Forum Discussion
DGMalcolm
Jul 24, 2022Iron Contributor
Prevent Azure AD & Intune Enrollment
Is there a way to prevent a user from connecting a personal/home PC to Azure AD and, more importantly, to prevent them from enrolling in Intune? We have a growing number of personal systems that show as Azure AD devices and a significant number of those are Intune enrolled.
TIA
~DGM~
Hi DGMalcolm ,
yes it is possible.
To block Intune enrollment you have the option to set enrollment restrictions
https://docs.microsoft.com/en-us/mem/intune/enrollment/enrollment-restrictions-set
For azure ad you have to option users may join azure ad. And you can allow azure ad join for some users, all users or block (none)
kind regards,
rene
- setting up server side prevention by configuring the enrollment restrictions is indeed the way to go
https://call4cloud.nl/2021/08/the-battle-between-aadj-and-aadr/#part1
As configuring a registry key for each device (or using a gpo) client side isn't the best method - Mr_HelaasSteel Contributor
Hi DGMalcolm ,
yes it is possible.
To block Intune enrollment you have the option to set enrollment restrictions
https://docs.microsoft.com/en-us/mem/intune/enrollment/enrollment-restrictions-set
For azure ad you have to option users may join azure ad. And you can allow azure ad join for some users, all users or block (none)
kind regards,
rene
- MDMhackedHELPCopper Contributor
Hello, it started with one device but ALL my devices have auto enrolled into MDM Intune enrollment. Either my spouses MDM work computer and phone auto enrolled everything from the home network or it's a complete hack scenario. Either way, I need HELP. Please. This has been ongoing now for almost 6-months: permissions changed, passwords changed, social accounts hacked. My main PC, where it started, shows active enrollment. Factory resets failed to clear it and it's across both PC and Mac operating systems, as well as android and iphone.
How to disconnect my name and devices and STOP auto enrollment with new devices. I'm out thousands because I didn't understand what was happening. HELP is so appreciated as normal IT companies are not trained in this and had no idea. - DGMalcolmIron ContributorThank you for this, it's given me a good start.