So, next question from my side...
Is it somehow possible to enroll a device for a user without knowing his password?
Via the old device admin method or the BYOD Work Profile it is possible to choose the "Sign in from different device" option and then finish the setup.
The person preparing the device was able to contact the user, told him the code to sign in and then finish the setup.
Via this COPE enrollment you have to enter the PW twice.
The first Sign In is directly after the work profile is created.
Then you set up the device PIN(s) if required and download the Authenticator and Intune App.
When the two apps are installed you have to sign again to register the device in Intune.
On the first sign in it is possible to choose to sign in via a different device.
On the second sign in this is not possible, you have to enter the password. (Or I was not able to get it working...)
Does it even make sense to require a second sign in nearly instantly after the first one?
We are looking for a way to prepare devices for users without the requirement to get their passwords.