How to get HAADJ devices enrolled with device credentials to show primary user in Intune?

Ahmed Sh 60 Reputation points
2024-05-17T11:27:36.0966667+00:00

Hello,

I have a question where the scenario is as following.

-Third party tool is used Identity provider (and to provision ad users in 365 cloud )

-Devices are HAADJ joined(using GPO/Ad connect in testing phase).

-Devices are enrolled to Intune using SCCM cloud attach, And MDM auto enrollment with device credentials.

-Primary user showing in Intune is not assigned but can later be manually assigned in cloud.

-To be clear, AD connect is not used to provision users in cloud due to the third party provisioning tool.

-UPN mismatch between AD and Entra is causing us to avoid using user credentials for MDM auto enrollment as onprem domain user is not recognized in the cloud.

Question:

-What method can be used if any to show primary users assigned to the device in Intune (could there be some sort of mapping between cloud and onprem in the current setup?

-Any other suggestions to have the devices enrolled to Intune (Obviously without removing third party identity/Provisioning service)?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,340 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,509 questions
0 comments No comments
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 9,390 Reputation points Microsoft Vendor
    2024-05-20T06:35:29.8833333+00:00

    @Ahmed Sh,Thanks for posting in Q&A.

    I have done some research about this issue, here are some suggestions you can refer.

    1.Hybrid AADJ device will only be assigned a primary user when the user logs into the device for the first time.

    https://learn.microsoft.com/en-us/mem/intune/remote-actions/find-primary-user#who-is-assigned-as-the-primary-user

    2.Based on my searches, you can try the method mentioned in the following link to enroll your device into Intune, but it will remove 3rd party identity/configuration services.

    https://learn.microsoft.com/en-us/mem/configmgr/comanage/tutorial-co-manage-clients

    3.If you want to enroll the device into Intune, it is recommended that you use User credential in Group Policy, but this method will not work with the SCCM cloud attach

    https://petri.com/how-to-automatically-hybrid-azure-ad-join-and-intune-enroll-pcs/

    Non-official, just for reference.

    Hope above information can be helpful.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


2 additional answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more