SCCM: Co-management setup with SCCM Client installation

I decided to set up a test lab for co-management. Here is what I have:

Azure AD tenant. In addition to Primary * I have multiple custom domains registered.

SCCM 1806 on-prem

I started from deploying CMG as demonstrated in Justin’s video: 

The only difference – I did not use internal domain name for CMG, just left it as That allowed me to avoid CNAME requirement.

after that I configured co-management as per

but unfortunately SCCM client was not installed on my test machine joined to Azure AD.

I am using enhanced HTTP on SCCM side; my internal MP operates in HTTP mode and there is no certificate installed on the the Client. I tried to be as close as possible to real BYOD scenario.

After some troubleshooting I sent the question to Technet forums 

Based on the forum discussion I replaced Intune MSI-based SCCM Client deployment to W32 App which Microsoft has currently in preview. Just as Martin recommended:

Nick provided great help with tokens troubleshooting. I found his article here:

And do not forget to Approve the Client in SCCM console (at least in my case it was a workgroup machine and auto-approval was not enabled on SCCM).

It took ~15 min after approval before the Client got policy from SCCM MP.

After all everything is working, but took some time with research and troubleshooting…


Nokia Lumia 835: Camera application failed “Something went wrong”

I tried to make a quick photo and got “Something went wrong” error on my phone Sad smile

I searched Intenet a bit and it looked like the issue is wide spread and people most often send the device to service since it a hardware issue.

I was almost there, but decided to think again if I changed anything recently. Sure enough I tested Microsoft Intune mobile device management and subscribed my phone to it. Even though “Camera off” policy was not enabled there it looks like it broke the device somehow.

So, I un-enroll from Intune and tried camera again. Now it works! Smile

Bottom line, I am not saying it will fix the issue in all cases, but at least worth to try to un-enroll you device from any sort of Mobile Device Management solution (if you have rights) and try without it.

Intune: Microsoft Application links for IOS and Android

Joe Kuster compiled a list of links we can use with Intune to populate Corp Portal with MS apps. Thank you Joe!


Microsoft Word:

Microsoft Excel:

Microsoft PowerPoint:

Microsoft OneDrive:

Microsoft OneNote for iPhone:

Microsoft OneNote for iPad:

Microsoft Intune Managed Browser:

Work Folders:

OWA for iPhone:


RD Client:

Sunrise Calendar:

Office Lens:

OneDrive for Business:

Office 365 Admin:

Office 365 Message Encryption Viewer:

SharePoint Newsfeed:

Office Sway:

Dynamics CRM:

Azure Authenticator:



Office Delve:

RMS Sharing:

Office 365 Video:



Microsoft Word:

Microsoft Excel:

Microsoft PowerPoint:

Microsoft OneDrive:

Microsoft Intune Managed Browser:

Microsoft Intune PDF Viewer:

Microsoft Intune Image Viewer:

Microsoft Intune AV Player:

Microsoft Office Hub:

Office Lens:

Microsoft Account:

Sunrise Calendar:



Remote Desktop Client:

Lync 2013:

Office Remote:

Keyboard for Excel:

OWA for Android:

Office 365 Admin:



SCCM: Intune and SCCM–ways to do MDM

found a nice article on Technet clearly explaining when you may want integrate Intune and SCCM and when use Intune as a standalone product: