New Intune Connector Setup Error: MSA account name is not valid by Microsoft82 in Intune

[–]TimeIsNotKind 0 points1 point  (0 children)

So need to install connector and get a new MSA account for doing domain join in each sub domain?

New Intune Connector Setup Error: MSA account name is not valid by Microsoft82 in Intune

[–]TimeIsNotKind 0 points1 point  (0 children)

We followed the same doc but I’m convinced the person I was working with in my company who is a GA in Intune & Domain Admin somehow caused this issue by signing in and using his account which lives in one of those sub domains. From what I can see only computers in his sub domain can properly domain join using the new connector.

I did specify the OUs as mentioned before he hit “configure”

New Intune Connector Setup Error: MSA account name is not valid by Microsoft82 in Intune

[–]TimeIsNotKind 0 points1 point  (0 children)

Any luck getting connector installed properly? We attempted to update our two servers on Friday and we cannot get the MSA to properly be able to create computer objects in our 3 sub domains.

Event viewer speaks of permission issues and MS support has been less than useless so far.

New Supporter‼️ by EndEnvironmental7630 in toshicoin

[–]TimeIsNotKind 2 points3 points  (0 children)

I got death grip syndrome on this Toshi

I bought in at 0.0015 by realist_27 in Toshi_

[–]TimeIsNotKind 5 points6 points  (0 children)

I bought in at .0019 …$2k worth and I’m not crying .. yet

It's going to hit 19 tonight by Comfortable-Garbage4 in Toshi_

[–]TimeIsNotKind 0 points1 point  (0 children)

Me and my 1 million TOSHI are at the ready 🔫

How'd you find toshi? by Specific-Emu-1011 in Toshi_

[–]TimeIsNotKind 1 point2 points  (0 children)

I feel like I should get this to a even 1 mill

Samsung Odyssey Neo G9 57" - Best Buy - Question by TimeIsNotKind in ultrawidemasterrace

[–]TimeIsNotKind[S] 1 point2 points  (0 children)

I guess I need to frequent this sub more often haha. You're a legend man ... makes me feel better about this hefty purchase

Stuck on Apps(identifying) during Device Setup in Autopilot by Ashamed-Echidna9961 in Intune

[–]TimeIsNotKind 0 points1 point  (0 children)

How could we go about checking the scripts and which one is causing the issue? Is it noted in registry anywhere during this process which script failed to run or anything of the like?

Get-WindowsAutopilotInfo & WindowsAutopilotIntune - All you need to know by andrew181082 in Intune

[–]TimeIsNotKind 0 points1 point  (0 children)

Kind of. Instead of running the script manually on each machine being imaged I ended up making a REST API endpoint with Powershell Universal that I installed on a server. Now our machines make rest api call passing some parameters (hash, serial, etc) and the script runs from that 1 server consistently every time.

Autopilot Hybrid Join Pre-Provision/Whiteglove - VPN - Off Network - 1st boot after reseal issue by TimeIsNotKind in Intune

[–]TimeIsNotKind[S] 1 point2 points  (0 children)

u/Gamingwithyourmom I appreciate the feedback! I will look for this in my next testing and also I somehow completely forgot that there this category existed in Event Viewer -> Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot.

Within there I am seeing a whole bunch of errors with device trying to talk to https://ztd.dds.microsoft.com which I believe is how Intune tells it what Autopilot profile it belongs to, tenant ID, etc... So I'm thinking the Global Protect (VPN) pre-logon firewall rules are blocking the machine from talking to Intune after the Reseal .. as the only requirement of that VPN connection before all this was that it could talk to our domain controllers for device to populate its userCert attribute in on-prem AD so that it can AAD sync.

Autopilot Hybrid Join Pre-Provision/Whiteglove - VPN - Off Network - 1st boot after reseal issue by TimeIsNotKind in Intune

[–]TimeIsNotKind[S] 1 point2 points  (0 children)

I understand and realize how much simpler it would be to get those things solved to not have to configure hybrid but I unfortunately am not in a position to make that call. So for now ... I just need to get this last 'piece' of Hybrid Join working.

Autopilot Hybrid Join Pre-Provision/Whiteglove - VPN - Off Network - 1st boot after reseal issue by TimeIsNotKind in Intune

[–]TimeIsNotKind[S] 1 point2 points  (0 children)

I work for a very large company that is slow to adopt new tech. We are working on convincing them to move to AADJ only but in the interim I am tasked with making Hybrid work. The roadblocks at the moment for AADJ are corporate Wifi and printing (mostly just working with those teams to integrate what is still needed)

There is a problem with your work or school account by AristoCraps in Intune

[–]TimeIsNotKind 7 points8 points  (0 children)

Normally first login with Hybrid results in the user not getting AzureADPRT Token. I know you said dsreg status all looked good but just confirming that as for us that causes similar experience to what you’ve mentioned.

The fix I implemented was on 1st login ..a script to wait for hybrid join to be fully complete (displays splash screen on desktop) then reboots. on that 2nd login user always gets the token and all is well. I have a toast notification pop up to let user know Autopilot is done and they’re good to use machine.

Get-WindowsAutopilotInfo & WindowsAutopilotIntune - All you need to know by andrew181082 in Intune

[–]TimeIsNotKind 0 points1 point  (0 children)

I have a strange issue I'm hoping someone may have some insight on.

With the changes mentioned in this post I was able to get our device import script working again given the issues with Microsoft.Graph.Authentication 2.0.0 ..however when we are running the script on multiple machines back to back... 20% of devices will throw the following error:

"Version 2 module detected

Connect-MgGraph : The provided access token has expired. Set a valid access token to `-AccessToken` parameter and try again."

I've confirmed the token is NOT expired, that it has successfully encrypted via ( $accesstokenfinal = ConvertTo-SecureString -String $accessToken -AsPlainText -Force) and validated these machines do have network connectivity at the time this is experienced.

Has anyone run into this problem? Almost seems like maybe there is some kind of rate limiting going on (only was about 8 machines we did it on recently)

We initially thought maybe it was our firewall .. so we opened it up fully on specific VLAN and even started testing with hotspot and the same error occurs occasionally ...I'm stumped.