maciejrebisz.com

IT

Intune – Windows device enrollment restrictions – Mobile-First Cloud-First

maximios May 11, 2021

Now it is finally available – that being the feature to restrict enrollment for Windows device in Intune to corporate owned device only. There is many companies that will not allow there user to enroll private owned devices in there corporate environment. It has been a possibility for some time on other device type like IOS, Android and macOS.

The following methods qualify as being authorized as a Windows corporate enrollment:

  • The enrolling user is using a device enrollment manager account.
  • The device enrolls through Windows AutoPilot.
  • The device is registered with Windows Autopilot but is not an MDM enrollment only option from Windows Settings.
  • The device’s IMEI number is listed in Device enrollment > Corporate device identifiers. (Not supported for Windows Phone 8.1.)
  • The device enrolls through a bulk provisioning package.
  • The device enrolls through automatic enrollment from SCCM for co-management.

How to set it up:
Start the Microsoft 365 Device Management portal

Click on Device enrollment

  1. Click Enrollment restrictions
  2. Click Default
  1. Click Properties
  2. Click Configure
  3. Click Block

Now the end user is not allowed to enroll a personal Windows Devices.

What is the end user experience like:

When trying to enroll a device from the settings app on Windows 10

Accounts:

  1. Access work or school
  2. Enroll only in Device management
  3. Enter the Azure AD credential

Then this message will show up for the end user

There is many scenarios where the device enrollment restriction can be of value – but please only use it if you need it and under no circumstances allow your users to use there own devices.

If you allow users to use there own devices – I will be a great idea to let the end user be able to enroll there devices so that they can be Intune managed and be marked as compliant to use with Conditional Access.

Happy testing

/Per

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ Conditional Access – Page 2 – Mobile-First Cloud-First › Use ADMX Policy to prevent Microsoft Teams from starting automatically after installation with Intune – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes