Intune Enrollment status page was shown at multiple sessions at Ignite 2017, specially with Autopilot, this feature is not only for AutoPilot devices, but for all Windows devices that are AzureAD joined. Back in November 2017 I did a blog post on Intune Enrollment status page a couple of week later the feature was gone. Now it is here again and with great new features. Intune Enrollment status page is only support on Windows 10 1803 also known as RS4, unlike first time the enrollment status page was in Intune for Windows 10 1709 RS3 – this new page do not have any effect on Windows other than RS4.

In this blog post I will show how to setup the Intune Enrollment page and what it looks like from the End-user perspective, and at the end I will tell where I have found that the Intune Enrollment is not working so good.


How to configure Enrollment status page:

Start the Microsoft 365 device management portal https://devicemanagement.portal.azure.com

  1. Click Device Enrollment
  2. Click Windows Enrollment
  3. Click Enrollment Status Page (Preview)

Intune Enrollment Status Page (Preview) - 01

  1. Select the Default

Intune Enrollment Status Page (Preview) - 02

  1. Click Settings
  2. Click Yes

Intune Enrollment Status Page (Preview) - 04

  1. Show app and profile installation progress – enables the feature
  2. Block device use until all apps and profiles are installed – this prevents the end-user from shutting down the status page (see below for what happens if this settings is set to No)
  3. Allow users to reset devices if installation error occurs – allows the end user to reset the devices and start the device provisioning all over again
  4. Allow users to use device if installation errors occurs – give the end-user the possible to go to the Windows desktop and use the devices is there is any errors
  5. Show error when installation takes longer than specified number minutes – sets a timeout in minutes, if it takes longer time to get the devices up and running it will go into error mode
  6. Show custom message when an error occurs – give the IT department the possibility to give the end-user a custom message is any thing goes wrong
  7. Allow users to collect logs about installation errors – so the end-user can give error logs to the IT departments

Intune Enrollment Status Page (Preview) - 05


How is the end-user expirence:

After the End-user has entered the AzureAD/O365 credentials and password the Enrollment status page is showed to the end-user

Windows - Enrollment Status Page (Preview) - 01

In the first Device preparation it will show status for :

  • Securing your hardware
  • Joining your organization’s network
  • Registering your device for mobile management

Windows - Enrollment Status Page (Preview) - 02

Then the Device setup will starts, and deploy devices assigned:

  • Security policies
  • Certificates
  • Network connections
  • Apps

In my case I don’t have anything devices assigned.

Windows - Enrollment Status Page (Preview) - 03

Then the Account setup will starts, and deploy user assigned:

  • Security policies
  • Certificates
  • Network connections
  • Apps

Windows - Enrollment Status Page (Preview) - 04

You can see details on how many settings that have been deployed and how many there is missing

Windows - Enrollment Status Page (Preview) - 05

When it is finished the devices is ready to use with the settings and installed apps.

Windows - Enrollment Status Page (Preview) - 06


The scenario where the IT admin allows the end-user to bypass the Intune Enrollment page looks a little different:

If Block devices use until all apps and profiles are installed  is set to No

Intune Enrollment Status Page (Preview) - 04a

There will be a “Continue anyway” button that the End-user can click and the device will move on in the OOBE process like when the Enrollment page is not configured

Windows - Enrollment Status Page (Preview) - 10

 

Some things you need to remember when you are using Intune Enrollment status page:

If you have assigned a profile that requires a reboot the reboot screen will show up and reboot the devices after 2 minutes no matter if the devices is finished for not.

Enrollment Status Page (Preview) - WDAG 00

After the reboot, then the status page will show failed – and you can “try again”

Enrollment Status Page (Preview) - WDAG 01

At the moment I don’t have a solution for this behavior other than not use Intune profiles that gives a reboot. In my case it was Windows Defender Application Guard and Windows Defender Application Control , all in the Endpoint Protection profile in Intune, the reason is that all 3 settings are installing a Windows Feature that requires a reboot. I can also be a application that do not suppress a reboot that will give the same behavior.


More info:
Set up an enrollment status page

 

Happy testing – this is a long waited feature.