Hybrid FooUser issue

Tillo, Travis 0 Reputation points
2026-07-30T23:08:50.93+00:00

On hybrid Entra-joined devices, device-context MDM enrollment (deviceenroller /c /AutoEnrollMDM, MDM app id 0000000a-...) creates an MS DM Server enrollment record stamped with placeholder UPN fooUser@<tenant>.onmicrosoft.com, obtains an MDM certificate, but stalls permanently at EnrollmentState 1 and never appears in Intune. This is 100% reproducible on a fully cleaned device (no prior enrollment records, certs, or tasks) and occurs regardless of SCCM client state. fooUser appears in no configuration, script, or Entra sign-in log — it is generated by the enrollment process itself. Pure Entra-joined devices (AVD) enroll cleanly with a blank UPN. What causes the enrollment service to stamp fooUser and stall at State 1 for hybrid devices?

Microsoft Security | Intune | Enrollment
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.