Forum Discussion
Windows 11 + Intune: restrict devices to MDM-managed Wi-Fi profiles only
Your result matches the documented intent of AllowManualWiFiConfiguration set to 0: Windows permits Wi-Fi connections only to networks provisioned by MDM. Microsoft lists this device policy for Windows Pro, Enterprise, Education, and IoT Enterprise, so Entra versus hybrid join is not the deciding factor. The policy controls connection eligibility; hiding unmanaged SSIDs is the Windows UI behavior you are observing, not a separate SSID-filter guarantee. Before expanding deployment, push every required school profile first, because applying the block without a managed profile can leave devices offline and can remove user-created profiles. Pilot each Windows release, edition, adapter, dock, and certificate-authentication path separately. In Intune, review the per-setting status, then export the MDM diagnostic report from a test device and confirm the Policy CSP result. Also test password changes, certificate renewal, Wi-Fi outage failover, Autopilot, and recovery access. Your current configuration is supported, but validate visibility behavior after feature updates.