Forum Discussion

lfk73's avatar
lfk73
Brass Contributor
May 11, 2024
Solved

Why not in Intune

So I built a fresh windows 10 machine and when logging in for the first time i used my corporate login.  My machine shows up in devices in Entra and not in Intune.  i would expect an added machine be enrolled in intune automatically.

 

What did i miss?

  • lfk73 if it’s your device, you can remove it from your Entra ID in Settings by going to Access Work or School, click the account, and select remove. Your computer will reboot.

     

    Now redo the Entra ID join using an account that’s within scope of your automatic enrollment, and it’ll be joined to your Entra ID and Intune enrolled all in one go.

     

    Unfortunately, there is no built-in process to enroll a Windows device that’s already been Entra ID joined. There are some scripts and workarounds that you can find on the internet, but the Microsoft way is to do this process above.

5 Replies

  • ChrisVargas's avatar
    ChrisVargas
    Copper Contributor
    Automatic enrollment is not enabled by default.

    Set up automatic enrollment:

    https://learn.microsoft.com/en-us/mem/intune/enrollment/windows-enroll
    • lfk73's avatar
      lfk73
      Brass Contributor

      ChrisVargas hmm so seem that might have been the problem.

       

       

      So now how do i get it enrolled after enabling the Automatic enrollment?  Some script?  Sorry for the noob questions im learning.

      • ChrisVargas's avatar
        ChrisVargas
        Copper Contributor

        lfk73 if it’s your device, you can remove it from your Entra ID in Settings by going to Access Work or School, click the account, and select remove. Your computer will reboot.

         

        Now redo the Entra ID join using an account that’s within scope of your automatic enrollment, and it’ll be joined to your Entra ID and Intune enrolled all in one go.

         

        Unfortunately, there is no built-in process to enroll a Windows device that’s already been Entra ID joined. There are some scripts and workarounds that you can find on the internet, but the Microsoft way is to do this process above.

  • Most of the time, the user is not licensed for it... or is not in the mdm scope... or the mdm scope is off(automatic enrollment disabled)