Jump to content

Recommended Posts

Posted

Hi. Does anyone know how to bypass/skip the registering your device for mobile management when using sccm? Everything was working fine but now the process won't complete at it fails on this screen. It does the securing and joining to AD find but then the rest just fails. In SCCM the agent is yet to NO for automatically enroll. We're not using Intune or MDM so just want it to continue working locally for now?

Anyone else had this and why its just suddenly happened? I'm assuming when the device checks for updates its pulling something down to do this.

thanks

1000042504.jpg

Posted

Is that during OOBE or first login? To me that looks like autopilot (which fires during oobe ). Which suggests that the device’s hardware hash is registered in intune/autopilot. If so,  that failure is pretty normal if you didn’t do something in the intune->enrollment portal to (re) enable that specific device to re-enroll.

 

Posted

The machine doesnt get as far as the login screen. Not sure how it would even contact autopilot/intune as we use proxy server to connect to the internet and the device wouldnt be in InTune.

Posted

Typically proxies/firewalls are configured to allow devices to bypass filtering/proxies for enrolment/management. Unless you built it yourself, or explicitly chose to change what it offered as useful defaults, your devices are probably able to phone home to check for MDM enrolments.

Windows (like MacOS and iOS) phones home during setup and checks to see if it is owned by an org. If Apple/Microsoft have a record for that device, the device is then passed off into the org's preferred MDM to apply org settings etc.  

 

This device appears to have received info from Intune/Autopilot that *somebody* owns it and it needs to fully enrol in their management platform and apply the various settings.  It's for some reason failing at this stage. This could be because your filtering platform is getting in the way , or because stale records exist and the device needs to be "unlocked" in Autopilot.

 

Of course, from your point of view, it does not need to be unlocked because its not supposed to be enrolling in the first place! To resolve this you can  go to autopilot devices and remove it. You will likely have to search for the device there based on its serial number (hostnames don't really exist/are completely arbitrary within the autopilot phase). If the device is not there, then its possible that the device/motherboard has previously been registered in someone else's tenant. I'm not sure the flow to resolve that.  

More info about troubleshooting Autopilot phase here:Windows Autopilot troubleshooting FAQ | Microsoft Learn

 

Posted
1 minute ago, psydii said:

Typically proxies/firewalls are configured to allow devices to bypass filtering/proxies for enrolment/management. Unless you built it yourself, or explicitly chose to change what it offered as useful defaults, your devices are probably able to phone home to check for MDM enrolments.

Windows (like MacOS and iOS) phones home during setup and checks to see if it is owned by an org. If Apple/Microsoft have a record for that device, the device is then passed off into the org's preferred MDM to apply org settings etc.  

 

This device appears to have received info from Intune/Autopilot that *somebody* owns it and it needs to fully enrol in their management platform and apply the various settings.  It's for some reason failing at this stage. This could be because your filtering platform is getting in the way , or because stale records exist and the device needs to be "unlocked" in Autopilot.

 

Of course, from your point of view, it does not need to be unlocked because its not supposed to be enrolling in the first place! To resolve this you can  go to autopilot devices and remove it. You will likely have to search for the device there based on its serial number (hostnames don't really exist/are completely arbitrary within the autopilot phase). If the device is not there, then its possible that the device/motherboard has previously been registered in someone else's tenant. I'm not sure the flow to resolve that.  

More info about troubleshooting Autopilot phase here:Windows Autopilot troubleshooting FAQ | Microsoft Learn

 

Hi

thanks for reply. where would i remove it from as the device wouldnt be enrolled in our own 365 tenant?

Posted
4 hours ago, psydii said:

Check here: Windows Autopilot devices - Microsoft Intune admin center 

You might also be able to check in on the machine itself: Interpreting the Windows Autopilot profile – Out of Office Hours

 

It's also possible something else other than autopilot is causing that screen to appear, but I've only ever seen that during autopilot, or when explicitly enrolling during a non-automated windows install.

Nothing shows in intune because when the machine is imaged how would it know what tenant to try and attach to if no credentials have been entered?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...