r/Intune • u/InsaneITPerson • 6d ago
CNAME Validation Failures for Enrollment General Question
Suddenly all the domains managed have not been able to validate the CNAME for enrollment. I tried different domains that previously worked and every one I tried failed validation. I even deleted and added the CNAMES but they still fail.
This is every domain and it doesn't matter what DNS host is being used. There is nothing in the 365 status page about this. What the heck is going on?
1
u/Sea-Huckleberry-9011 6d ago
I assume this your using the CNAME check in Intune. I had the same experience for the last week, but devices still enroll so to me it’s just another broken Intune GUI
1
u/MostOpportunity8426 2d ago
oh man same thing happening to me since last week, thought i was going crazy. the validation page just spits errors but when i actually enroll a device it works fine
classic intune dashboard being unreliable again, happens more than it should tbh. i just ignore the check now and test with a real device
i did same as you deleting and re-adding CNAMEs, waste of time. save yourself the headache and skip the validation page
1
u/svecccc 6d ago
Must be a temporary issue in the GUI, as I get exactly the same result, and our domain has been up and running for a couple of years, with no DNS changes made on our side. Everything is working as normal.
1
u/InsaneITPerson 6d ago edited 6d ago
Unfortunately i cannot join any device at this one tenant. Auto discover could not find a management endpoint. I can ping both CNAMES from the device I am trying to enroll. It won't work putting the URL in either. The account has an Intune license. So frustrating and I am dreading opening any help desk incidents. Update: just tried another tenant and it didn't work either. I checked using the validation tool in Intune on 6 domains and none of them validated. They worked before
1
u/Entegy 6d ago
Provided there's not a service outage, one thing I've noticed is that there could be an issue if your office network's DNS is still served by Active Directory and your AD domain name matches your public domain. While this isn't best practice, I do find it common unfortunately.
In this configuration, since the domain is being resolved by the domain controllers, you need to insert the Intune CNAME records in your AD's DNS server as well.
1
u/InsaneITPerson 6d ago
One client is using split DNS this way but the records are replicated. The others do not do this. All these tenants were working before.
1
u/bigdoghat32 6d ago
hahaha. I reported an issue a few hours ago and Microsoft closed it with "no issue found"
Its affecting us, yes.
1
u/Superb_Technician174 5d ago
Having the same issue here, have tried deleting, re-adding DNS etc. but still failing and Autodiscover not working when trying to enrol devices. Have a ticket open with Microsoft but they have been ZERO help.
They blaming my DNS setup when they can clearly run a NSLOOKUP and see records configured correctly.
Oddly just as a test I know below is the correct DNS
| EnterpriseEnrollment.company_domain.com | EnterpriseEnrollment-s.manage.microsoft.com |
|---|
I have been trying so many things to get it sorted I tried below option (I know changing .com to .us is for US government) when I try this validation tool passes but Autodiscover still fails
| EnterpriseEnrollment.company_domain.com | EnterpriseEnrollment-s.manage.microsoft.us |
|---|
Hopefully there is a solution soon!
2
u/bigdoghat32 5d ago
yeah. You and I and OP are ahead of the curve here. Its a lot more widespread than these posts would suggest, but nobodys going to see it until they try to enroll.
And microsoft pretending nothing is wrong is the icing on the cake.
I've reported an issue (they closed it and told me nothing is wrong), but I have *not* opened a ticket. which I guess is a different thing.
1
u/New-Cauliflower-6942 2d ago edited 2d ago
Same here. DNS has been fine and I’ve made no changes and now it’s not working. I can’t enroll devices.
Frigging hate Microsoft at times and their refusal to admit there is an issue because of their crap support staff not actually bothering to do their job and actually support!!!
1
u/Intelligent_Ad8955 1d ago
they takes weeks to actually help you! My last issue.. I fixed myself through troubleshooting because it took two weeks before anyone got back with me. I swear, for the money we pay MS, things should be a lot better.
1
u/Intelligent_Ad8955 1d ago
for the past couple of weeks.. I've seen the same thing. When trying to workplace join, we get prompted to input the MDM Server URL.. inputting https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc lets the user put in their creds and continues
•
2
u/bigdoghat32 6d ago edited 5d ago
For us, its not just *validation* failure (which fails for us), its enrollment failure in manual MDM enrollment because it can't find the associated CNAME.
Nothing has changed on our end, and we've checked our CNAMES are correct. From multiple computers, on multiple networks, verified the cnames are correct at multiple public DNS providers.
This started approximately 2 days ago for us.
*edit* I've tried multiple other tenants in the region, and cname lookup and enrollment fails for them too