When you try to auto-enroll a device in Microsoft Intune by using Windows 10 Mobile Device Management (MDM) through a Group Policy Object, the attempt fails, and you experience the following additional symptoms:
- The Task Scheduler generates an error on the \Microsoft\Windows\EnterpriseMgmt\Schedule folder. This folder is created by the enrollment client that automatically enrolls a device in MDM from an Aaure Active Directory (Azure AD) task. The last-run result is as follows:
Event 76 Auto MDM Enroll: Failed (Unknown Win32 Error code: 0x8018002b)
- In Event Viewer, you may also see the following event logged under Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin:
Log Name: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin
Event ID: 76
Description: Auto MDM Enroll: Failed (Unknown Win32 Error code: 0x80180002b)
- Open Active Directory Users and Computers.
- Select the user object for the affected user.
- Open Properties, and then select the Account tab.
- Change the UPN suffix to a valid value (for example, from contoso.local. to contoso.com).
After you complete these steps, either wait for the next synchronization to occur, or force a delta sync from the synchronization server. To do this, following these steps:
- Open an administrative PowerShell window.
- Run the following commands:
Start-ADSyncSyncCycle -PolicyType Delta
Note If this method does not resolve the problem, see the following Knowledge Base article:
4463749 "0x8018002B" error and Windows 10 MDM auto-enrollment for Intune fails if the user scope is set to None