question

icelava avatar image
icelava asked ·

Can no longer find device serial number in Azure AD for inclusion into group for Windows Autopilot

We have previously been repeatedly deploying test computers with Windows Autopilot according to tutorial

https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm

We have a group assigned to the deployment profile, and that group includes device objects with the serial numbers of HWIDs extracted and imported into Intune. Each test computer went through the procedure just fine.

Today, I imported another .csv with a new HWID. It gets shown in the [Microsoft Intune > Device enrollment - Windows enrollment > Windows Autopilot devices] blade. However, when I go back to Azure AD portal and try to add that device object to the assigned deployment group, I cannot find its serial number (since it doesn't have a name yet) listed in the [Add members] blade. Filtering by serial number doesn't work.

This wasn't a problem before. I think the only significant difference for this particular computer is that it was previously AAD-registered and joined and later enrolled in Intune as separate activities as a test computer for pre-existing states. But it was retired off Intune, and unjoined and deleted off AAD. So that shouldn't cause any remnant artefact problems, would it?

How can I narrow down and locate that specific device object? Or was there something else Intune needed to send to AAD for that entry to exist, but didn't send for some reason?

azure-active-directory
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

icelava avatar image
icelava answered ·

Looks like if the new device (serial number) record does not ultimately flow to AAD, it might be necessary to delete all the records and try re-importing the HWID again. My second test of retiring and deleting (after a manual join/enrol) and then re-importing worked.

https://social.technet.microsoft.com/Forums/en-US/681005b9-ce84-41c9-9228-905817a8de18/cannot-find-device-serial-number-in-azure-ad-after-hwid-import?forum=microsoftintuneprod

Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak avatar image
MarileeTurscak answered ·

How long ago was it added? Hardware and Software Inventory (including serial number) is refreshed every 7 days in Intune, so it's possible that it's just not visible yet. https://docs.microsoft.com/en-us/intune/remote-actions/device-inventory

Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

icelava avatar image
icelava answered ·

What? 7 days? Is that the lead time one must perform Intune side, just so that it can be included in the Azure AD group marked for deployment profile?

In all our tests, the new device records (serial numbers) end up very quickly in AAD when we imported the HWIDs, and we could perform the Autopilot procedure practically immediately.

This problem only happens for computers that previously existed in AAD and had their records retired and deleted off Intune and AAD (fully, at least from the Azure portal UIs perspective). They will never appear as serial-numbered devices; only a manual register/join + enroll procedure client-OS-side will let AAD surface out that device record, with its serial number as a secondary property instead of being the primary identifier (which is computer name by that point).

Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.