Jul 06 2022 06:39 AM
Unbeknownst to me, none of our Windows laptops that are auto-enrolled into InTune via Azure AD join are included with the device limitation so we can't "limit" a number of devices an Employee is to have.
So if InTune cannot include these laptops that all Employees have, I assume I must then change the limitation to 1 device which would be a cellphone (since we supply all Employees with one). That solves the issue of not adding more than 1 mobile device (since the conditional access policy will force them to enroll if they try add email or apps to a different phone) but what about multiple laptops?
I know the risk is less but there is nothing stopping an Employee from joining another laptop to Azure as it only requires an email, password and MFA which they have. I can't change the Azure device limitation to 1 because Azure also lists the devices from Intune so won't that cause an issue there?
There seems to be so many things Microsoft didn't think about. Yes we love the auto-enroll with InTune since it's easy but now we can't limit?
Jul 06 2022 11:46 PM
Jul 07 2022 05:58 AM
Jul 07 2022 07:48 AM