Hello,
we (IT) are looking at Intune and autopilot to deploy and manage our windows laptops and Samsung phones,.

I am a complete newbie to Intune, (bar watching a few courses on the subject)
so today, i said id try to enroll my laptop in Intune.

Under Windows Enrolment, i have changed the “Automatic Enrolment” Scope to “Some” Rather than “All” for testing. I have Created a group “Intune-TestMDM” and have added my regular user account as a member of that group.

i went to the MS Store, Downloaded the company portal, and signed in.

when i sign in, i get a message that “This device hasn’t been set up for corporate use yet, Select this message to begin Setup”
when i click that… the “Connect this device to work” has an exclamation on it, so i choose “Next”, Then “connect” then at “Setup a work or school account” i type my email address, press Next, and then i get “you don’t have the right privileges to perform this operation, please talk to your admin”

I’m a bit stumped.
the account in question has a "Microsoft 365 Business Premium " license assigned to it .

The laptop is already Domain Joined, (all pcs etc are Domain joined) , can it also be added to azure for management?

Any advice on what i need to check, id greatly appreciate it.

Thanks D

5 Spice ups

Only an account with admin privileges on the device can enroll the device into MDM. You need to open Company Portal as an administrator.

4 Spice ups

Hi @Evan7191
when i try that, i get the following.

Inital logon with Admin account, and then try to setup work or school account “your device is already connect to your organization”

so im still stuck…

Try opening command prompt or Powershell as an administrator and run the following:

dsregcmd /status

That will show the debug of Entra join and Intune enrollment.

2 Spice ups

You said the laptop was Domain joined. It will have to be removed from the Domain before it can be enrolled in Intune. Unless you set up a hybrid azure environment, which I believe requires more configuration on the Azure/Intune side.

5 Spice ups

This is a good point and relevant to OP’s situation. For proper hybrid enrollment, Entra Connect is needed. However, a provisioning package can enroll domain-joined workstations to Intune even without hybrid configuration.

2 Spice ups

Microsoft Partner # 2487855
Please ensure account@org.com IE your email address in use, is actually strapped into the same org account as intended Intune licensing. Sometimes when you setup stuff like this even if you have a GA on org, you wind up spawning in new-org.

1 Spice up

Others have hit on it. Either you are domain joined, or Entra joined, but there is a step between, hybrid joined, in which you can create a GPO and have devices auto-enroll (hybrid) to Entra. Entra Connect formerly Azure Active Directory Connector, can also be used to synchronize devices from Active Directory into Azure Active Directory (Entra). You can synchronize devices and users.

I am assuming though if you have 365 and a domain, that you may already be synchronizing domain users, you may just need to add devices now.

1 Spice up