Windows 10 Enrollment

%3CLINGO-SUB%20id%3D%22lingo-sub-548714%22%20slang%3D%22en-US%22%3EWindows%2010%20Enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-548714%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EWe%20have%20Intune%20and%20Automatic%20enrolment%20for%20Windows%2010%20devices.%20They're%20joined%20to%20our%20on%20premise%20AD%20domain%20and%20hybrid%20joined%20to%20Azure%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20issue%20is%20that%20the%20Helpdesk%20guys%20end%20up%20being%20the%20registered%20owner%20and%20the%20enrolled%20by%20owner%20for%20these%20devices%20rather%20than%20the%20user.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3ECan%20someone%20let%20me%20know%20how%20we%20can%20stop%20this%3F%20Is%20it%20just%20a%20case%20of%20logging%20in%20the%20intended%20user%20first%20and%20letting%20it%20sync%3F%20Do%20we%20have%20to%20connect%20the%20user%20to%20Azured%20AD%20from%20the%20Accounts%20page%20in%20Settings%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-548714%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-549832%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-549832%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F110461%22%20target%3D%22_blank%22%3E%40David%20Gorman%3C%2FA%3E%26nbsp%3Bnormally%20with%20intune%20on%20AAD%20only%20the%20first%20user%20account%20that%20connects%20to%20intune%20is%20made%20the%20device%20owner.%20we%20have%20a%20mix%20of%20clients%20that%20either%20have%20all%20devices%20registered%20under%20one%20account%20(not%20ideal%20for%20most)%20or%20more%20commonly%20log%20on%20as%20the%20device%20primary%20user%20during%20device%20setup.%20havent%20played%20with%20automatic%20enrolment%20for%20hybrid%20devices%20but%20i%20would%20assume%20the%20logic%20would%20be%20the%20same%20that%20the%20login%20account%20that%20is%20connecting%20to%20Intune%20will%20be%20made%20the%20owener%20of%20the%20device....%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAutomatic%20redeployment%20and%20logging%20in%20as%20the%20primary%20user%20will%20update%20the%20device%20owner%2C%20not%20sure%20what%20issues%20this%20would%20cause%20with%20the%20on-prem%20account%20and%20you%20may%20have%20issues%20with%20applications%20needing%20re-install%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESteve%3A)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-549997%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-549997%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F332611%22%20target%3D%22_blank%22%3E%40SteveMacNZ%3C%2FA%3E%26nbsp%3Bthis%20is%20helpful%2C%20thanks%2C%20I'm%20following%20this%20thread%20for%20my%20own%20use%3B%20can%20you%20clarify%20how%20automatic%20redeployment%20works%3F%20Is%20this%20a%20retire%2Fwipe%2Fdelete%20of%20the%20device%2C%20or%20something%20else%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20would%20be%20lovely%20if%20we%20could%20just%20reassign%20the%20device%20to%20a%20different%20user%20like%20you%20could%20in%20old%20Intune%2C%20but%20until%20then%20-%20I%20found%20it%20hard%20to%20find%20a%20definitive%20'best%20practice'%20for%20how%20to%20do%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-550179%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-550179%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F15957%22%20target%3D%22_blank%22%3E%40Dev%20Lunsford%3C%2FA%3E%26nbsp%3Byes%20it%20would%20be%20great%20to%20be%20able%20to%20change%20the%20owner%20via%20the%20device%20management%20UI.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Feducation%2Fwindows%2Fautopilot-reset%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Feducation%2Fwindows%2Fautopilot-reset%3C%2FA%3E%26nbsp%3Band%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fosddeployment.dk%2F2018%2F05%2F20%2Fhow-to-deploy-windows-10-automatic-redeployment-with-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fosddeployment.dk%2F2018%2F05%2F20%2Fhow-to-deploy-windows-10-automatic-redeployment-with-intune%2F%3C%2FA%3E%26nbsp%3Bfor%20more%20information%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-551696%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-551696%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20all.%20While%20I%20understand%20the%20issues%20around%20assigning%20the%20device%20to%20a%20different%20person%2C%20this%20is%20for%20the%20setup%20initially.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20it%20be%20best%20to%20stop%20Windows%2010%20auto%20enrolling%20(from%20Group%20Policy)%20and%20making%20it%20manual%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-551962%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-551962%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F110461%22%20target%3D%22_blank%22%3E%40David%20Gorman%3C%2FA%3E%26nbsp%3Bsorry%20to%20hijack%20your%20thread%20%3A)%3C%2Fimg%3E%20I%20thought%20it%20was%20the%20same%20question%20I%20had%20but%20I%20see%20it%20was%20a%20little%20different.%3C%2FP%3E%3CP%3EDev%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hi all,


We have Intune and Automatic enrolment for Windows 10 devices. They're joined to our on premise AD domain and hybrid joined to Azure AD.

 

The issue is that the Helpdesk guys end up being the registered owner and the enrolled by owner for these devices rather than the user.


Can someone let me know how we can stop this? Is it just a case of logging in the intended user first and letting it sync? Do we have to connect the user to Azured AD from the Accounts page in Settings?

 

We

5 Replies

@David Gorman normally with intune on AAD only the first user account that connects to intune is made the device owner. we have a mix of clients that either have all devices registered under one account (not ideal for most) or more commonly log on as the device primary user during device setup. havent played with automatic enrolment for hybrid devices but i would assume the logic would be the same that the login account that is connecting to Intune will be made the owener of the device....

 

Automatic redeployment and logging in as the primary user will update the device owner, not sure what issues this would cause with the on-prem account and you may have issues with applications needing re-install

 

Steve:)

@SteveMacNZ this is helpful, thanks, I'm following this thread for my own use; can you clarify how automatic redeployment works? Is this a retire/wipe/delete of the device, or something else?

 

It would be lovely if we could just reassign the device to a different user like you could in old Intune, but until then - I found it hard to find a definitive 'best practice' for how to do this.

Thanks all. While I understand the issues around assigning the device to a different person, this is for the setup initially.

 

Would it be best to stop Windows 10 auto enrolling (from Group Policy) and making it manual

@David Gorman sorry to hijack your thread :) I thought it was the same question I had but I see it was a little different.

Dev

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies