in soti azure ad joined laptops are easily getting onboarded but local on prem ad i am getting issues what can be the possible reason

Adding on premAD joined laptops facing issues while onboarding

5 months ago
Windows
ANSWERS
RC
Raymond Chan Diamond Contributor
5 months ago

Have you checked that your On-premises AD has been properly configured/integrated to your MobiControl server?  Some possible tests can be assignment of User-ID to enrolled devices (of other device platform such as Android or Apple) in the device detail tab in the web-console, enrollment of Android/iOS devices with AD authentication enabled in the enrollment policy, addition of new web-console administrator account for specific AD user/group, etc.

S
SSMOD@SOTI
5 months ago

Hey Ankit,

there can be few possible reasons:

  1. AD Integration Misconfiguration: The on-premises AD might not be fully or correctly integrated with the MobiControl server, causing authentication or enrollment failures.

  2. Network Connectivity: The MobiControl server may have connectivity issues accessing the on-prem AD domain controllers or related services (LDAP/LDAPS).

  3. Permissions: The service account used for AD integration might lack the necessary permissions to query users or groups.

  4. Enrollment Policy Settings: Enrollment policies might be configured differently for on-prem devices vs. Azure AD devices, especially concerning AD authentication requirements.

  5. Synchronization Issues: If you’re using hybrid setups, synchronization delays or errors between on-prem AD and Azure AD could cause inconsistent states.

  6. Certificate or Security Issues: Sometimes certificate trust issues or firewall rules block necessary communication between MobiControl and on-prem AD.

Kindly check it and confirm if due to anyone of these, the issue is showing up.