Intune auto enrollment

karthik palani 1,036 Reputation points
2022-09-25T17:13:23.817+00:00

Hi All,

I am trying to auto enroll the Windows 10 21H1 devices to Intune. All devices are Hybrid AD but some how its not enrolling in to Intune.

The user ID are part of MDM auto enroll group, also group policy applied to all devices with user credential option.

We dont have conditional access policy or any conflicting policies

"Error: Auto MDM Enroll: Device Credential (0x0), Failed (Unknown Win32 Error code: 0x8018002a)
Warning: Auto MDM Enroll DmRaiseToastNotificationAndWait Failure (Unknown Win32 Error code: 0x8018002a)"

Tried rejoining the machine to Hybrid AD, manual enroll is working fine. Please advice on how to fix this issue

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,996 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,423 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,569 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 51,981 Reputation points Microsoft Vendor
    2022-09-26T02:39:48.55+00:00

    @karthik palani , For the error "Auto MDM Enroll: Failed (Unknown Win32 Error code: 0x8018002a)", it may occur when multi-factor authentication (MFA) is Enforced. if prevents the enrollment. Please try one of the following methods to see if it ca be fixed:

    • Set MFA to Enabled but not Enforced. For more information, see Set up multi-factor authentication.
    • Temporarily disable MFA during enrollment in Trusted IPs.

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-co-management-auto-enrolling#hybrid-azure-ad-joined-devices-fail-to-enroll-and-generate-error-0x8018002a

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. karthik palani 1,036 Reputation points
    2022-09-26T12:18:05.5+00:00

    After disabling MFA, i got test machines enrolled automatically. So should i disable MFA for all users and perform the enrollment.

    Or is there any other ways to follow. Please advice


  3. Muhammad Safeer Saqib 6 Reputation points
    2025-02-13T08:44:39.6233333+00:00

    Hi @Crystal-MSFT ,

    I have same issue where I excluded the device from the Conditional Access policy requiring "device compliance" but didn't disable MFA and its working. Now considering whether excluding Microsoft Intune and Microsoft Intune Enrollment from the Conditional Access policy would work, instead of disabling MFA for all users?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.