We've setup Intune with NDES and an on-prem PKI to issue User Certificates to Intune enrolled devices.
This is working great for Windows10 devices, and we are using the Intune extension to check that a device is Managed, Corporate owned and compliant.
We are having an issue with Android devices registered in Intune - they are visible in Intune, and are showing as compliant etc, but for some reason the extension isn't able to find them.
The only difference between the devices in Intune that I can see is that the MAC address for Android devices is in the format AA:BB:CC:DD:EE:FF, whereas Windows devices are AABBCCDDEEFF.
The Filter query in the Intune HTTP auth source is as follows, but there is no 'Upper Case with Colon Delimiter' option we can use.
Unfortunately the DEBUG logs from the extension don't shed much light ont this.
Has anyone been able to use the extension for Android devices successfully before?
Checking with Microsoft. This seems to be new behavior.
We logged a support ticket with Microsoft, they pointed us to this article which says Android devices aren't supported with what looks like the Intune API that the ClearPass extension uses - can anyone confirm?
That should not be related to your issue. We're still awaiting a response from Intune enngineering.
Do you have the MS ticket number, I could try and escalate from my end as I have the same issue?
I have the same issue.
But for inexplicable reason, it works for few Androids.
Can you please also share the MS ticket in order to escalate on my own?
any new on this? what was the solution?
we have the exact same behaviour for over 1k new ipads
So a reveal at the end of this post.
I missed this original thread..... reading through all of the comments, where do you fit into the above?
new-devices working v not?
It seems the issue appears when the MAC randomization is enabled on the mobile. By disabling it, problem is solved for each Android.
@dannyjump, the behavior is the same, device make the query to intune, device is in intune, clearpass dont find the device in intune.
i dont see a format mismatch tho. even the logs in the extension look fine, like this:
At Aruba, we believe that the most dynamic customer experiences happen at the Edge. Our mission is to deliver innovative solutions that harness data at the Edge to drive powerful business outcomes.
© Copyright 2021 Hewlett Packard Enterprise Development LPAll Rights Reserved.