I'm attempting to install and enrol the Intune Connector for AD on a member server in our domain. The server had the legacy connector installed and running successfully and I've uninstalled before downloading and installing the update connector.
Attempting to sign into the connector has resulted in a pause and then back to the Enrolment tab.
The ODJConnectorUI.log shows:
ODJ Connector UI Information: 0 : Executing IsMachineEnrolled method
*DateTime=2025-04-02T10:18:32.4560979Z*
ODJ Connector UI Error: 2 : ERROR: Failed to check if machine is already enrolled. Detailed message is: Object reference not set to an instance of an object.
*DateTime=2025-04-02T10:18:32.4580985Z*
ODJ Connector UI Information: 0 : User clicked on SignIn
*DateTime=2025-04-02T10:18:34.0604484Z*
ODJ Connector UI Information: 0 : Navigating to URL https://portal.manage.microsoft.com/Home/ClientLogon
*DateTime=2025-04-02T10:18:34.1444540Z*
ODJ Connector UI Information: 0 : Browser loaded page https://login.microsoftonline.com/common/oauth2/authorize?client_id=74bcdadc-2fdc-4bb3-8459-76d06952a0e9&redirect_uri=https%3A%2F%2Fportal.manage.microsoft.com%2Fsignin-oidc&response_type=code&prompt=select_account&scope=openid profile&response_mode=form_post&nonce=638791859143581307.OGY4NjUyMDMtMDY0YS00ZWE0LWFkNTItNWVlOTNkMmM1OGQyN2U1MGYxZjEtNDk0YS00OThlLThkYjQtYzdhOTgyMzg1ZmU0&display=host&state=CfDJ8Ji1hs71b9ZDlZfpMprk6xWlOKdzjKYJ0BYdxLP5A7zd79QRF83iSe3X1JH9yUSFjVSb4uWWhxdI7A0UeHoNvAYdicyHnbapL1FaTpZIxbbLwN8tTi3iIuhVhwsswF67a6D5mxIhY4tzFBvUPKg8qsJdZMj8G-cmuQ3FQ98hYNX8d6po4XeO7AVY-f5San6oGhxAVk0mXR-y0DTXpQ33Bx6G2mYGhsJy6KKvC8yiZi47r8osEgW1fWErTzamLr_oJdPIU9T-Hh6aAV16iWIF9MTKWiajj9uw_HMTE6I4RriyJfI2TwiaUSqmzCJ0mH0o9meHrawme1A7kPdbgh_Gc0hgbg7ZMTIWqzJHemVnPXqrKw7D9PaWxkf-iIST6Y4ivg&x-client-SKU=ID_NET472&x-client-ver=8.3.0.0
*DateTime=2025-04-02T10:18:34.9712594Z*
ODJ Connector UI Information: 0 : Browser loaded page https://portal.manage.microsoft.com/Home/ClientLogonSuccess
*DateTime=2025-04-02T10:18:49.9886841Z*
ODJ Connector UI Information: 0 : Getting the URL for EnrollmentService from https://manage.microsoft.com/RestUserAuthLocationService/RestUserAuthLocationService/ServiceAddresses
*DateTime=2025-04-02T10:18:50.2627010Z*
ODJ Connector UI Information: 0 : Received Url for EnrollmentService as https://fef.msub03.manage.microsoft.com/StatelessEnrollmentService from RestUserAuthLocationService.
*DateTime=2025-04-02T10:18:50.2627010Z*
ODJ Connector UI Information: 0 : Getting the URL for RAODJPlusFEGatewayService_FEF from https://manage.microsoft.com/RestUserAuthLocationService/RestUserAuthLocationService/ServiceAddresses
*DateTime=2025-04-02T10:18:50.2627010Z*
ODJ Connector UI Information: 0 : Received Url for RAODJPlusFEGatewayService_FEF as https://fef.msub03.manage.microsoft.com/TrafficGateway/TrafficRoutingService/RAODJPlus/StatelessODJService from RestUserAuthLocationService.
*DateTime=2025-04-02T10:18:50.2627010Z*
ODJ Connector UI Information: 0 : Searching for any pre-existing Managed Service Accounts installed on this machine.
*DateTime=2025-04-02T10:18:50.3177048Z*
ODJ Connector UI Information: 0 : MSA name : msaODJotY4G
*DateTime=2025-04-02T10:18:50.6357287Z*
ODJ Connector UI Error: 2 : ERROR: Enrollment failed. Detailed message is: Microsoft.Management.Services.ConnectorCommon.Exceptions.ConnectorConfigurationException: MSA account msaODJotY4G is not valid!
at Microsoft.Management.Services.ConnectorCommon.ManagedServiceAccountUtilities.ManagedServiceAccountUtilities.CreateManagedServiceAccount(String domainName, String precreatedMsaAccount)
at ODJConnectorUI.EnrollmentTab.CreateMsa(String domainName, StepsStarted& stepsStartedFlag)
at ODJConnectorUI.EnrollmentTab.webBrowser_LoadCompleted(Object sender, NavigationEventArgs e)
*DateTime=2025-04-02T10:18:50.8667425Z*
ODJ Connector UI Information: 0 : Storing telemetry: CreateMsaAccount, hasException: True
*DateTime=2025-04-02T10:18:50.8687426Z*
ODJ Connector UI Information: 0 : Sending telemetry: CreateMsaAccount, hasException: True
*DateTime=2025-04-02T10:18:50.8797424Z*
ODJ Connector UI Information: 0 : Sending telemetry to ODJService
*DateTime=2025-04-02T10:18:50.9047425Z*
ODJ Connector UI Information: 0 : RAODJPlus Service URL: https://fef.msub03.manage.microsoft.com/TrafficGateway/TrafficRoutingService/RAODJPlus/StatelessODJService/odjConnectorTelemetry/uploadTelemetry
*DateTime=2025-04-02T10:18:50.9047425Z*
ODJ Connector UI Information: 0 : Successfully sent request to RAODJPlusFEGatewayService_FEF
*DateTime=2025-04-02T10:18:51.5427600Z*
ODJ Connector UI Information: 0 : Response from ODJService: OK
*DateTime=2025-04-02T10:18:51.5427600Z*
ODJ Connector UI Error: 8 : Removing Managed Service Account ...
*DateTime=2025-04-02T10:18:51.5447596Z*
ODJ Connector UI Error: 8 : Successfully removed Managed Service Account
*DateTime=2025-04-02T10:18:51.5457591Z*
ODJ Connector UI Error: 8 : Returning to the home page
*DateTime=2025-04-02T10:18:51.5457591Z*
The Intune | ODJConnector | Operational log is reporting:
ODJRequestHandlingPipelineDownload_Failure: Failed to download ODJ requests.
InstanceId:D0039F3A-05ED-4B89-BD6E-98573D3D371A,
DiagnosticCode:Unknown_Error,
DiagnosticText:We are unable to complete your request because a server-side error occurred. Please try again. [Exception Message: "DiagnosticException: 0x0FFFFFFF. We are unable to complete your request because a server-side error occurred. Please try again."]
My on-prem account has create permissions to the Managed Service Accounts OU and the account is created there. The signed in Entra ID account has an Intune license and the Intune Administrator role
So, what am I missing?