Would I be able to deploy Provisioning Packages via Intune and have it apply during Enrollment Status?
My idea would be to target the provisional package based on the users role or membership [HR, Finance, IT etc..]; the (.ppkg) can apply to the users role vs targeting the hardware. In the event the endpoint is re-purpose, I can send an Intune Remote-Wipe or AutoPilot Reset. Reissue the hardware to another team member/staff, they login, the (.ppkg) applies and it will be at the desired business ready state for that specific user. Or if I decide to purchase inexpensive Windows 10 endpoints have an (.ppkg) Kiosk mode allowing specific application(s) such as Citrix Receiver restricting the user from navigating Windows as well. Forcing the end user to our RSA or MFA storefront. This way they log into their assigned workspace. If so, we would be able to use Intune and Windows 10 vs GoogleAdmin and Chrome OS for our thin client solution.