Jump to content

Recommended Posts

Posted

I've ran an Intune pilot with a group of staff where it went really well.

 

Finally SLT took the plunge and we have got 100 laptops ready to deploy, except the deployment isn't doing the same as the original pilot.

 

All laptops are refurb Dell Latitudes 5420 - SCCM to deploy the initial Windows 11 image and then some powershell scripts to add the Hardware hash to intune - this bit works perfectly.

 

Member of staff comes along, signs in to start the enrollment process and then leave, and the laptop does its thing......

 

Laptop reboots and staff log in again and it continues phase 3 of the enrollment process (finishes installing apps) - I don't remember it doing this during the pilot (but this was 3 months ago and a lot has happened since for me to remember)

 

Laptop finishes the whole process, staff log in and set up the windows hello and all good.

 

On the original pilot laptops - if  I logged in or another member of staff logged in at a later dates, the laptop would just do the Windows Hello bit and then all good.

 

On the laptops ready to deploy to staff, if I or another member of staff log in, it starts from Phase 3 of the deployment (installing apps) - which has be confused as it had never done this before. - Is this normal behaviour??

 

Also on MS Endpoint/Intune - Devices -> Enrollment -> Windows Autopilot Devices, if I go to a pilot laptop, it show the user assigned, on an new laptop it doesn't (even though the user has logged in) - I have never assigned users this way (or that I can remember) - again should user automatically be assigned to the laptop if they enrolled it?  - It shows them as the primary user under the device -> Windows Devices.

 

I'm confused and concerned that the pilot group enrollment is behaving slightly differently to the production deployment.

 

Any intune guru's about to help shine a light for me 🙂

 

Cheers

Posted
1 hour ago, mdrabble said:

Laptop reboots and staff log in again and it continues phase 3 of the enrollment process (finishes installing apps) - I don't remember it doing this during the pilot (but this was 3 months ago and a lot has happened since for me to remember)

 

I've been going through the same thing just recently, trying to perfect my Intune build. If you have to login to continue the enrolment process (I'm assuming you've got the Enrolment Status Page (ESP) and a handful of software that has to install before ESP can finish), this suggests that there's been an unexpected restart somewhere in the process. This is normally caused by a software title installing and causing a reboot. Check the logs to see what was installing just before the process was interrupted.

 

 

Quote

Also on MS Endpoint/Intune - Devices -> Enrollment -> Windows Autopilot Devices, if I go to a pilot laptop, it show the user assigned, on an new laptop it doesn't (even though the user has logged in) - I have never assigned users this way (or that I can remember) - again should user automatically be assigned to the laptop if they enrolled it?  - It shows them as the primary user under the device -> Windows Devices.

 

I did our AutoPilot slightly differently to you. I created an AutoPilot profile and dropped it into the device's C:\Windows folder during imaging, which causes it to enroll during OOBE. I then have a policy set, to register all devices to AutoPilot. But that aside, none of my devices in AutoPilot are registered to a user. They're registered to the enrolling user in Intune Devices, but nothing under AutoPilot Devices.

Posted
1 hour ago, mdrabble said:

I'm confused and concerned that the pilot group enrollment is behaving slightly differently to the production deployment.

 

Maaaate. The Thursday group will behave to the Tuesday group in Intune. I've had to reconcile myself to "it works 95% of the time" tbh.

  • Haha 1
Posted
2 hours ago, mdrabble said:

I'm confused and concerned that the pilot group enrollment is behaving slightly differently to the production deployment.

 

 

Congratulations welcome to intune :p 

  • Haha 3
Posted

Nice to know I'm not going mad!

 

I've been googling, double checking settings reimagining test machines exactly the same way as the pilot group - even resorted to ChatGPT!!!!

 

on a slightly different question, on the enrollment I have app set to device groups but it waits until the account setup before installing them - is this normal?

 

Beginning to think I've gone down a rabbit hole and wish I stayed as I was.....

Posted
16 minutes ago, mdrabble said:

on a slightly different question, on the enrollment I have app set to device groups but it waits until the account setup before installing them - is this normal?

 

New one on me. What kind of apps are we talking, Win32, LOB, or Microsoft Store?

 

If you check in the settings of the app itself, under Properties and below the install commands, is the install behaviour set as System or User? Could be a user-focused app that you've deployed to a device group, maybe?

  • Like 1
Posted
19 minutes ago, mdrabble said:

Beginning to think I've gone down a rabbit hole and wish I stayed as I was.....

 

Questioning one's sanity also seems to be a normal feature of Intune, I have noticed. 

  • Like 1
Posted
17 minutes ago, DavR said:

 

New one on me. What kind of apps are we talking, Win32, LOB, or Microsoft Store?

 

If you check in the settings of the app itself, under Properties and below the install commands, is the install behaviour set as System or User? Could be a user-focused app that you've deployed to a device group, maybe?

 

Combination of all 3 - the LOB I need to change over to Win32

 

Win32 - all set for System

LOB - set to Device

MS Store - 

 

Install behaviour is either as System For Win32/Store and Device for LOB

 

Apps are assigned to Dynamic Device groups which targets the Autopilot device with a Staff device tag.

 

May have to chalk this down to another intune "Feature"

Posted

Are all of these appearing in the ESP, after the user logs on for the second time, after enrolment?

 

I'm wondering if this is to do with that unexpected reboot in the process again. I'd try and resolve that as a priority. 

Posted

Happening on ESP and then app continue after the reboot - which I have gone through the apps and change the Device restart behaviour to No specific action.

 

About to reimage laptop again and will see what happens next....

Posted

ok.... did a fresh start rather and a re-image and now apps are installing correct via the Device Setup 😕

 

Think it just which way the wind is blowing if Intune does things correctly 🤣

Posted

Yep, that sounds about right. Sometimes it pays to just send it round again and hope for the best 🤣

 

As long as it's working, that's the main thing.

  • Like 1
Posted

bit of a random ask, but how is your ESP configured?

I have a feeling I may have changed something which is why the ESP is showing when other people are signing in.

 

Current i have Only show page to devices provisioned by out-of-box experience (OOBE) set to No, should this be set to yes?  I have a feeling it should be......

Posted

image.png.7676104f5640b5da6d8bd431582f61e0.png

 

I have mine set to "Yes", but then, I think the only route my devices have into Intune is via OOBE. I can't think of another one, off the top of my head. Your scenario may be different if you're building the device in SCCM then registering via scripts.

 

Even so, though, I would only expect that ESP screen to run once (re-starting at successive logons if it hasn't completed). Are you still seeing the ESP at unexpected times then, I thought you'd had a clean install on your last test? 

  • Thanks 1
Posted

Changing to Yes has solve it!

 

I had a look through all the notes i made during the testing process and i made little note to say I had changed it to see what effect it made and then totally forgot about it as I didn’t test after that until now.

 

I am definitely beginning loose my marbles as I don’t even remember changing that setting or making the note - but it was in my notepad in my handwriting!

 

I’m feeling so relieved! As tomorrow begins the rollout of 100 laptops to staff!  

 

@DavR thank you so much for your patience and help 🙂

 

Posted

 

Ah, great news! So does this mean that this removes the ESP from your deployment scenario? Or just confines it to the correct part of the process?

 

Best of luck with the deployment starting tomorrow. Do let us know how many different outcomes you get, running the exact same sequence on the exact same hardware 😉

 

Posted

Confine to the correct process.

 

Adding mgmt things

device config

user config

 

once completed additional users don’t see the ESP, which is how it originally worked.

 

Important as I can have spares configured for supply staff and hot swaps for damages.

Posted

You know, that totally makes sense now. 

 

Only show during OOBE = Only show for device setup, plus for the user that enrolled. If you set that to No, then people who are simply new to the device also get an ESP screen, rather than just processing whatever it needs to do in the background. 

 

Having never tweaked that setting, it would never have occurred to me that this behaviour might exist. Well remembered.

Posted

🤬😭:censored: I official hate intune!!  Is it too late to switch from 365 to google and chrome books????

 

So I take the laptop out of the box, plug in, member of staff signs in and it bypasses apps and then goes to desktop, where it then installs apps.

 

Do a fresh start on the device and start the process again and it looks like there is an application error somewhere.

 

Why it wasn't flagged on the initial sign in I have no idea, it waited until the fresh start was done to reveal the issue!

 

Have exported the logs to try and find the issue.
 

 

Posted
4 minutes ago, mdrabble said:

🤬😭:censored: I official hate intune!!  Is it too late to switch from 365 to google and chrome books????

 

So I take the laptop out of the box, plug in, member of staff signs in and it bypasses apps and then goes to desktop, where it then installs apps.

 

Do a fresh start on the device and start the process again and it looks like there is an application error somewhere.

 

Why it wasn't flagged on the initial sign in I have no idea, it waited until the fresh start was done to reveal the issue!

 

Have exported the logs to try and find the issue.
 

 

Sorry, just scanned the thread,  I didn't see if you are deploying apps to users or to devices? I only ever assign apps to devices as that's the only reliable way I've found if its a shared device (even as hot spares). I had no end of issues if I assigned to users, I believe best practice is to not mix up both user and computer assignment. 

Posted

When you say, the member of staff signs on, is this part of an OOBE first run sequence, or, have you pre-prepped the laptop in some way and they're going straight to a standard user logon?

 

When we changed ESP to OOBE Only = YES, that will mean that apps etc will only install either during the OOBE process, OR, they'll run in the background after first login. If we're not doing OOBE, then under this setting there is no chance for the apps to installed pre user's first login.

 

I'm enrolling all of mine using an enrolment account via OOBE at first run. This means the ESP sequence runs for that enrolment account user, and that user only. When that's done, it's fully prepped, no further installs required.

Posted
7 minutes ago, buzzard said:

Sorry, just scanned the thread,  I didn't see if you are deploying apps to users or to devices? I only ever assign apps to devices as that's the only reliable way I've found if its a shared device (even as hot spares). I had no end of issues if I assigned to users, I believe best practice is to not mix up both user and computer assignment. 

 

Apps assigned to device as I wanted them to be available for any user that logs in.

Posted
3 minutes ago, DavR said:

When you say, the member of staff signs on, is this part of an OOBE first run sequence, or, have you pre-prepped the laptop in some way and they're going straight to a standard user logon?

 

When we changed ESP to OOBE Only = YES, that will mean that apps etc will only install either during the OOBE process, OR, they'll run in the background after first login. If we're not doing OOBE, then under this setting there is no chance for the apps to installed pre user's first login.

 

I'm enrolling all of mine using an enrolment account via OOBE at first run. This means the ESP sequence runs for that enrolment account user, and that user only. When that's done, it's fully prepped, no further installs required.

 

@DavR thank you for helping - and If anything I type comes across as rude etc, it not meant - not having a great morning as you can imagine 🤣

 

I'll try and go through the whole process from start to finish - but what I dont get it how it worked perfectly during the pilot and then has gone :censored:

 

SCCM process installs a "gold" image of Windows 11, 24H2 at the very end of the Task Sequence, it use to run 3 PowerShell scripts (have since disabled these scripts and put a pause command in, to run the scripts manually as they sometimes timed out)

 

Script 1 - copy files to C drive

Script 2 - Grab Hardware Hash and upload online

Script 3 - Remove SCCM client and clean up files, then run Sysprep /oobe and reboot.

 

Scripts from here - Intune Hardware Hash Import During Task Sequence | credibleDEV

 

Screenshot of TS attached.

 

Laptop reboots and then get to the welcome page - School landing page, ready for user to sign in and start the Intune process.

 

User logs in and then the ESP kicks in, completed the Device Prep stage, no issue

Device setup, it skipped the apps

User Setup, again skipped the apps and then finally you would complete the Windows hello and get to the desktop, where apps would then start to install :confused2:

 

Using Intune, I then selected the laptop and select fresh start, laptop reboots, goes through the clean up process and then back to the welcome page ready for user to sign in again.

 

This time when the user signs in, on the Device setup stage, it recognises apps to install and then gives and error 0x800700c1 which I think is to do with Win32 apps, when I expand things, I see error 0x0000000

 

What I don't understand, is why is this error not showing on the initial setup and skips the apps (I am guessing it skips the apps due to the error) - but then why install the apps when at the Desktop???

 

Why does it only appear when Fresh Start has been triggered??

 

All the apps have deployed out on the pilot group, so I really dont understand what is going on or what has changed.

 

I have exported the MDMLogs, which I am staring at and going eh?

 

other option is to remove all apps and add then back one by one and re image laptop after each test to workout which app causing the issue. - Thankfully I can narrow down the list to 11 apps, as it mentioned Win32 issue, so I can ignore LOB or Store apps.

 

Cheers

Mark

 

 

 

 

Screenshot 2025-06-16 113543.png

IMG_0957.jpg

IMG_0956.jpg

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...