Troubleshooting

Intune Connector for Active Directory

Hybrid Autopilot requires an active Intune Connector for Active Directory registered in this tenant.

Missing Intune Connector for Active Directory

Documentation

Hybrid Autopilot requires an active Intune Connector for Active Directory.

Job ID
Tenant ID
Template
Solidice step-by-step: Intune Connector for Active Directory

Use this procedure instead of creating a separate traditional service account. Current connector installations create an MSA* managed account automatically. The important step is to give that connector-managed account the correct permissions on the OU where Autopilot computers will be created.

1. Choose the connector server

  1. Use a supported Windows Server that is joined to the Active Directory domain.
  2. Make sure the server can resolve the AD domain through internal DNS.
  3. Confirm the server can reach the internet over HTTPS (TCP 443).
  4. Do not install the connector on a workstation or on a server that is frequently powered off.
  5. For production, use a server that is expected to remain online during Autopilot deployments.

2. Download the connector from Intune

  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices → Windows → Windows enrollment.
  3. Open Intune Connector for Active Directory.
  4. Select Add or the option to download the connector.
  5. Copy the installer to the domain-joined connector server.

3. Install and register the connector

  1. Run the connector installer as a local administrator on the server.
  2. Complete the installation using the default service settings unless your environment requires otherwise.
  3. Open the installed Intune Connector application.
  4. Select Sign In.
  5. Authenticate with an administrator account from the same tenant being deployed through Solidice.
  6. Complete the registration and allow the connector a few minutes to appear in Intune.
Important: The sign-in account registers the connector with Intune. It is not the account that creates computer objects in Active Directory.

4. Confirm the connector is Active

  1. Return to Intune Connector for Active Directory in the Intune admin center.
  2. Confirm the connector server appears in the list.
  3. Confirm its status is Active.
  4. Confirm the last check-in time is current.
  5. If the connector is not Active, do not continue with the Hybrid deployment yet.

5. Find the connector-managed MSA account

Newer connector versions create a managed service account with a name beginning with MSA. You normally do not create a separate service account manually.

  1. Open Active Directory Users and Computers on a domain controller or management server.
  2. Enable View → Advanced Features.
  3. Search Active Directory for an account beginning with MSA.
  4. Identify the account associated with the Intune Connector server.
  5. Do not move the MSA account into the computer OU just to make Autopilot work. The account only needs delegated rights on that OU.
What the MSA account does: The connector uses this managed identity when it requests Offline Domain Join computer objects. The account must be able to create and delete computer objects in each OU targeted by your Domain Join profiles.

6. Delegate permissions to the target OU

  1. Open Active Directory Users and Computers.
  2. Enable View → Advanced Features.
  3. Right-click the OU where Autopilot computers should be created.
  4. Select Delegate Control.
  5. Add the connector's MSA* account.
  6. Select Create a custom task to delegate.
  7. Select Only the following objects in the folder.
  8. Select Computer objects.
  9. Enable Create selected objects in this folder.
  10. Enable Delete selected objects in this folder.
  11. On the permissions page, grant the required computer-object read/write permissions.
  12. Finish the wizard.
Common failure: If the MSA account does not have permission on the exact OU used by the Domain Join profile, Hybrid Autopilot can fail with an ODJ blob or NetProvisionComputerAccount error.

7. Verify the OU path used by Intune

The Domain Join profile should use the OU distinguished name, not a friendly ADUC path.

OU=Autopilot,OU=Computers,DC=corp,DC=contoso,DC=com
  1. Open the Hybrid Domain Join profile in Intune.
  2. Confirm the domain name is correct.
  3. Confirm the OU distinguished name points to the OU where the MSA permissions were delegated.
  4. Confirm the computer naming prefix is the intended value.

8. Validate the connector service on the server

Run PowerShell as Administrator:

Get-Service | Where-Object {
    $_.DisplayName -match 'Intune|ODJ|Connector'
} | Format-Table Status, Name, DisplayName -AutoSize

The Intune Connector service should be running. If it is stopped, start it and check the Windows event logs before retrying.

9. Re-run the Solidice Hybrid preview

  1. Return to the Solidice deployment portal.
  2. Start a new Hybrid Autopilot preview.
  3. Confirm Intune Connector for Active Directory reports Success.
  4. Confirm the Domain Join / ODJ profile is valid.
  5. Confirm Hybrid readiness reports Success.
  6. Select Deploy now only after the preview is ready.

10. If it still fails

Connector missing in Intune

Reopen the connector application on the server and sign in again. Verify that the tenant used during connector registration is the same tenant connected to Solidice.

Connector shows inactive

Check the connector service, outbound HTTPS connectivity, system time, TLS inspection, and server event logs.

ODJ blob generation fails

Verify the MSA account has create/delete computer-object rights on the exact OU configured in the Domain Join profile.

Computer object is created in the wrong OU

Correct the OU distinguished name in the Domain Join profile and verify delegation on the new target OU.

Recommended checks

  1. Install the connector on a domain-joined Windows Server with reliable access to Active Directory, DNS, and Microsoft cloud services.
  2. Register the connector in the same Microsoft 365 tenant used by this Solidice deployment.
  3. Wait until Intune reports the connector as Active before continuing.
  4. Locate the MSA* account created automatically for the connector and delegate permissions to the target computer OU.
  5. Grant the connector account permission to create and delete computer objects in the target OU.
  6. Verify the Hybrid Domain Join profile uses the correct AD domain and OU distinguished name.
  7. Run the Solidice Hybrid preview again. The Intune Connector result should change to Success.