Client Enrolment Auth failed

Solved
Trixxz
Here to help

Client Enrolment Auth failed

Hi all

 

Today we have experienced a problem adding new clients via enrolment. We enter in the enrolment address and our meraki endpoint address, at the point we get asked to sign into azure we get an "auth fail" box appear.

 

We can sync with Azure OK on the Overview Page in SSM

 

This is on a Windows 10 and Windows 11 machine.

 

Has anyone else seen/solved this? We have a ticket open at the moment but we aren't getting very far it seems.

1 Accepted Solution
Rebekah
Conversationalist

Not yet heard anything further from Meraki but my devices suddenly started enrolling normally at the end of last week. Only changes I've made to our Meraki environment was that I'd turned authenication off, then back on again.

View solution in original post

13 Replies 13
Meraki_fan2
New here

Same here with Google OAuth, on Windows 11. The same problem occurs with the browser enrollment. Still no replies on the ticket so far.

Trixxz
Here to help

Ive had some back and forth with Email support - Nothing suggested other than "Turn off Auth as a workaround" Ive basically been told that ill need to call in for complex troubleshooting support.

Rebekah
Conversationalist

I haven't yet logged a ticket with Meraki regarding this but we're experiencing the same issue.

 

Nothing has changed on our setup lately and it was working last on the 10th January when I set up my last batch of laptops. Only thing that's changed in the interrim are maybe a few windows updates.

 

Tried to use the "Send enrollment link" method as well but the web page just spins indefinitely at "waiting for device to check in".

 

Occurs for us on Windows 10 and 11 devices with Google Auth. 

Trixxz
Here to help

One of our techs is on with Tech support now, ill update if we have fix given to us.

Trixxz
Here to help

Nothing to add today - Tech support had us do a screen recording of the problem as it occurs which we have sent. Only update from Meraki today was "we are looking into this"

khchang
Conversationalist

I have same issue

Tech support answer 

---------------------------------------------------

I am checking your dashboard right now and also double checking with my team and seems we are currently having Authentication issue with third-party Authenticator when enrolling device to SM.

A workaround at this point of time from our team is Navigate to System Manager > Configure > General > Enrollment settings then uncheck "Authentication".
-----------------------------------------------------------

 

it's not a good idea. but can save problem temporary.

 

Hope it's useful to you.

I would bear in mind that when setting that, you leave a big security hole.

khchang
Conversationalist

thanks for your reminder.I know it's danger.still wait tech support better answer

Rebekah
Conversationalist

I've had an email from Meraki regarding this, this is what I've been told:

 

"Thank you for contacting Cisco Meraki Technical Support and providing the steps taken so far. There does appear to be some other users reporting this and a case has been opened internally"

 

Hopefully they find the cause soon.

Rebekah
Conversationalist

Not yet heard anything further from Meraki but my devices suddenly started enrolling normally at the end of last week. Only changes I've made to our Meraki environment was that I'd turned authenication off, then back on again.

Hi Rebekah - I did the exact same thing this morning out of frustration - Devices now enrolling again 🙂

How did you turn the authentication off and back on again?  In the meraki portal or where?  Can you please elaborate?

Trixxz
Here to help

Just an update - it was working up until yesterday and now we are getting "Credentials incorrect or Auth Timeout" when enrolling desktop machines. @Meraki Please can you give us some idea of A: what is wrong and B: how long to fix?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels