cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
17834
Views
11
Helpful
19
Replies

MDM users needs to log in?

alyssafriesen
Community Member

I just installed the MDM application on a new machine and enrolled in device management. I can see the device in Systems Manager, but not all of the profile settings are being applied. If see that under "Profiles" there is an error message that says "The MDM user needs to log in to the device for settings to be updated".

I'm not finding any documentation on this and I'm not sure what it wants. I am logged into the machine and Microsoft reports that the sync is working correctly, but settings like WiFi are not propagating out to the device (which is connected via ethernet at the moment).

19 Replies 19

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Authentication when enrolling is not a hard requirement, but I find it makes many things work better so I tend to use it.

You can authenticate against Office 365, Google and Active Directory.

https://documentation.meraki.com/SM/Device_Enrollment/SM_Enrollment_Authentication

TomBenoit
Community Member

I am currently managing machines that are not on a domain. I am getting this error message over time i.e. the profile works for a while and then it will not accept any updates I make to the profile. The local admin account that setup the managed profile is logged in. Any ideas?

We are having the exact same issue. It works initially and then just stops working.

tmhunt2
Visitor
Agent version

Current Version:

3.5.2

Arthur Dent
Cisco Employee
Cisco Employee

So, windows has two modes (currently) of enrollment. MDM and agent. Because the MDM is tied to a user account on the device, it can't be updated if that user is not logged in, and that's why you are getting this message

If you use the Systems Manage agent on the device, you won't get this error.

I hope that helps

Paul

We do use the Systems Manager agent on the device and we are getting this message. We enroll the device via Windows profile and then install the agent.

And if the user who enrolled the device using Windows profile is not logged in, regardless of whether they have the agent or not, you'll get the message.

Would be great if this could be fixed.

Currently I use the following procedure for Windows Devices:

- Install Systems Manager Agent

- Give the future user admin rights to enroll the device.

- Ask the user to log in once

- enroll device

- logout the user

- take back admin rights

If the device then changes the user, you can repeat the whole process 😞

Is that the right way?

BlakeRichardson
Meraki Community All-Star
Meraki Community All-Star

I am going to be really cheeky here and its just a joke but you could buy a Mac 😜

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

Yes, it all works just fine for Macs and iPads. Sigh.

MConley
Community Member

We continue to be unable to perform as simple an operation as changing the password on our SSID thanks to our inability to push changes out to Windows devices. I continue to be stunned at Meraki's lack of response to this issue.

The user who enrolled into MDM with Windows is the only user that will be affected by MDM commands

Therefore, THAT user has to be logged in for changes to Windows MDM profiles to be effective

As noted elsewhere in this thread, that is precisely what Meraki have gotten wrong. There are settings on Windows that are device-specific, not user-specific, and these need to be pushed out regardless of who happens to be logged in at any given moment. Wi-Fi passwords are one such setting; there are numerous others. The Meraki MDM model for pushing profiles to Windows devices is broken; it works correctly for macOS and iOS.

You're absolutely right: WiFi configs can be applied at the user level or the device level. I'm checking with engineering as to which one we do, and I'm creating a feature request to allows admins to decide which of these it is

HOWEVER: What is immutable is the need for the ENROLLED user to be logged in for changes to be made. That is a restriction of Microsoft, and something we cannot change