Autoenrollement for Windows 10 devices
Since Windows 10 1709, it is possible to automatically enroll the computer on Azure Active Directory (AD). For this you can use using a group policy parameter.
Requirments for Autoenrollment
Autoenrollment requires meeting some prerequisites :
- Computer running Windows 10 1709 or later
- Mobile Device Management (MDM) service has configured
- Active Directory is synchronised with Azure Active Directoy
- ADMX for Windows 10 if your domain controllers runs on Windows Server 2012 R2.
synchronized Active Directory with Azure Active Directory
It is important to synchronize the Active Directory with the Azure Active Directory. Azure AD hybrid must be configured. You can use the links below links :
Configure Application on Azure AD
On the Azure portal (azure.microsoft.com), click on Azure Active Directory.
On the menu click on Mobility (MDM and MAM) and select Microsoft Intune on the central panel.
Configure MDM User Scope. If you want apply parameter to all user, select All. if you need to apply to some user, select Some and choose Azure Active Directory Groups. This group can be synchronised to Active Directory or can be created directly to Azure Active Directory. Click on Save to validate the choice.
Configuration on on-premise infrastructure can now be performed
Configure group policy on AD on premise
From the domain controllers access the Group Policy Management console. Expand Domains, Your domain name and click on Group Policy Objects.
Right click on Group Policy Objects and click on New on the context menu. Enter the desired name and click OK.
Right click on the GPO and select Edit. On the Group Policy Management Editor, expand Computer Configuration, Policies, Administrative Templates, Windows Components, MDM.
Double click on Enable automatic MDM enrollment using default Azure AD credentials and click on Enabled. Click on OK.
Link the group policy to the root of the domain or the desired organizational unit. Restart the computer and open a session with user account. Open Windows Settings and cick on Accounts.
Select Access Work and school on the menu. The connection at the domain Active Directory appear. Click on Info.
Information about connection and sync status are present on the Windows.
The computer has been present on Intune console.
Event viewer can permit to verify if auto-enrollment is been applied. Open event viewer and expand Appliations and Servces log, Microsoft, Windows, DeviceManagement-Enterprise-Diagnostics-Provider and Admin.
If the auto-enrollment worked, event with ID 75 is present.
This section contains some errors I may have had when I implemented auto-enrollment.
Error Auto MDM Enroll : Credential (0x0), Failed (the system try to dekete the JOIN of a drive that is not joined). If you have this error, Azure AD hybrid is not configured or computer account not synchronised. Refer you to my article on the subject (the link is present earlier in this article).
Error Auto MDM Enroll : Credential (0x0), Failed (Unknow Win32 Error Code 0x8018002b). MAM User Scope has activated. Select None and try auto-enrollment.