The Trials and Tribulations of InTune Auto-Enrollment - Tips and Tricks

Infostruction banner: a person holding a mug stands in a dim home office lit by server racks and monitors, with the Infostruction logo and wordmark across the centre.

Encountering errors during InTune auto-enrollment can be like navigating a maze without a map. But don’t worry; we’re here to provide you with the “map” and some handy “tools” to conquer this labyrinth. Let’s dissect these common errors and how to resolve them, turning your InTune enrollment journey from a daunting task into a walk in the park.

The Errors:

  • Auto MDM Enroll: Device Credential (0x0), Failed (Unknown Win32 Error code: 0x8018002a)
  • Auto MDM Enroll DmRaiseToastNotificationAndWait Failure (Unknown Win32 Error code: 0x8018002a)
  • MDM Session: OMA-DM message failed to be sent. Result: (Unauthorized (401)).
  • MDM Session: Failed to get AAD Token for sync session User Token: (Unknown Win32 Error code: 0xcaa2000c) Device Token: (The operation completed successfully.).
  • MDM ConfigurationManager: Caller did not specify user to impersonate to. Targetted user sid: (NULL) Result: (Unknown Win32 Error code: 0x86000022).
  • Event ID 76 Error Auto MDM Enroll: Device Credential (0x0), Failed (The background task activation is spurious.).

Diagnostic Toolkit

To peel back the layers of these errors, we’ll need to roll up our sleeves and dive into some diagnostics:

  • Scheduled Tasks: Peek into potential enrollment tasks with schtasks /query /fo LIST /v | findstr /i "InTune MDM Enroll".
  • Registry Recon: Navigate through HKLM:\SOFTWARE\Microsoft\Enrollments using Get-ChildItem to uncover any stale registrations.
  • Event Log Insights: Leverage Get-WinEvent -LogName "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" -MaxEvents 100 | sort TimeCreated | ft -AutoSize -Wrap to decipher detailed event logs.

Solutions Roadmap

Clear Outdated Registrations: Begin by removing old device registrations in Azure AD under Identity -> Devices to avoid any conflicts.

Deploy the Cleaner Script: Run a dedicated script to eliminate any lingering UPNs from the system. This step doesn’t necessarily require a reboot, so give it a try right away.

Direct Enrollment Commands: Use the command line to force the enrollment using these two commands. Ensure you’re executing these as the user entitled to InTune via Business Premium or an InTune plan.

  • gpupdate /force
  • %windir%\system32\deviceenroller.exe /c /AutoEnrollMDMUsingAADDeviceCredential
  • %windir%\system32\deviceenroller.exe /c /AutoEnrollMDM

Monitor the logs looking for good activity on the device, and reboot it, then try to perform the step again.  Nothing new just a remix of info I’ve found and particular way of going about it.

Post-Procedure Checkup: After running through the fixes, revisit the event logs to ensure all is clear and no new errors have surfaced.

Share your thoughts, leave a comment

Your email address will not be published. Required fields are marked *

You may also like these

INFOSTRUCTION

You're about to become an infostruction VIP!

By subscribing, you’ll receive a monthly round-up of the latest news. There’ll be no spam, I promise :)