Windows 10 Auto-enrollment

AutoEnrollment

Autoenrollement for Windows 10 devices

Since Windows 10 1709, it is possible to automatically enroll the computer on Azure Active Directory (AD). For this you can use using a group policy parameter.

Requirments for Autoenrollment

Autoenrollment requires meeting some prerequisites :

  • Computer running Windows 10 1709 or later
  • Mobile Device Management (MDM) service has configured
  • Active Directory is synchronised with Azure Active Directoy
  • ADMX for Windows 10 if your domain controllers runs on Windows Server 2012 R2.

synchronized Active Directory with Azure Active Directory

It is important to synchronize the Active Directory with the Azure Active Directory. Azure AD hybrid must be configured. You can use the links below links :

Configure Application on Azure AD

On the Azure portal (azure.microsoft.com), click on Azure Active Directory.

Access to the Azure Active Directory portal

Windows 10 Auto-enrollment

On the menu click on Mobility (MDM and MAM) and select Microsoft Intune on the central panel.

Configure Intune Application

Windows 10 Auto-enrollment

Configure MDM User Scope. If you want apply parameter to all user, select All. if you need to apply to some user, select Some and choose Azure Active Directory Groups. This group can be synchronised to Active Directory or can be created directly to Azure Active Directory. Click on Save to validate the choice.

Configure MDM Parameter

Windows 10 Auto-enrollment

Configuration on on-premise infrastructure can now be performed

Configure group policy on AD on premise

From the domain controllers access the Group Policy Management console. Expand Domains, Your domain name and click on Group Policy Objects.

Group Policu Management console

Windows 10 Auto-enrollment

Right click on Group Policy Objects and click on New on the context menu. Enter the desired name and click OK.

Create GPO for AutoEnrollment

Windows 10 Auto-enrollment

Right click on the GPO and select Edit. On the Group Policy Management Editor, expand Computer Configuration, Policies, Administrative Templates, Windows Components, MDM.

Activate MDM Enrollment with Group Policy.


Windows 10 Auto-enrollment

Double click on Enable automatic MDM enrollment using default Azure AD credentials and click on Enabled. Click on OK.

Activate Enable automatic MDM enrollment using default Azure AD credentials

Windows 10 Auto-enrollment

Link the group policy to the root of the domain or the desired organizational unit. Restart the computer and open a session with user account. Open Windows Settings and cick on Accounts.

Accounts on Windows Settings

Windows 10 Auto-enrollment

Select Access Work and school on the menu. The connection at the domain Active Directory appear. Click on Info.

Select Info button

Windows 10 Auto-enrollment

Information about connection and sync status are present on the Windows.

Information about the connection and sync status

Windows 10 Auto-enrollment

The computer has been present on Intune console.

Computer on Intune console

Windows 10 Auto-enrollment

Verify auto-enrollment

Event viewer can permit to verify if auto-enrollment is been applied. Open event viewer and expand Appliations and Servces log, Microsoft, Windows, DeviceManagement-Enterprise-Diagnostics-Provider and Admin.

Access to the eventlog Device-Management
Windows 10 Auto-enrollment

If the auto-enrollment worked, event with ID 75 is present.

Event id 75, auto-enrollment work fine
Windows 10 Auto-enrollment

Troubleshooting

This section contains some errors I may have had when I implemented auto-enrollment.

Error Auto MDM Enroll : Credential (0x0), Failed (the system try to dekete the JOIN of a drive that is not joined). If you have this error, Azure AD hybrid is not configured or computer account not synchronised. Refer you to my article on the subject (the link is present earlier in this article).

Error Auto MDM Enroll : Credential (0x0), Failed (Unknow Win32 Error Code 0x8018002b). MAM User Scope has activated. Select None and try auto-enrollment.

Configure Scope MAM
Windows 10 Auto-enrollment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.