Our Windows Autopilot client deployment relies on the machine tunnel connectivity to our AD controllers hosted on Azure.
It has turned out that once the Zscaler client connector is deployed via Intune during the Windows setup, the machine tunnel is successfully established (app package is deployed with the machine provisioning key), but the internal domain is not resolved.
Result: Windows Autopilot deployment is stuck in the “Enrollment Status Page” Stage 3, where the device is trying to join the on-premises domain.
Pre-verification tasks for automatic device joining have been completed. NO join can be performed for the device because no domain controller was found. The device must be connected to a network that is connected to an Active Directory domain controller.
Let’s assume our internal domain is company.lan where the domain is added to the search domains in ZPA.
What I’ve tested so far (and whats really strange IMHO):
nslookup company.lan → fails
ping company.lan → fails (should be resolved by Zscaler AFAIK)
ping ad01.company.lan → success (ICMP response when using a FQDN)
What I didn’t get is, why DNS resolution using a FQDN is working and resolving the domain itself is not.
Some screenshots for further clarification:
The required servers that needs to be contacted are added by IP and FQDN in the application segment.