question

HerasymAndrew-0832 avatar image
0 Votes"
HerasymAndrew-0832 asked AndrewMcAllister-1763 commented

Azure AD + Intune - double records

Hi.
When i enroll device to intune azure AD creates 2 records - one without owner but registered in MDM and second has owner but don't registered in MDM
154436-%D0%B7%D0%BE%D0%B1%D1%80%D0%B0%D0%B6%D0%B5%D0%BD%D0%BD%D1%8F.png
It's a big trouble - because i has policy "Conditional Access" to access to corporate documents and it doesn't understand that PC is in MDM.



mem-intune-enrollmentazure-ad-domain-services
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak-MSFT avatar image
1 Vote"
MarileeTurscak-MSFT answered AndrewMcAllister-1763 commented

This is expected if you do not have auto-enrollment enabled. The documentation covers this issue and the resolution:

"If you do not have Auto-MDM enrollment enabled, but you have Windows 10/11 devices that have been joined to Azure AD, two records will be visible in the Intune console after enrollment. You can stop this by making sure that users with Azure AD joined devices go to Accounts > Access work or school and Connect using the same account."

It should show up with no owner but say "Intune" in the MDM column, like the first entry in your screenshot, and it should have the same Device ID as what appears in the Intune portal.

See also, Two records under AAD Device

Please let me know if this helps.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

We have a similar issue, except that we definitely have auto-enrollment enabled both items have different IDs but the same name
191410-image.png


0 Votes 0 ·
image.png (20.5 KiB)
HerasymAndrew-0832 avatar image
1 Vote"
HerasymAndrew-0832 answered MarileeTurscak-MSFT commented

Thanks.
I has disable Auto enrollment.
At now I set "MDM user scope" to "All". I thinks its help me.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks for confirming!

0 Votes 0 ·