumping on the band wagon here. I have been playing with Intune and Azure. I can get the laptop to join Azure but doesn't apply Intune to it. What am i doing wrong. I've currently tired using a clean laptop and autopilot at the OOBE. Edited December 2, 2020 by newpersn
mdrabble Posted December 2, 2020 Author Posted December 2, 2020 How are you trying to add to Intune? I've created a User Driven Enrollment profile and downloaded it as a JSON file and saved it as AutopilotConfigurationFile.json in C:\Windows\Provisioning\AutoPilot folder. using this guide https://docs.microsoft.com/en-us/mem/autopilot/existing-devices Assigned an Intune License to my test user Not sure if you need Azure Branding configured - I am sure more qualified/seasoned Intune people will correct me Then Sysprep /oobe /reboot
newpersn Posted December 2, 2020 Posted December 2, 2020 I looked at that and looked away as I'm not using SCCM. Ideally looking at something to run at OOBE. To join to azure and apply MDM policies.
snagrat Posted December 2, 2020 Posted December 2, 2020 I looked at that and looked away as I'm not using SCCM. Ideally looking at something to run at OOBE. To join to azure and apply MDM policies. Have you imported the Hardware Hash into AutoPilot?
newpersn Posted December 2, 2020 Posted December 2, 2020 How do I get the hardware hash? Its a dell latitude 5470 im playing with currently?
snagrat Posted December 2, 2020 Posted December 2, 2020 How do I get the hardware hash? Its a dell latitude 5470 im playing with currently? https://docs.microsoft.com/en-us/mem/autopilot/add-devices#collecting-the-hardware-hash-from-existing-devices-using-powershell
newpersn Posted December 2, 2020 Posted December 2, 2020 So. Clean install (add software if needed) (don't connect to Internet) Get hardware hash and upload it to Intune. Sysprep /generalize /oobe What do I do at the oobe? Kick autopilot in with the profile on a stick? Sorry. I think i spent too much time reading i to this and got confused.
snagrat Posted December 2, 2020 Posted December 2, 2020 Get the hardware hash first and upload to AutoPilot. Make sure the deployment profile gets assigned. OOBE the device and restart. You will be asked for Keyboard layout etc and then to join a network. Then it detects you are joined to an Org and give you the “Welcome to Org” screen. At this point you sign in to enrol the device. In future Hash can be sent by laptop manufacturer. You/They import and ship devices. End user just turns on, enter WiFi details and boom they are joined to Org. No need for IT to touch the device.
FragglePete Posted December 2, 2020 Posted December 2, 2020 This is quite a nice little trick: You can get the Hardware Hash of a new machine and upload without having to setup the device first. I am too loving Intune from what I've seen so far, but just waiting for the licenses to be applied at the moment before I continue. Pete 1
snagrat Posted December 2, 2020 Posted December 2, 2020 I have created a script that downloads and installs the required components, creates the hardware hash file and uploads it to OneDrive. We deployed this to around 800 machines so I could upload all the hash first then it was just a simple step to reset the machine. There was the manual step of combining all individual files into one but that wasn’t too hard and gave us the ability to check the computers. Since we have had two batches of 200 Surface Go’s delivered and they get given out to the Pupils without needing to touch them.
newpersn Posted December 2, 2020 Posted December 2, 2020 This is quite a nice little trick: You can get the Hardware Hash of a new machine and upload without having to setup the device first. I am too loving Intune from what I've seen so far, but just waiting for the licenses to be applied at the moment before I continue. Pete I'm guessing by doing this, I would need to turn each laptop on and connect to LAN and run those commands. What happens after you ran the script? Laptop restarts and happy to be used the students with the MDM applied to the system? Sorry for the so many questions. I have created a script that downloads and installs the required components, creates the hardware hash file and uploads it to OneDrive. We deployed this to around 800 machines so I could upload all the hash first then it was just a simple step to reset the machine. There was the manual step of combining all individual files into one but that wasn’t too hard and gave us the ability to check the computers. Since we have had two batches of 200 Surface Go’s delivered and they get given out to the Pupils without needing to touch them. Willing to share? We are currently looking at student laptop loan scheme and have a trial of Intune currently.
BenLycett Posted December 3, 2020 Posted December 3, 2020 You can get this from the manufacturer. If you have any laptops from the DfE you will find this in the spreadsheet provided. Here is a link you may find useful. https://docs.microsoft.com/en-us/mem/autopilot/add-devices#:~:text=You%20can%20use%20a%20PowerShell,the%20hardware%20hash%20belongs%20to.
dezt Posted December 4, 2020 Posted December 4, 2020 I have used this process to get the hardware hash without setting up windows, it takes a few minutes but saves time on installing windows and then running the powershell script. https://www.thelazyadministrator.com/2020/01/27/get-a-new-computers-auto-pilot-hash-without-going-through-the-out-of-box-experience-oobe/ 1
Brimstone Posted December 4, 2020 Posted December 4, 2020 Since we have had two batches of 200 Surface Go’s delivered and they get given out to the Pupils without needing to touch them. I've been doing this since 2015 with macOS and iOS..... 1
newpersn Posted December 8, 2020 Posted December 8, 2020 Have I done something wrong. Do you assign users to the devices? Tested today and it come up with the test account I was using.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now