Encountering errors during InTune auto-enrollment can be like navigating a maze without a map. But don’t worry; we’re here to provide you with the “map” and some handy “tools” to conquer this labyrinth. Let’s dissect these common errors and how to resolve them, turning your InTune enrollment journey from a daunting task into a walk in the park.
The Errors:
- Auto MDM Enroll: Device Credential (0x0), Failed (Unknown Win32 Error code: 0x8018002a)
- Auto MDM Enroll DmRaiseToastNotificationAndWait Failure (Unknown Win32 Error code: 0x8018002a)
- MDM Session: OMA-DM message failed to be sent. Result: (Unauthorized (401)).
- MDM Session: Failed to get AAD Token for sync session User Token: (Unknown Win32 Error code: 0xcaa2000c) Device Token: (The operation completed successfully.).
- MDM ConfigurationManager: Caller did not specify user to impersonate to. Targetted user sid: (NULL) Result: (Unknown Win32 Error code: 0x86000022).
- Event ID 76 Error Auto MDM Enroll: Device Credential (0x0), Failed (The background task activation is spurious.).
Diagnostic Toolkit
To peel back the layers of these errors, we’ll need to roll up our sleeves and dive into some diagnostics:
- Scheduled Tasks: Peek into potential enrollment tasks with
schtasks /query /fo LIST /v | findstr /i "InTune MDM Enroll". - Registry Recon: Navigate through
HKLM:\SOFTWARE\Microsoft\EnrollmentsusingGet-ChildItemto uncover any stale registrations. - Event Log Insights: Leverage
Get-WinEvent -LogName "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" -MaxEvents 100 | sort TimeCreated | ft -AutoSize -Wrapto decipher detailed event logs.
Solutions Roadmap
Clear Outdated Registrations: Begin by removing old device registrations in Azure AD under Identity -> Devices to avoid any conflicts.
Deploy the Cleaner Script: Run a dedicated script to eliminate any lingering UPNs from the system. This step doesn’t necessarily require a reboot, so give it a try right away.
Direct Enrollment Commands: Use the command line to force the enrollment using these two commands. Ensure you’re executing these as the user entitled to InTune via Business Premium or an InTune plan.
- gpupdate /force
- %windir%\system32\deviceenroller.exe /c /AutoEnrollMDMUsingAADDeviceCredential
- %windir%\system32\deviceenroller.exe /c /AutoEnrollMDM
Monitor the logs looking for good activity on the device, and reboot it, then try to perform the step again. Nothing new just a remix of info I’ve found and particular way of going about it.
Post-Procedure Checkup: After running through the fixes, revisit the event logs to ensure all is clear and no new errors have surfaced.