Forum Discussion

RomanK7's avatar
RomanK7
Brass Contributor
May 09, 2022

Enroll a Windows device in Intune with a non-administrator account

Hi

 

Basically, I am referring to the following article:

https://docs.microsoft.com/en-us/troubleshoot/mem/intune/no-permission-to-enroll-windows-devices

I have devices here that use Office 365 but are not synchronized with Azure AD Connect. This is also not possible (different AD). In order to be able to simplify a few points (conditional access, office installation), I would like to bring the devices into Intune.
The easiest way seems to me to be via the Company Portal App. And here's the point: isn't there a way to do this reasonably on existing devices without requiring the user to be a local admin?

How do you do this? Or is there a way to "take away" the user's admin rights after the Intune enrollment?

I hope I was able to adequately describe my concern. Otherwise just ask please.


11 Replies

  • Moe_Kinani's avatar
    Moe_Kinani
    Bronze Contributor
    RomanK7,

    You have two ways to do this:

    1. Sync the other AD with ADConnect, make them Hybrid Joined and apply gpo to auto enroll them to intune.

    https://cloudbymoe.com/f/enrolling-workstations-to-intune-using-gpo

    2. Sign in to each PC as a local admin and enroll them to Intune.

    Hope this helps!
    Moe
    • RomanK7's avatar
      RomanK7
      Brass Contributor
      On point 2: How is the device then assigned to the user in Azure AD / Intune? Enrollment manager?
      • Moe_Kinani's avatar
        Moe_Kinani
        Bronze Contributor
        It will be assigned to the user you join it with to intune. For example, Local admin user is Xyz and you join it abc@dmain.com, primary user in Intune will be abc@dmain.com

        Moe
  • Oktay Sari's avatar
    Oktay Sari
    Iron Contributor

    RomanK7 

    Not quite clear what the situation is so I have a few questions:

     

    1. Do your users have 2 accounts to deal with? One for on-premises and one for Office 365?
    2. Do your users log-in with their on-premise AD account on AD joined devices?
    3. Or are we talking about unmanaged devices with local accounts and no admin rights?
    4. You don't want the devices to be Azure AD joined but only MDM enrolled. Is that right?
    5. Why is Azure AD Connect not possible? Can you clarify?
    6. How do users work with Office 365 sources? Browser only?
    7. What licenses do your users have?

    By the way, It's not a requirement to have Intune managed devices to use conditional access. Conditional access can allow or restrict access to Microsoft 365 resources when users sign-in (identity-driven signals) using a managed or unmanaged devices, local apps or the browser. https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview 

    • RomanK7's avatar
      RomanK7
      Brass Contributor
      I'm sorry I didn't write everything clearly. I try to answer.
      1. No, only one Account is synced with Azure AD Cloud Sync, not Cloud Connect.
      2. Login on Device with their on-premise account.
      3. AD Joined Device with no local Admin rights.
      4. Right, only MDM enrolled
      5. Other AD (subsidiary)
      6. Apps and Web
      7. Microsoft 365 E3
  • What you're trying to do is (user-)enroll the device as BYOD, if I understand your description correctly, and that requires local admin-privileges.

    For more information on your options, see:
    https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-methods#user-self-enrollment-in-intune


    • RomanK7's avatar
      RomanK7
      Brass Contributor
      That's how I (unfortunately) see too