Registering devices with Intune for management and policy enforcement
Hybrid FooUser issue
On hybrid Entra-joined devices, device-context MDM enrollment (deviceenroller /c /AutoEnrollMDM, MDM app id 0000000a-...) creates an MS DM Server enrollment record stamped with placeholder UPN fooUser@<tenant>.onmicrosoft.com, obtains an MDM certificate, but stalls permanently at EnrollmentState 1 and never appears in Intune. This is 100% reproducible on a fully cleaned device (no prior enrollment records, certs, or tasks) and occurs regardless of SCCM client state. fooUser appears in no configuration, script, or Entra sign-in log — it is generated by the enrollment process itself. Pure Entra-joined devices (AVD) enroll cleanly with a blank UPN. What causes the enrollment service to stamp fooUser and stall at State 1 for hybrid devices?