Intune device enrolment error

Shiv 60 Reputation points
2023-04-28T08:48:12.5033333+00:00

HI,

I can enrol windows devices to Intune but configuration policy, apps and compliance policy is keep pending. Non of the policy are working in any of the devices. I can see multiple errors on the device event viewer.

Errors on the machine.

Event ID: 2545, Source: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property.

MDM Declared Configuration: Function (checkNewInstanceData) operation (Read isNewInstanceData) failed with (The parameter is incorrect.)

Event ID: 404, Source: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property.

MDM ConfigurationManager: Command failure status. Configuration Source ID: (9D618D8F-243A-409C-9D79-5CDB1524A45E), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Receiver/Properties/Policy/FakePolicy/Version), Result: (The system cannot find the file specified.).

Event ID:281 Source : DbxSvc

CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property.

Event ID:1010 Source : ModernDeployment-Diagnostics-Provider

Autopilot.dll WIL error was reported.

HRESULT: 0x80070002

File: onecoreuap\admin\moderndeployment\autopilot\commonutils\hardwareinfo.cpp, line 362

Message: NULL

Can anyone help to resolve this issue.

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
908 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,302 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
144 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-05-01T01:39:52.3933333+00:00

    @Shiv, Thansk for posting in Q&A. For the error MDM Declared Configuration: Function (checkNewInstanceData) operation (Read isNewInstanceData) failed with (The parameter is incorrect.) I suspect this is caused by a failed enrollment performed by ConfigMgr leads to an inconsistent or partially rolled back enrollment state on the client, leaving the device in a state where subsequent enrollment attempts cannot succeed.

    From your description, it seems the windows has already enrolled. Please confirm if the error still occurs now. Go to device side Accounts->Access work or school, find the account, click info and sync to see if the device can sync with Intune successfully.

    Meanwhile, you can also restart the device and see if the result will be different.

    However, if the issue still persists, please collect the following information to clarify:

    1. How many devices are affected? Is any device working well? What is the difference between the working one and the not working one?
    2. Could you confirm if the devices are enrolled with co-management or Autopilot?
    3. For the configuration policy, if we check on the device, has the setting taken affected on the device? For the app, was it installed on the device?

    If there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Shiv 60 Reputation points
    2023-05-02T15:08:38.94+00:00

    Issue resolved by changing the MDM authority from 0365 to Microsoft Intune.

    https://video2.skills-academy.com/en-us/mem/intune/fundamentals/mdm-authority-set#set-mdm-authority-to-intune

    0 comments No comments

  3. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-05-03T02:53:41.0033333+00:00

    @Shiv, Thanks for the update. I am glad to hear that the issue is resolved. Here, please let me write a brief summary to help others find the solution quickly:

    Issue description:

    Get the following errors during windows enrollment and the configuration policy, apps and compliance policy is keep pending.

    Event ID: 2545, Source: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property.

    MDM Declared Configuration: Function (checkNewInstanceData) operation (Read isNewInstanceData) failed with (The parameter is incorrect.)

    Event ID: 404, Source: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property.

    MDM ConfigurationManager: Command failure status. Configuration Source ID: (9D618D8F-243A-409C-9D79-5CDB1524A45E), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Receiver/Properties/Policy/FakePolicy/Version), Result: (The system cannot find the file specified.).

    Event ID:281 Source : DbxSvc

    CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property.

    Resolution:

    Issue resolved by changing the MDM authority from 0365 to Microsoft Intune.

    https://video2.skills-academy.com/en-us/mem/intune/fundamentals/mdm-authority-set#set-mdm-authority-to-intune

    Thanks for your time and have a nice day!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments