Forum Discussion
Enroll a Windows device in Intune with a non-administrator account
Hi
Basically, I am referring to the following article:
https://docs.microsoft.com/en-us/troubleshoot/mem/intune/no-permission-to-enroll-windows-devices
I have devices here that use Office 365 but are not synchronized with Azure AD Connect. This is also not possible (different AD). In order to be able to simplify a few points (conditional access, office installation), I would like to bring the devices into Intune.
The easiest way seems to me to be via the Company Portal App. And here's the point: isn't there a way to do this reasonably on existing devices without requiring the user to be a local admin?
How do you do this? Or is there a way to "take away" the user's admin rights after the Intune enrollment?
I hope I was able to adequately describe my concern. Otherwise just ask please.
11 Replies
- Moe_KinaniBronze ContributorRomanK7,
You have two ways to do this:
1. Sync the other AD with ADConnect, make them Hybrid Joined and apply gpo to auto enroll them to intune.
https://cloudbymoe.com/f/enrolling-workstations-to-intune-using-gpo
2. Sign in to each PC as a local admin and enroll them to Intune.
Hope this helps!
Moe- RomanK7Brass ContributorOn point 2: How is the device then assigned to the user in Azure AD / Intune? Enrollment manager?
- Moe_KinaniBronze ContributorIt will be assigned to the user you join it with to intune. For example, Local admin user is Xyz and you join it abc@dmain.com, primary user in Intune will be abc@dmain.com
Moe
- Oktay SariIron Contributor
Not quite clear what the situation is so I have a few questions:
- Do your users have 2 accounts to deal with? One for on-premises and one for Office 365?
- Do your users log-in with their on-premise AD account on AD joined devices?
- Or are we talking about unmanaged devices with local accounts and no admin rights?
- You don't want the devices to be Azure AD joined but only MDM enrolled. Is that right?
- Why is Azure AD Connect not possible? Can you clarify?
- How do users work with Office 365 sources? Browser only?
- What licenses do your users have?
By the way, It's not a requirement to have Intune managed devices to use conditional access. Conditional access can allow or restrict access to Microsoft 365 resources when users sign-in (identity-driven signals) using a managed or unmanaged devices, local apps or the browser. https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview
- RomanK7Brass ContributorI'm sorry I didn't write everything clearly. I try to answer.
1. No, only one Account is synced with Azure AD Cloud Sync, not Cloud Connect.
2. Login on Device with their on-premise account.
3. AD Joined Device with no local Admin rights.
4. Right, only MDM enrolled
5. Other AD (subsidiary)
6. Apps and Web
7. Microsoft 365 E3
- NielsScheffersIron ContributorWhat you're trying to do is (user-)enroll the device as BYOD, if I understand your description correctly, and that requires local admin-privileges.
For more information on your options, see:
https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-methods#user-self-enrollment-in-intune- RomanK7Brass ContributorThat's how I (unfortunately) see too