SOLVED

Azure AD P1 and Autopilot question

%3CLINGO-SUB%20id%3D%22lingo-sub-1705011%22%20slang%3D%22en-US%22%3EAzure%20AD%20P1%20and%20Autopilot%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1705011%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20looking%20to%20try%20autopilot%20with%20Azure%20AD%20only%20as%20well%20as%20hybrid%20AD%20join.%20Want%20to%20understand%20all%20the%20licensing%20requirements%20for%20Azure%20AD%2C%20Intune%20and%20Autopilot.%20Is%20it%20possible%20to%20run%20a%20Autopilot%20in%20production%20with%20limited%20number%20of%20Azure%20AD%20Premium%20P1%20licenses.%20We%20do%20not%20have%20Azure%20AD%20P1%20for%20enterprise%20only%20few%20licenses%20.%3C%2FP%3E%3CP%3E1)%20Will%20it%20be%20possible%20to%20reclaim%20these%20Azure%20AD%20P1%26nbsp%3B%20licenses%20and%20assign%20to%20another%20set%20of%20machines%20after%20autopilot%20process%20is%20complete.%3C%2FP%3E%3CP%3E2)%20Without%20Azure%20AD%20PP1%20what%20functionality%20do%20we%20loose%20with%20respect%20to%20Intune%20and%20autopilot%20in%20production%20environment.%3C%2FP%3E%3CP%3E3)%20Do%20we%20need%20to%20enabled%20Device%20Write%20back%20in%20Azure%20AD%20connect%2C%20when%20is%20it%20needed%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1705011%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1706370%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20P1%20and%20Autopilot%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1706370%22%20slang%3D%22en-US%22%3EHi%20VK%3CBR%20%2F%3E%3CBR%20%2F%3E1)%20The%20AAD%20licenses%20would%20be%20assigned%20to%20users%2C%20not%20devices.%20Licenses%20can%20be%20reassigned%2C%20but%20you%20would%20need%20to%20ensure%20that%20users%20aren't%20leveraging%20any%20other%20capabilities%20of%20AADP%20P1%20prior%20to%20the%20licenses%20being%20revoked%20and%20then%20losing%20those%20features%20as%20well.%20%3CBR%20%2F%3E2)%20The%20biggest%20initial%20benefit%20you%20get%20by%20adding%20AADP%20P1%20to%20Autopilot%20is%20that%20the%20devices%20will%20automatically%20enroll%20with%20Intune%20after%20performing%20the%20AAD%20Join%2C%20rather%20than%20it%20being%20an%20extra%20manual%20step.%20This%20means%20that%20if%20a%20device%20reset%20is%20performed%2C%20and%20the%20AAD%20P1%20license%20isn't%20assigned%20to%20the%20user%2C%20the%20device%20will%20be%20AAD%20Joined%2C%20but%20not%20Intune%20managed%20until%20that%20is%20addressed%20separately.%20%3CBR%20%2F%3E3)%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-device-writeback%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-device-writeback%3C%2FA%3E%20has%20more%20details%2C%20but%20two%20of%20the%20main%20scenarios%20are%20WHfB%20with%20hybrid%20certs.%20and%20CA%20via%20ADFS.%20Others%20may%20have%20some%20additional%20use%20case%20scenarios%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1708152%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20P1%20and%20Autopilot%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1708152%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F48091%22%20target%3D%22_blank%22%3E%40Mark%20O'Shea%3C%2FA%3E%26nbsp%3B%20Hi%20Mark%20%2C%20Thank%20you%20for%20the%20detailed%20responses.%20We%20are%20looking%20to%20use%20Azure%20AD%20P1%20and%20Intune%20only%20for%20Auotpilot%20process.%20Once%20the%20Auotpilot%20process%20is%20complete%20and%20the%20SCCM%20client%20is%20installed%20on%20the%20machine%2C%20I%20was%20thinking%20the%20ongoing%20licensing%20requirement%20may%20be%20covered%20by%20the%26nbsp%3B%20SCCM%20co-management%20license.%20Please%20suggest%20if%20you%20see%20any%20issues%20with%20this%20approach.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1708269%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20P1%20and%20Autopilot%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1708269%22%20slang%3D%22en-US%22%3EAzure%20AD%20Premium%20P2%20license%20is%20assigned%20on%20per%20user%20basis.%20If%20only%20100%20users%20wants%20to%20use%20the%20premium%20features%2C%20license%20needs%20to%20be%20assigned%20to%20only%20those%20100%20users%20and%20not%20to%20all%20200%20users.%3CBR%20%2F%3E%3CBR%20%2F%3EFor%20guest%20users%2C%20you%20need%20to%20maintain%205%3A1%20which%20means%2C%20if%20guest%20users%20want%20to%20use%20Premium%20P2%20features%2C%20you%20don't%20need%20to%20assign%205%20licenses%20to%205%20guest%20users.%20You%20just%20need%20to%20assign%201%20license%20to%20any%20of%20those%205%20guest%20users.%20If%2010%20guest%20users%20want%20to%20use%20Premium%20feature%2C%20assign%20license%20to%20only%202%20guest%20users%20out%20of%20those%2010%20users%2C%20in%20order%20to%20stay%20compliant.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1710184%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20P1%20and%20Autopilot%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1710184%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F210281%22%20target%3D%22_blank%22%3E%40vk%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20aren't%20enabling%20other%20AADP%20P1%20scenarios%2C%20I%20think%20this%20would%20work%20for%20the%20enrolment%2C%20but%20longer%20term%20hopefully%20there%20are%20other%20things%20in%20P1%20that%20you%20can%20leverage%20which%20means%20it%20will%20be%20rolled%20out%20for%20everyone.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3ENormally%20I%20would%20recommend%20creating%20groups%20based%20on%20licensing%2C%20but%20in%20your%20case%20I%20think%20the%20slight%20delays%20of%20the%20dynamic%20groups%20being%20updated%20when%20licenses%20are%20reassigned%20might%20be%20a%20problem%2C%20so%20I%20would%20just%20stick%20to%20assigning%20users%20to%20the%20groups.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

We are looking to try autopilot with Azure AD only as well as hybrid AD join. Want to understand all the licensing requirements for Azure AD, Intune and Autopilot. Is it possible to run a Autopilot in production with limited number of Azure AD Premium P1 licenses. We do not have Azure AD P1 for enterprise only few licenses .

1) Will it be possible to reclaim these Azure AD P1  licenses and assign to another set of machines after autopilot process is complete.

2) Without Azure AD PP1 what functionality do we loose with respect to Intune and autopilot in production environment.

3) Do we need to enabled Device Write back in Azure AD connect, when is it needed?

4 Replies
Highlighted
Best Response confirmed by Mark O'Shea (MVP)
Solution
Hi VK

1) The AAD licenses would be assigned to users, not devices. Licenses can be reassigned, but you would need to ensure that users aren't leveraging any other capabilities of AADP P1 prior to the licenses being revoked and then losing those features as well.
2) The biggest initial benefit you get by adding AADP P1 to Autopilot is that the devices will automatically enroll with Intune after performing the AAD Join, rather than it being an extra manual step. This means that if a device reset is performed, and the AAD P1 license isn't assigned to the user, the device will be AAD Joined, but not Intune managed until that is addressed separately.
3) https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-device-writeback has more details, but two of the main scenarios are WHfB with hybrid certs. and CA via ADFS. Others may have some additional use case scenarios

@Mark O'Shea  Hi Mark , Thank you for the detailed responses. We are looking to use Azure AD P1 and Intune only for Auotpilot process. Once the Auotpilot process is complete and the SCCM client is installed on the machine, I was thinking the ongoing licensing requirement may be covered by the  SCCM co-management license. Please suggest if you see any issues with this approach.

Highlighted
Azure AD Premium P2 license is assigned on per user basis. If only 100 users wants to use the premium features, license needs to be assigned to only those 100 users and not to all 200 users.

For guest users, you need to maintain 5:1 which means, if guest users want to use Premium P2 features, you don't need to assign 5 licenses to 5 guest users. You just need to assign 1 license to any of those 5 guest users. If 10 guest users want to use Premium feature, assign license to only 2 guest users out of those 10 users, in order to stay compliant.
Highlighted

@vk 

 

If you aren't enabling other AADP P1 scenarios, I think this would work for the enrolment, but longer term hopefully there are other things in P1 that you can leverage which means it will be rolled out for everyone. 

Normally I would recommend creating groups based on licensing, but in your case I think the slight delays of the dynamic groups being updated when licenses are reassigned might be a problem, so I would just stick to assigning users to the groups.