Jump to content

Recommended Posts

Posted

Hi All,

 

Currently we manage our domain joined machines from a DC server via Group Policy. We do have SCCM but it's only really being used for a couple of app installations, and monitoring anti-virus. It was never really setup to do very much at all and I don't want to invest any more time in it.

 

With a move to Windows 11, I also need to move around from App-V which we currently use for a number of our third party apps.

 

I've been testing using Intune to deploy apps to Windows 11 clients which were 'Co-Managed' in Intune, but sending them up from SCCM in the pilot co-management method. What I now what to do is skip the Co-Management bit and simply have Windows 11 machine appear in Intune.

 

We're imaging by MDT still (As it works and I'm struggling to see how Autopilot works as a replacement for it). All our machines are normally Hybrid joined and synced via Azure AD Connect. I've got the 'Automatic MDM enrolment' set in Group Policy, but the machine doesn't appear in Intune.

 

Looking in Entra ID, it's showing up, but with a registered status of 'Pending'. Although it does have a registered date on the list of devices before. The device itself when I run dsregcmd /status shows it as 'AzureADJoined' and 'DomainJoined'. But not MDM paths listed.

 

So I'm clearly missing something here, but I'm not wondering if this is even the right path to take. As I keep finding people online saying 'Don't hybrid join and manage' or 'Use autopilot' followed by 'Don't use autopilot to local domain join'.

 

So before I get further down this rabbit hole, am I right to keep digging?

 

Cheers,

Rob

Posted

Hi,

 

I am currently down the same rabbit hole. Spent some time trying to get Hybrid join working with Autopilot and I dont think its worth the effort (Seems to create a duplicate entra device?!) You also can't specify the computer name on the Hybrid Domain join Intune profile . Looks like some potential scripts/apps to do it.

 

I originally setup Co-Management, but seems to take ages to sync and isntall apps. Coming from a SCCM task sequence that is pretty zero touch this is frustrating.

 

I would be interested if you have got any further?

Posted

I've had Co-Management working ok with it registering the machines to Intune, but I'm trying to bypass needing that as well. I've got the Group Policy 'Automatic MDM Join' setup, but so far I've not got a machine to successfully join. However I've not had much time since my last post to mess with it.

 

I've also avoided Autopilot so far for Local Domain Joined machines. I just use it for Entra Joined machines (Not hybrid joined). Things like staff laptops for example.

 

My aim right now is to have MDM image a machine has it normally would, then Group Policy apply at the end of the MDT process. Machine joins the MDM (Ideally using the MDM Account which is a 'Enrolment Manager' or what ever they call it so you don't have a machine limit. At this point, the machine is Hybrid Joined to Intune, with Local Domain as it's 'Primary' control. Intune then deploys apps to the machine which is the main focus for having it in Intune right now.

 

If I get more time to look at this in the next few weeks I'll let you know how I get on.

  • Thanks 1
  • 2 weeks later...
Posted
Hi,

 

I am currently down the same rabbit hole. Spent some time trying to get Hybrid join working with Autopilot and I dont think its worth the effort (Seems to create a duplicate entra device?!) You also can't specify the computer name on the Hybrid Domain join Intune profile . Looks like some potential scripts/apps to do it.

 

I originally setup Co-Management, but seems to take ages to sync and isntall apps. Coming from a SCCM task sequence that is pretty zero touch this is frustrating.

 

I would be interested if you have got any further?

I'm going to be in the same hole. We're moving to InTune for cyber security reasons. Just got to grips with SCCM and have managed to automate all applications/drivers depending on room numbers. Practically zero touch like you've said other than entering LDAP info. Cant wait(!)

Posted

So update on this. I've made progress on it. Got machines to join Intune now but there are a few things to note about this.

 

First, I'm not using Autopilot, mainly as it's designed for Device to Entra ID, with Local AD bolted on. All the advice, including from Microsoft is to not use this for local domain machines unless you have too. So I'm not. I'm still using MDT for imaging the machine, with no Intune parts setup in MDT or the TS.

 

Group Policy is set to Automatic MDM enrolment. So once the machine has finished the MDT process, joined AD and got this GP policy, it's trying to join Intune as the MDM.

 

However, to do this, it needs a few things, first it needs the machine to already be in Entra ID. If you sync devices by Entra ID Connection (Formally Azure AD Connect), this can up to 30 minutes (Based on default 30 minute sync) plus some Entra ID processing time. So the MDT Task Sequence has normally long finished by this point.

It also needs a user who has a MDM licence who has permission to join an MDM. This is normally 'Everyone' as long as you have MDM licencing to cover all users. Once that user logs on, it will join Intune via that user, and set that user as the 'Primary User'. It doesn't count towards the device joining number (Limited to 5 devices normally). So you don't need them to be a Device Enrolment Manager.

 

So it appears the only method of using MDT & Intune, is to give it enough time to sync and then wait for a user to login. You then need to remove that user as the Primary User, so the machine changes to 'Shared Device' mode. Which is a pain but I'm hoping some scheduled scripting might resolve this, not sure.

 

This site has been a big help to me, mainly the 'Things that can go wrong' section at the end.

https://intunestuff.com/2025/01/28/microsoft-intune-autopilot-hybrid-entra-id-azure-ad-join-the-complete-guide/

 

Once joined to Intune, I've got Apps set to be required and optional on machines. Based on the 'System' context for the apps installation. Mainly of these are targeting groups I had setup in my local AD which I used to use for App-V targeting. Sometimes can be slow, but sometimes quick. Not done enough testing yet to work out why this is, but it's working which means I'm now enjoying some eduhobnobs in celebration. Well, in truth I've had it working over the week, I'm still enjoying them though soo..

 

Hope this helps those on a similar path to me. If I find anything more of use I'll let you know, but feel free to ask questions if you want more info.

 

Cheers,

Rob

Posted

These are currently Windows 10 local domain devices, office, classroom teacher and ICT Suite machines. So they've always been onsite AD & GP managed. So while full Entra ID & Intune controlled might be the end goal, the plan with this step moving to Windows 11 is to dip our toes in the water lets say.

 

We do have staff laptops which are solely Intune managed. They work well but have some downfalls for more shared user use. Currently Papercut MF is my main concern with moving to cloud joined and managed. Our staff laptops are printing via Mobility Print, which works but doesn't feel 'Mass printing' ready.

Posted

I went from domain joined to hybrid and then finally to Entra only. Taking this route allowed me to gradually move to Entra one careful step at a time whilst learning Intune and Autopilot in the process. I spent time getting all the apps we use into Intune and playing around with test devices and configuration until I felt comfortable enough to unlease Intune on the school.

 

I still have a local Papercut MF server and we use Print Deploy to get the queue onto devices. Talk to your Papercut support, they will be able to help.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...