Skip to content

Commit ac309e3

Browse files
authored
Merge pull request #17804 from MicrosoftDocs/fix-conflict-release-intune-2504
Fix merge conflicts with main in release-intune-2504
2 parents b596fff + 4363aab commit ac309e3

34 files changed

+726
-273
lines changed

.github/workflows/StaleBranch.yml

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,17 @@ name: (Scheduled) Stale branch removal
22

33
permissions:
44
contents: write
5-
5+
6+
# This workflow is designed to be run in the days up to, and including, a "deletion day", specified by 'DeleteOnDayOfMonth' in env: in https://github.com/MicrosoftDocs/microsoft-365-docs/blob/workflows-prod/.github/workflows/Shared-StaleBranch.yml.
7+
# On the days leading up to "deletion day", the workflow will report the branches to be deleted. This lets users see which branches will be deleted. On "deletion day", those branches are deleted.
8+
# The workflow should not be configured to run after "deletion day" so that users can review the branches were deleted.
9+
# Recommendation: configure cron to run on days 1,15-31 where 1 is what's configured in 'DeleteOnDayOfMonth'. If 'DeleteOnDayOfMonth' is set to something else, update cron to run the two weeks leading up to it.
10+
611
on:
712
schedule:
8-
- cron: "0 9 1 * *"
13+
- cron: "0 9 1,15-31 * *"
914

10-
# workflow_dispatch:
15+
workflow_dispatch:
1116

1217

1318
jobs:

autopilot/device-preparation/requirements.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ author: frankroj
88
ms.author: frankroj
99
ms.reviewer: madakeva
1010
manager: aaroncz
11-
ms.date: 04/02/2025
11+
ms.date: 04/21/2025
1212
ms.collection:
1313
- M365-modern-desktop
1414
- highpri
@@ -119,7 +119,10 @@ Microsoft Entra ID validates user credentials. Additionally, the device is joine
119119
120120
#### Microsoft Intune
121121
122-
Once authenticated, Microsoft Entra ID triggers enrollment of the device into the Intune mobile device management (MDM) service. For more information about Intune's network communication requirements, see [Network endpoints for Microsoft Intune](/mem/intune-service/fundamentals/intune-endpoints).
122+
Once authenticated, Microsoft Entra ID triggers enrollment of the device into the Intune mobile device management (MDM) service. For more information about Intune's network communication requirements, see the following articles:
123+
124+
- [Network endpoints for Microsoft Intune](/mem/intune-service/fundamentals/intune-endpoints).
125+
- [Network requirements for PowerShell scripts and Win32 apps](/intune/intune-service/fundamentals/intune-endpoints).
123126
124127
#### Windows Autopilot device preparation automatic device diagnostics collection
125128

autopilot/includes/intune-connector.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.reviewer: madakeva
66
ms.subservice: autopilot
77
ms.service: windows-client
88
ms.topic: include
9-
ms.date: 02/27/2025
9+
ms.date: 04/21/2025
1010
ms.localizationpriority: medium
1111
---
1212

@@ -22,7 +22,7 @@ The purpose of the Intune Connector for Active Directory, also known as the Offl
2222

2323
> [!IMPORTANT]
2424
>
25-
> Starting with Intune 2501, Intune uses an updated Intune Connector for Active Directory that strengthens security and follows least privilege principles by using a [Managed Service Account (MSA)](/windows-server/identity/ad-ds/manage/understand-service-accounts#standalone-managed-service-accounts). When the Intune Connector for Active Directory is downloaded from within Intune, the updated Intune Connector for Active Directory is downloaded. The previous legacy Intune Connector for Active Directory is still available for download at [Intune Connector for Active Directory](https://www.microsoft.com/download/details.aspx?id=105392&msockid=3cb707200c316b2c119712450d8b6a5d), but Microsoft recommends using the updated Intune Connector for Active Directory installer going forward. The previous legacy Intune Connector for Active Directory will continue to work through sometime in May 2025. However, it needs to be updated to the updated Intune Connector for Active Directory before then to avoid loss of functionality. For more information, see [Intune Connector for Active Directory with low-privileged account for Windows Autopilot Hybrid Microsoft Entra join deployments](https://aka.ms/Intune-Connector-blog).
25+
> Starting with Intune 2501, Intune uses an updated Intune Connector for Active Directory that strengthens security and follows least privilege principles by using a [Managed Service Account (MSA)](/windows-server/identity/ad-ds/manage/understand-service-accounts#standalone-managed-service-accounts). When the Intune Connector for Active Directory is downloaded from within Intune, the updated Intune Connector for Active Directory is downloaded. The previous legacy Intune Connector for Active Directory is still available for download at [Intune Connector for Active Directory](https://www.microsoft.com/download/details.aspx?id=105392&msockid=3cb707200c316b2c119712450d8b6a5d), but Microsoft recommends using the updated Intune Connector for Active Directory installer going forward. The previous legacy Intune Connector for Active Directory will continue to work through sometime in June 2025. However, it needs to be updated to the updated Intune Connector for Active Directory before then to avoid loss of functionality. For more information, see [Intune Connector for Active Directory with low-privileged account for Windows Autopilot Hybrid Microsoft Entra join deployments](https://aka.ms/Intune-Connector-blog).
2626
>
2727
> Updating of the Intune Connector for Active Directory to the updated version isn't done automatically. The legacy Intune Connector for Active Directory needs to be manually uninstalled followed by the updated connector manually downloaded and installed. Instructions for the manual uninstall and install process of the Intune Connector for Active Directory are provided in the following sections.
2828

autopilot/known-issues.md

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ author: frankroj
88
ms.author: frankroj
99
ms.reviewer: madakeva
1010
manager: aaroncz
11-
ms.date: 04/08/2025
11+
ms.date: 04/21/2025
1212
ms.collection:
1313
- M365-modern-desktop
1414
- highpri
@@ -43,22 +43,27 @@ This article describes known issues that can often be resolved with configuratio
4343
4444
### Known issues with the Intune Connector for AD version 6.2501.2000.5
4545
46-
Date added: *April 8, 2025*
46+
Date added: *April 8, 2025*<br>
47+
Date updated: *April 18, 2025*
4748
4849
The following issues are under active investigation:
4950
5051
- **Error `MSA account <accountName> is not valid` when signing in.**
51-
52-
This error occurs when the connector successfully creates the MSA but fails to retrieve the data from the domain controller. Various issues can cause the error, including replication delays between domain controllers in single domain, or when the user account exists in a different domain to the connector machine.
5352
53+
This error occurs when the connector successfully creates the MSA but fails to retrieve the data from the domain controller. Various issues can cause the error, including replication delays between domain controllers in single domain, or when the user account exists in a different domain to the connector machine.
54+
55+
This issue is resolved in build **6.2504.2001.8.**
56+
5457
- **Error `Failed to create a managed service account - Element not found`.**
5558
5659
- **Error `Cannot start service ODJConnectorSvc on computer '.'. ---> System.ComponentModel.Win32Exception: The service did not start due to a logon failure` after the MSA is created.**
57-
58-
This error occurs when the service can't run as the MSA. The service not being able to run as the MSA can be caused by various issues, including group or local policy restricting **Log on as a service** privileges.
5960
61+
This error occurs when the service can't run as the MSA. The service not being able to run as the MSA can be caused by various issues, including group or local policy restricting **Log on as a service** privileges. For more information on how to mitigate this error, see [Troubleshooting FAQ](/autopilot/troubleshooting-faq#why-is-the-error--cannot-start-service-odjconnectorsvc-on-computer------occurring-when-setting-up-the-intune-connector-for-active-directory-).
62+
6063
- **Error `System.DirectoryServices.DirectoryServicesCOMException (0x8007202F): A constraint violation occurred.`**
6164
65+
For information on how to mitigate this error, see [Troubleshooting FAQ](/autopilot/troubleshooting-faq#troubleshooting-the-intune-connector-for-active-directory).
66+
6267
### TPM attestation isn't working for TPMs which use high-range RSA 3072EK
6368
6469
Date added: *April 4, 2025*
@@ -73,8 +78,7 @@ The Windows Autopilot profile setting which enables automatic configuration of t
7378
7479
### Windows Autopilot report incorrectly shows failure even though the deployment was successful
7580
76-
Date added: *February 11, 2025*
77-
81+
Date added: *February 11, 2025*<br>
7882
Date updated: *March 20, 2025*
7983
8084
This issue is resolved.

autopilot/troubleshooting-faq.yml

Lines changed: 22 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ metadata:
99
ms.author: frankroj
1010
ms.reviewer: madakeva
1111
manager: aaroncz
12-
ms.date: 04/04/2025
12+
ms.date: 04/21/2025
1313
ms.collection:
1414
- M365-modern-desktop
1515
- highpri
@@ -472,10 +472,30 @@ sections:
472472
- The administrator installing and configuring the Intune Connector for Active Directory doesn't have the required permissions as outlined in the [Intune Connector for Active Directory Requirements](windows-autopilot-hybrid.md?tabs=intune-connector-requirements#requirements).
473473
- The organization unit (OU) specified in the Intune Connector for Active Directory `ODJConnectorEnrollmentWiazard.exe.config` XML configuration file doesn't exist.
474474
475-
For detailed information on the error and what caused it, see the `ODJConnectorUI.log` normally located in the folder `C:\Program Files\Microsoft Intune\ODJConnector\ODJConnectorEnrollmentWizard`.
475+
For detailed information on the error and what caused it, see the `ODJConnectorUI.log` normally located in the following folder:
476+
477+
`C:\Program Files\Microsoft Intune\ODJConnector\ODJConnectorEnrollmentWizard`
478+
479+
Follow the steps to [Increase the computer account limit in the Organizational Unit](tutorial/user-driven/hybrid-azure-ad-join-computer-account-limit.md?tabs=updated-connector) if the following error appears in the `ODJConnectorUI.log`:
480+
481+
**`System.AggregateException: One or more errors occurred. ---> System.DirectoryServices.DirectoryServicesCOMException: A constraint violation occurred.`**
476482
477483
For more information, see [Install the Intune Connector for Active Directory on the server](windows-autopilot-hybrid.md?tabs=updated-connector#install-the-intune-connector-for-active-directory-on-the-server).
478484
485+
- question: |
486+
Why is the error "Cannot start service ODJConnectorSvc on computer '.'" occurring when setting up the Intune Connector for Active Directory?
487+
answer: |
488+
This error might occur for several reasons including:
489+
490+
- The domain has more than one domain controller with a replication latency policy. The MSA was created in one of the domain controllers but the search happened against another domain controller. Wait until replication has completed in accordance with your policy or manually sync. Once the replication is complete, then open the connector and choose **Configure MSA**.
491+
492+
- A group policy is configured that doesn't allow services to be started as a non-privileged account. Make sure the MSA account has **Log on as a service** privileges granted. For example, see this instance with Operations Manager to [Enable service logon](/system-center/scom/enable-service-logon#enable-service-log-on-permission-for-run-as-accounts).
493+
494+
- question: |
495+
Why is the error "Microsoft Edge can't read and write to its data directory" occurring?
496+
answer: |
497+
This error indicates that the user needs read/write permissions to the listed directory. For more information on how to grant these permissions, see [Manage user data folders](/microsoft-edge/webview2/concepts/user-data-folder?tabs=win32).
498+
479499
- question: |
480500
Why did enrollments start failing when using the Intune Connector for Active Directory?
481501
answer: |

autopilot/tutorial/pre-provisioning/hybrid-azure-ad-join-intune-connector.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ author: frankroj
77
ms.author: frankroj
88
ms.reviewer: madakeva
99
manager: aaroncz
10-
ms.date: 02/27/2025
10+
ms.date: 04/21/2025
1111
ms.topic: tutorial
1212
ms.collection:
1313
- tier1

autopilot/tutorial/user-driven/hybrid-azure-ad-join-intune-connector.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ author: frankroj
77
ms.author: frankroj
88
ms.reviewer: madakeva
99
manager: aaroncz
10-
ms.date: 02/27/2025
10+
ms.date: 04/21/2025
1111
ms.topic: tutorial
1212
ms.collection:
1313
- tier1

autopilot/whats-new.md

Lines changed: 15 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ author: frankroj
88
ms.author: frankroj
99
manager: aaroncz
1010
ms.reviewer: madakeva
11-
ms.date: 02/27/2025
11+
ms.date: 04/21/2025
1212
ms.collection:
1313
- M365-modern-desktop
1414
- tier2
@@ -32,11 +32,24 @@ appliesto:
3232
>
3333
> For more information on using RSS for notifications, see [How to use the docs](/mem/use-docs#notifications) in the Intune documentation.
3434
35+
## Updated build for the low privileged account for Intune Connector for Active Directory
36+
37+
Date added: *April 18, 2025*
38+
39+
We've updated the low-privileged Intune Connector for Active Directory build. New in build **6.2504.2001.8:**
40+
41+
- Updated the sign in page to use WebView2, built on Edge, instead of WebBrowser.
42+
- **Error `MSA account <accountName> is not valid`** when signing in has been fixed.
43+
- **Error `Cannot start service ODJConnectorSvc on computer '.'`** can now be mitigated. For more information, see [Troubleshooting FAQ](/autopilot/troubleshooting-faq#why-is-the-error--cannot-start-service-odjconnectorsvc-on-computer------occurring-when-setting-up-the-intune-connector-for-active-directory-).
44+
- **Error `System.DirectoryServices.DirectoryServicesCOMException (0x8007202F): A constraint violation occurred.`** can now be mitigated. For more information, see [Troubleshooting FAQ](/autopilot/troubleshooting-faq#why-is-the-error--the-msa-account-couldn-t-be-granted-permission-to-create-computer-objects-in-the-following-ous--occurring-when-installing-the-intune-connector-for-active-directory-).
45+
46+
Download and install the latest version to get these changes.
47+
3548
## Low privileged account for Intune Connector for Active Directory for Hybrid join Windows Autopilot flows
3649
<!--9544276-->
3750
Date added: *February 27, 2025*
3851
39-
We've updated the Intune Connector for Active Directory to use a low privileged account to increase the security of your environment. The old connector will continue to work until deprecation in late May 2025.
52+
We've updated the Intune Connector for Active Directory to use a low privileged account to increase the security of your environment. The old connector will continue to work until deprecation in late June 2025.
4053
4154
For more information, see [Deploy Microsoft Entra hybrid joined devices by using Intune and Windows Autopilot](windows-autopilot-hybrid.md).
4255

autopilot/windows-autopilot-hybrid.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ author: frankroj
66
ms.author: frankroj
77
manager: aaroncz
88
ms.reviewer: madakeva
9-
ms.date: 03/28/2025
9+
ms.date: 04/21/2025
1010
ms.topic: how-to
1111
ms.service: windows-client
1212
ms.subservice: autopilot

0 commit comments

Comments
 (0)