SOLVED

correct my understanding on enroll personal pc to intune

%3CLINGO-SUB%20id%3D%22lingo-sub-2987974%22%20slang%3D%22en-US%22%3Ecorrect%20my%20understanding%20on%20enroll%20personal%20pc%20to%20intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2987974%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20very%20confused%20about%20%3CSTRONG%3Eenrolling%20the%20personal%20PC%20to%20intune%3C%2FSTRONG%3E%20that%3C%2FP%3E%3CP%3Ewhen%20we%20connect%20our%20work%20account%20via%20%3CSTRONG%3E%3CEM%3ESetting%20%26gt%3B%26gt%3B%20Accounts%20%26gt%3B%26gt%3B%20Access%20work%20or%20school.%3C%2FEM%3E%3C%2FSTRONG%3E%20This%20enrollment%20method%20means%20we%20enroll%20as%20MDM%20right%3F%20and%20the%20user%20doesn't%20need%20to%20log%20in%20with%20the%20work%20account%20for%20accessing%20to%20their%20pc.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2987974%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2988907%22%20slang%3D%22en-US%22%3ERe%3A%20correct%20my%20understanding%20on%20enroll%20personal%20pc%20to%20intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2988907%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EHI%2C%20you%20are%20mentioning%20AADR.%20If%20you%20want%20to%20get%20a%20good%20understanding%20about%20aadj%20vs%20aadr%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fcall4cloud.nl%2F2021%2F08%2Fthe-battle-between-aadj-and-aadr%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcall4cloud.nl%2F2021%2F08%2Fthe-battle-between-aadj-and-aadr%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20you%20think%20about%20AADR%3A%20Azure%20AD%20knows%20about%20the%20device%20but%20DOESN%E2%80%99T%20REQUIRE%20a%20corporate-owned%20identity%20to%20login%20into%20the%20device%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2991221%22%20slang%3D%22en-US%22%3ERe%3A%20correct%20my%20understanding%20on%20enroll%20personal%20pc%20to%20intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2991221%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F620702%22%20target%3D%22_blank%22%3E%40Rudy_Ooms%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAppreciate%20it!%3CBR%20%2F%3Eso%2C%20this%20means%20if%20you%20add%20the%20work%20account%20to%20your%20personal%20laptop.%20Your%20device%20will%20become%20%22AADR%22%20and%20enrolled%20(MDM)%2C%20is%20it%20correct%3F%3C%2FP%3E%3CP%3EIn%20my%20lab%2C%20my%20personal%20device%20is%20shown%20like%20this%2C%20is%20it%20MDM%20or%20MAM%3F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22mmchx_1-1637549275438.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F328489iA6B25A055BCE9A03%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22mmchx_1-1637549275438.png%22%20alt%3D%22mmchx_1-1637549275438.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22mmchx_2-1637549330610.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F328490iFF36D80A3C2CD132%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22mmchx_2-1637549330610.png%22%20alt%3D%22mmchx_2-1637549330610.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I'm very confused about enrolling the personal PC to intune that

when we connect our work account via Setting >> Accounts >> Access work or school. This enrollment method means we enroll as MDM right? and the user doesn't need to log in with the work account for accessing to their pc.

3 Replies
Hi,

HI, you are mentioning AADR. If you want to get a good understanding about aadj vs aadr

https://call4cloud.nl/2021/08/the-battle-between-aadj-and-aadr/

When you think about AADR: Azure AD knows about the device but DOESN’T REQUIRE a corporate-owned identity to login into the device

@Rudy_Ooms 

Appreciate it!
so, this means if you add the work account to your personal laptop. Your device will become "AADR" and enrolled (MDM), is it correct?

In my lab, my personal device is shown like this, is it MDM or MAM?

mmchx_1-1637549275438.png

mmchx_2-1637549330610.png

 

best response confirmed by mmchx (Occasional Contributor)
Solution
Hi,

In the blog I mentioned, I am also mentioning the MDM vs MAM part.

"So to be clear: You can add a user to both groups who are in the MDM AND MAM scope but when doing so a user with a personal BYOD will automatically be pushed to MAM and the device will not be managed with Intune and will never ever be compliant!"

And your device is "compliant" so :)....