in soti azure ad joined laptops are easily getting onboarded but local on prem ad i am getting issues what can be the possible reason

Adding on premAD joined laptops facing issues while onboarding

10 months ago
Windows
ANSWERS
RC
Raymond Chan
10 months ago

Have you checked that your On-premises AD has been properly configured/integrated to your MobiControl server?  Some possible tests can be assignment of User-ID to enrolled devices (of other device platform such as Android or Apple) in the device detail tab in the web-console, enrollment of Android/iOS devices with AD authentication enabled in the enrollment policy, addition of new web-console administrator account for specific AD user/group, etc.

S
SSMOD@SOTI
9 months ago

Hey Ankit,

there can be few possible reasons:

  1. AD Integration Misconfiguration: The on-premises AD might not be fully or correctly integrated with the MobiControl server, causing authentication or enrollment failures.

  2. Network Connectivity: The MobiControl server may have connectivity issues accessing the on-prem AD domain controllers or related services (LDAP/LDAPS).

  3. Permissions: The service account used for AD integration might lack the necessary permissions to query users or groups.

  4. Enrollment Policy Settings: Enrollment policies might be configured differently for on-prem devices vs. Azure AD devices, especially concerning AD authentication requirements.

  5. Synchronization Issues: If you’re using hybrid setups, synchronization delays or errors between on-prem AD and Azure AD could cause inconsistent states.

  6. Certificate or Security Issues: Sometimes certificate trust issues or firewall rules block necessary communication between MobiControl and on-prem AD.

Kindly check it and confirm if due to anyone of these, the issue is showing up.