Jump to content

Recommended Posts

Posted

Like loads of other schools, we've had a stack of laptops delivered to hand to students. We had some delivered earlier last year, which we were able to move from the DfE InTune over to ours and they deployed/worked fine. However, we've had more laptops delivered (HP 250 G7), but they're unsecured devices, not enrolled into any Intune.

Our process:

  • Boot laptop
  • At OOBE - Get hash ID with Powershell script
  • Import hash to Intune
  • Connect to WiFi
  • Laptop goes to Setting up your device page
  • Consistently fails at Security Policies stage and will not proceed

I cannot figure out why tall of these brand new unboxed devices are failing at the same point, when they previously worked on the first batch of devices we received.

 

Can anyone help point me in the right direction?

Posted
Do you know if the devices are definitely running Win10 Pro? Most of the time when I've had errors enrolling devices onto InTune, it's due to being home edition.
  • Thanks 1
Posted (edited)
Yeah we're seeing this too. Though only about 5-10% total failure. Most have some policy failure but we're pushing them out of the door anyway. They are running ProfessionalEducation Edited by psydii
  • Thanks 1
Posted

Not had an issue with the Dell's we had (swapped from HP at last minute).

Can I be sneaky and asked how you transfer from one EndPoint Management (DfE) to your own?

  • Thanks 1
Posted
I can't help there, we ordered them unmanaged. There are others here who have worked through the process to have a DfE Intune device released.
  • Thanks 2
Posted
Do you know if the devices are definitely running Win10 Pro? Most of the time when I've had errors enrolling devices onto InTune, it's due to being home edition.

It's Windows 10 ProEducation 2004.

 

Yeah we're seeing this too. Though only about 5-10% total failure. Most have some policy failure but we're pushing them out of the door anyway. They are running ProfessionalEducation

We're seeing a 100% failure rate. If we push them out anyway, the user gets the Windows Hello prompt every time. If you get this, what are you doing, re Windows Hello?

Posted

Thats interesting.... having similar issues not only with that model of HP but some older ones as well.

 

Just testing with my surface book pro from home to see if it is an Intune issue.

  • Thanks 1
Posted
Do you get an error code when it fails?

I should have included the message in my OP (I should know better!). It just says that it timed out trying to get the security policy and then automatically fails all remaining steps.

Posted (edited)

I found I Needed to add some sites to the exception filter and non https inspections lists.

 

Added the following

 

amd.com

hp.com

hpanalytics.net

intel.com

nuvoton.com

Edited by mdrabble
Added websites
  • Thanks 1
Posted
How have you configured the deployment profile for AutoPilot? Is it user driven or self deploy?

It's self deploy, because we're also removing from of the crapware that came with them.

Posted

This may be your issue then. The Self Deploy is still in Preview at this time at has certain requirements of the device, such as BitLocker TPM 2.0 etc.

 

I would try removing the assignment of the profile for self deploy, and create a new profile with User Driven. Assign this to all devices and give it about 15 minutes. Then try kicking a device off again, which may have to be a device that has not been attempted before as the old InTune profile will have been pulled down to the failed device.

  • Thanks 1
Posted (edited)
This may be your issue then. The Self Deploy is still in Preview at this time at has certain requirements of the device, such as BitLocker TPM 2.0 etc.

 

I would try removing the assignment of the profile for self deploy, and create a new profile with User Driven. Assign this to all devices and give it about 15 minutes. Then try kicking a device off again, which may have to be a device that has not been attempted before as the old InTune profile will have been pulled down to the failed device.

Ah OK, thanks.

We've just attempted this, but it failed (on a brand new device, which shows in the assigned devices for that profile). The OOBE steps were; Language setup, keyboard layout setup, additional keyboard layout setup, network setup (which then goes off and talks to Intune), restarts and continues the OOBE, then asks whether to set up as a personal or organisation device. Chose organisation and signed in with Intune admin credentials and then it errors out. I've attached the error.

[ATTACH=CONFIG]60439[/ATTACH]

 

Edit: That error relates to the user not having an Intune license assigned. Just assigned it and will try again. Do all users need an Intune license assigned, if they're to use these laptops at home?

Edited by CHiLL
Posted
The OOBE steps should be; Language setup, keyboard layout setup, additional keyboard layout setup, network setup (which then goes off and talks to Intune) followed by a screen saying "Welcome to [your organisation name]!". This is the start of the user driven autopilot profile.
  • Thanks 1
Posted
Edit: That error relates to the user not having an Intune license assigned. Just assigned it and will try again. Do all users need an Intune license assigned, if they're to use these laptops at home?

 

Yes they do.

  • Thanks 1
Posted (edited)
OK, thanks. It appears to be progressing, though we're now getting the Windows Hello setup on the brand new devices, when setting it up with our Intune admin account. This is despite it being set to disabled in Windows Enrollment. However, when we logged then logged on with a standard user, they didn't get a Windows Hello prompt. It appears to just be a ask once (which we cancel) and then it doesn't come back. Is this expected behaviour? Edited by CHiLL
Posted

Is it expected behaviour? Well, we've come to expect it, but we don't believe that it should be happening :)

 

Lots of little quirks and inconsistency's with the OOBE + Intune at the moment. Things seemed much more consistent back when this guy still worked at Microsoft. I wonder if they lost some talent in the dev/support team that has lead to a drop in service reliability.

Posted
OK, thanks. It appears to be progressing, though we're now getting the Windows Hello setup on the brand new devices, when setting it up with our Intune admin account. This is despite it being set to disabled in Windows Enrollment. However, when we logged then logged on with a standard user, they didn't get a Windows Hello prompt. It appears to just be a ask once (which we cancel) and then it doesn't come back. Is this expected behaviour?

 

Can you try using a standard user account (with an Intune licence assigned) rather than an admin account? User driven autopilot is designed for standard user accounts. You can remove/change the primary user after it's built if needed.

Posted
OK, thanks. It appears to be progressing, though we're now getting the Windows Hello setup on the brand new devices, when setting it up with our Intune admin account. This is despite it being set to disabled in Windows Enrollment. However, when we logged then logged on with a standard user, they didn't get a Windows Hello prompt. It appears to just be a ask once (which we cancel) and then it doesn't come back. Is this expected behaviour?

 

You can manage the Windows Hello within the Enroll section of Intune. Its under Devices menu.

 

Another thing to check is whether Require MFA to join devices is enabled. Log into Azure Portal, open Azure AD. Click Devices and then Device Settings from left side. I think this is now off by default but used to be on previously. If not used, i would recommend enabling Enterpise State Roaming from the same section. https://docs.microsoft.com/en-us/azure/active-directory/devices/enterprise-state-roaming-overview

 

And yes, Intune licence is required per user

  • 4 weeks later...
Posted (edited)

Sorry for bringing up an old-ish thread, having a similar issue with MFA during Autopilot and also with Students installing O365.

 

Out of interest are you guys using A3 licenses?

 

We've just realised that when installing O365 on Desktops our users are now being prompted to register their MFA details (and Windows Hello too!). Closing the prompt for MFA gets rid of it and the applications end up registered, but still. I believe I may have found the policy causing this, if you go to:

 

Azure AD> Azure AD> Security> Identity Protection> MFA Registration Policy

 

Ours is set to All Users for Require Azure AD MFA registration. The problem is, the whole section is greyed out and I can't see a way to change it, it appears that you need a P2 license in order to do so. No idea why Microsoft have set this as default and then hid the ability to change something so fundamental behind the P2 paywall :mad:

Edited by foofighterjim

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...