<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/413989#M93034</link>
    <description>&lt;P&gt;All of this is explained in the blog post. There is a wrapper script running the setup and doing all of the registry changes. The blog post has GitHub links to all of the scripts.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 19:30:42 GMT</pubDate>
    <dc:creator>mdepalmaevr</dc:creator>
    <dc:date>2021-06-17T19:30:42Z</dc:date>
    <item>
      <title>Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/338808#M85149</link>
      <description>&lt;P&gt;We are in the development phase of deploying a large number of new laptops to our user base. Due to the current circumstances with COVID and the changes we have made for out employees we would like to allow our users to receive the devices directly and utilize Intune for the deployment along with GlobalProtect pre-logon functionality.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently have a working setup to utilize machine certificate based pre-logon along with SAML after Windows login. Our Intune profiles are successfully pushing the certificates and GlobalProtect Client before the end point attempts to join the domain, but the client never seems to attempt to connect to the portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping others have gone down this path and had some insight on how to get this to successfully work or if it is even possible. Any information would be helpful since Microsoft has no good information on the process. Our setup is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANOS - 9.1.3&lt;/P&gt;&lt;P&gt;GlobalProtect Client - 5.1.5&lt;/P&gt;&lt;P&gt;Certificate Chain on both the Firewall as well as all clients&lt;/P&gt;&lt;P&gt;Portal Configuration - pre-logon configuration agent first then SAML authentication second with auto generated cookies to manipulate the configuration agent being used.&lt;/P&gt;&lt;P&gt;Gateway Configuration - both portal agents point to the same gateway and require a client certificate with the root and intermediate configured within a certificate profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As mentioned the pre-logon method works without any issue in production, but when we attempt to deploy a workstation using Microsoft Intune Windows 10 Out of Box or AutoPilot the process fails.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see a lot of MS documentation about using UWP GlobalProtect and am not sure on if it is required.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 00:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/338808#M85149</guid>
      <dc:creator>inclusa-admin</dc:creator>
      <dc:date>2020-07-16T00:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/352159#M87146</link>
      <description>&lt;P&gt;I wrote up an article on getting GlobalProtect pre-login to work together with Windows Autopilot here:&amp;nbsp;&lt;A href="https://blog.markdepalma.com/?p=528" target="_blank"&gt;https://blog.markdepalma.com/?p=528&lt;/A&gt;. There was an issue pushing the client and getting pre-logon to kick in the first time that I had to work around. I go over all of this here.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 15:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/352159#M87146</guid>
      <dc:creator>mdepalmaevr</dc:creator>
      <dc:date>2020-09-25T15:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/366727#M88751</link>
      <description>&lt;P&gt;Looks like working solution but to integrate with existing environment ,where we are doing authentication of portal based on LDAP or Radius etc will not work in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In such case we need OR&amp;nbsp; case&amp;nbsp; of Authentication if certificate authentication fails User authentication will work or viseversa&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 11:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/366727#M88751</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-12-02T11:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/375556#M89187</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157000"&gt;@mdepalmaevr&lt;/a&gt;&amp;nbsp;you don't really need to set&amp;nbsp;LogonFlag + LogonState on the registry if you do the installation with '&lt;SPAN&gt;msiexec /i "GlobalProtect64-5.2.4.msi" /q PORTAL=fqdn.address PRELOGON=1'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At least this works for me without additional hustle.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 07:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/375556#M89187</guid>
      <dc:creator>tigeli</dc:creator>
      <dc:date>2020-12-21T07:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/389412#M90619</link>
      <description>&lt;P&gt;Hello everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I was also working on the GP setup with our desktop team over the past few months and we have seen very odd behavior with the task process via MS Intune and Autopilot even after we had GP working well via user and machine certificate auth.&amp;nbsp; Yesterday, we had another meeting with MS Support and were told that Autopilot, specifically with Hybrid AD, is not supported and build sequences will fail. We had been troubleshooting this for a few months when MS dropped this on us. The MS engineer spent nearly 10 minutes telling us not to attempt Autopilot with a Hybrid AD environment. The MS engineer was also specific in stating that other MS reps will not be aware of this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this saves someone some time if trying to use Autopilot in a Hybrid AD environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 15:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/389412#M90619</guid>
      <dc:creator>Chris_S</dc:creator>
      <dc:date>2021-03-05T15:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/389426#M90622</link>
      <description>&lt;P&gt;When you say sequences, what are you using for that? Sounds like you are trying to use SCCM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From an Intune perspective hybrid AD is 100% supported, the feature they released last year was literally to enable Autopilot for hybrid AD clients over VPN. The MS engineer you spoke to is very incorrect in saying that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What issues were you actually having with this? I've had great success with hybrid Autopilot and GlobalProtect VPN. My configuration was documented here:&amp;nbsp;&lt;A href="https://blog.markdepalma.com/?p=528" target="_self"&gt;https://blog.markdepalma.com/?p=528&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 16:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/389426#M90622</guid>
      <dc:creator>mdepalmaevr</dc:creator>
      <dc:date>2021-03-05T16:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/413659#M93002</link>
      <description>&lt;P&gt;Hi, Could you expain more in detail? ... where did you add this "&lt;SPAN&gt;msiexec /i "GlobalProtect64-5.2.4.msi" /q PORTAL=fqdn.address PRELOGON=1'." ? In the win32 installation command?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also did you deploy the prerequiste registry changes using the PowerShell script?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 19:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/413659#M93002</guid>
      <dc:creator>Intuneforwork</dc:creator>
      <dc:date>2021-06-16T19:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/413989#M93034</link>
      <description>&lt;P&gt;All of this is explained in the blog post. There is a wrapper script running the setup and doing all of the registry changes. The blog post has GitHub links to all of the scripts.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 19:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/413989#M93034</guid>
      <dc:creator>mdepalmaevr</dc:creator>
      <dc:date>2021-06-17T19:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/414237#M93082</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/57032"&gt;@tigeli&lt;/a&gt;&amp;nbsp;You said you used&amp;nbsp;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;msiexec /i "GlobalProtect64-5.2.4.msi" /q PORTAL=fqdn.address PRELOGON=1'. for install command.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Didn't you use any other script PS1 file(For registry changes) along with the Global protect app while wrapping?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2021 17:59:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/414237#M93082</guid>
      <dc:creator>Intuneforwork</dc:creator>
      <dc:date>2021-06-19T17:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/414238#M93083</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157000"&gt;@mdepalmaevr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the shared blog you are using the&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://github.com/markdepalma/Windows-Autopilot-Hybrid-Join-Scripts" target="_blank"&gt;InstallGlobalProtect.cmd&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. for install command but&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/57032"&gt;@tigeli&lt;/a&gt;&amp;nbsp; has used the following&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;msiexec /i "GlobalProtect64-5.2.4.msi" /q PORTAL=fqdn.address PRELOGON=1'."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am looking for a solution without using the GPO.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2021 18:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/414238#M93083</guid>
      <dc:creator>Intuneforwork</dc:creator>
      <dc:date>2021-06-19T18:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/415582#M93273</link>
      <description>&lt;P&gt;&lt;A href="https://github.com/markdepalma/Windows-Autopilot-Hybrid-Join-Scripts/blob/master/InstallGlobalProtect.cmd" target="_self"&gt;InstallGlobalProtect.cmd&lt;/A&gt; launches&amp;nbsp;&lt;A href="https://github.com/markdepalma/Windows-Autopilot-Hybrid-Join-Scripts/blob/master/InstallGlobalProtect.ps1" target="_self"&gt;InstallGlobalProtect.ps1&lt;/A&gt;.&amp;nbsp;InstallGlobalProtect.ps1 then places all the correct registry values... GPO is not doing this.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 12:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/415582#M93273</guid>
      <dc:creator>mdepalmaevr</dc:creator>
      <dc:date>2021-06-28T12:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Intune  Out of Box Experience and Autopilot Hybrid AD Join</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/426162#M94451</link>
      <description>&lt;P&gt;Hi Tigeli,&lt;/P&gt;&lt;P&gt;I've tried this command msiexec.exe /i "GlobalProtect64-5.2.7.msi" /q into Intune and the installation of the app&amp;nbsp; got failed.&lt;/P&gt;&lt;P&gt;Do you have any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 16:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-intune-out-of-box-experience-and-autopilot-hybrid-ad/m-p/426162#M94451</guid>
      <dc:creator>waple02</dc:creator>
      <dc:date>2021-08-11T16:34:56Z</dc:date>
    </item>
  </channel>
</rss>

