Can't login to AAD-added device

Terry Smith 1 Reputation point
2020-10-01T18:37:20.097+00:00

Second time typing this so I'll try to get to the point:
I've got AAD set up for my school with about 60 devices successfully added and in use.
I just set up a new computer that I was hoping to keep accessible to a few choice accounts in the domain rather than anyone being able to sign in. I created a device configuration profile for this in MDM and applied it to the desktop computer in question.
Now no account is able to log into the computer (including my own). I've deleted the policy but the computer doesn't appear to sync these policies unless it's logged in, which I'm unable to do.
Is there a way to fix this without a factory reset? Perhaps a way to force an AAD sync without logging in?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,783 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,657 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,320 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 45,571 Reputation points Microsoft Vendor
    2020-10-02T03:02:57.233+00:00

    @Andrew HUSSEY From your description, I know after deploying a device configuration profile, no account is able to login although we remove the profile. If there's any misunderstanding, feel free to let us know.

    To sync the Intune policy to the device, we can go to Microsoft Endpoint Manager admin center and go to the device side, choose Sync to see if it is working.
    29736-image.png

    Meanwhile, try to login the device with a local administrator account to see if it is successful.

    In addition, please get a screen shot of the device configuration we set. So that we can test in the lab to get more options.

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. Nick Hogarth 3,436 Reputation points
    2020-10-01T22:25:16.703+00:00

    What was the policy you assigned to the device exactly? Could you login with your AAD account before that? Have you tried initiating a sync from the portal https://video2.skills-academy.com/en-us/mem/intune/remote-actions/device-sync#sync-a-device ?


  3. Andrew HUSSEY 1 Reputation point
    2020-10-05T09:22:37.813+00:00

    Thanks for the replies.

    It turns out that after allocating the correct licence it takes some time for it to propagate.

    Somewhat frustrating that there can't be an error message to say "user not licensed for InTune" or similar.

    Anyway, I appreciate people taking the time to reply.

    Andrew