maciejrebisz.com

IT

Block personal Windows devices from enrolling into Intune – Mobile-First Cloud-First

maximios May 11, 2021

I see more and more customers that are allowing Azure Active Directory join of Windows 10 Devices also with automatic MDM enrollement into Intune, and many are concerned about letting personal devices getting into Intune and there for having the possibility to be complaint. When a device is compliant, we can use it to give access to corporate resources with Conditional Access.
There is a way to block Intune enrollment of personal devices, but it requires that you need to understand the consequences for doing that.

A Windows device that the end user is enrolling into Intune is personal unless that you tell Intune that it is a corporate device or you AzureAD join from OOBE.A corporate Windows devices is also:

  • Hybrid joined Windows device with automatic MDM enrollment GPO set
  • SCCM Co-managed device
  • Autopilot device
  • Bulked enrolled with WCD or set up school PC
  • Enrollment with a Device Enrollment Manager

How to configure the device restriction to only allow corporate Windows device

Start the Microsoft 365 device management portal

  1. Click on Device enrollment
  2. Click on Device restriction
  3. Click on default

  1. Click on properties
  2. Click on Select platforms
  3. Ensure that you are allowing Windows (MDM) enrollment set to allow or all Windows enrollment will be blocked

  1. Click on properties
  2. Click on configure
  3. Click on block for Windows personally owned

From a end user perspective they will get a welcome message when the device is a Autopilot device

Note: If you are injecting the AutopilotConfigurationFile.json file in you image solution or other ways with out uploading the Autopilot device information to Intune, it does not have a corporate ID in Intune and are there for a personal device!

But when it is not a Autopilot device – AKA a personal device the end user will get a error message that the device will not enroll and you need to contact your system administrator

If you have configured Windows Information Protection (WIP) without enrollment it will still work.
When a user is installing Office365 ProPlus C2R from https://office365download.com after the installation has ended the end user normally just click yes without reading what there is written – and if WIP is not configured and the end user will get a error here. In my case WIP without enrollment is configured to secure access to corporate data.

The device will be registered to AzureAD so that Microsoft can check Office activation and check if the device need to be automatic MDM enrolled, WIP without enrollment or just do the device registering

After is it done you can check in the settings app that the device mas a management server address : https://wip.mam.manage.microsoft.com that shows it is not managed but get the WIP without enrollment policy from Intune (This still requires a Intune license)

Happy testing πŸ™‚

Read more:

Blocking personal Windows devices
https://docs.microsoft.com/en-us/intune/enrollment-restrictions-set#blocking-personal-windows-devices

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add β€œhidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ Use ADMX Policy to prevent Microsoft Teams from starting automatically after installation with Intune – Mobile-First Cloud-First › Intune Enrollment Status Screen for Windows 10 (Preview) – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add β€œhidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes