SOLVED

Documentation about Inune only enrollment on Microsoft Docs and use cases

%3CLINGO-SUB%20id%3D%22lingo-sub-1293815%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1293815%22%20slang%3D%22en-US%22%3EAre%20you%20looking%20for%20this%3F%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fmicroscott.azurewebsites.net%2F2018%2F08%2F31%2Fmanaging-windows-10-with-intune-the-many-ways-to-enrol%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fmicroscott.azurewebsites.net%2F2018%2F08%2F31%2Fmanaging-windows-10-with-intune-the-many-ways-to-enrol%2F%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1293860%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1293860%22%20slang%3D%22en-US%22%3E%3CP%3ELooks%20like%20it's%20this%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fmdm-enrollment-of-windows-devices%23connecting-personally-owned-devices-bring-your-own-device%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fmdm-enrollment-of-windows-devices%23connecting-personally-owned-devices-bring-your-own-device%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ecan't%20be%20sure%20since%20that%20one%20gives%20404%20error.%3CBR%20%2F%3E%3CBR%20%2F%3Eby%20the%20way%20just%20wanna%20check%20and%20confirm%20this%2C%20if%20a%20device%20is%20only%20enrolled%20in%20Microsoft%20MDM%20and%20not%20AAD%2C%20Intune%20or%20endpoint%20management%20can%20still%20control%20that%20device%20such%20as%20setting%20policies%20etc%2C%20right%3F%20will%20there%20be%20any%20limitations%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1294787%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1294787%22%20slang%3D%22en-US%22%3EIf%20you%20would%20enroll%20it%20like%20%233%2C%20the%20device%20would%20also%20be%20joined%20to%20AAD%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20my%20knowledge%2C%20all%20W10%20devices%20that%20enroll%20into%20Intune%20are%20also%20joined%20to%20AAD%2C%20no%20exceptions%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1295117%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1295117%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20come%3F%3CBR%20%2F%3EScenario%203%3A%20Enroll%20in%20MDM%20%3CSTRONG%3EOnly%3C%2FSTRONG%3E%20(User%20Driven)%3C%2FP%3E%3CP%3Eit's%20this%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fmdm-enrollment-of-windows-devices%23connecting-to-mdm-on-a-desktop-enrolling-in-device-management%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fmdm-enrollment-of-windows-devices%23connecting-to-mdm-on-a-desktop-enrolling-in-device-management%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1296002%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1296002%22%20slang%3D%22en-US%22%3EI'll%20test%20this%2C%20I'll%20let%20you%20know%20when%20I%20have%20tested%3CBR%20%2F%3EBut%20I%20thought%20enrollment%20requires%20the%20device%20in%20AAD%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1296273%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1296273%22%20slang%3D%22en-US%22%3EThank%20you%20so%20much!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1297436%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1297436%22%20slang%3D%22en-US%22%3EI%20just%20tested%3CBR%20%2F%3EIf%20you%20use%20this%20method%2C%20it%20indeed%20only%20joins%20to%20Intune.%20I%20was%20mistaken%3CBR%20%2F%3EIt%20does%20create%20a%20device%20in%20AAD%20(on%20object)%2C%20but%20it's%20not%20joined%20to%20AAD.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20mentioned%20on%20the%20blog%20post%20this%20would%20only%20be%20used%20in%20BYOD%20(personal%20devices%20that%20require%20management)%20or%20if%20you%20don't%20have%20automatic%20enrollment.%3CBR%20%2F%3E%3CBR%20%2F%3EWhy%20are%20you%20planning%20to%20use%20it%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1297771%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1297771%22%20slang%3D%22en-US%22%3EThank%20you%2C%20appreciate%20that!%3CBR%20%2F%3EI'm%20just%20trying%20to%20evaluate%20different%20approaches.%20I%20think%20if%20a%20device%20is%20only%20joined%20to%20MDM%20and%20not%20AAD%2C%20it%20is%20less%20secure%20and%20less%20controlled%2C%20right%3F%20because%20the%20user%20still%20has%20full%20Admin%20rights.%3CBR%20%2F%3E%3CBR%20%2F%3Eand%20more%20importantly%2C%20the%20group%20policies%20that%20I%20set%20in%20MDM%20for%20that%20device%2C%20can%20be%20changed%20by%20the%20user%20of%20that%20device%2C%20am%20I%20right%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1297811%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20find%20documentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1297811%22%20slang%3D%22en-US%22%3EIf%20you%20don't%20do%20an%20Azure%20AD%20join%2C%20the%20user%20doesn't%20login%20with%20his%20AAD%20credentials.%20This%20isn't%20desired%3CBR%20%2F%3E%3CBR%20%2F%3EA%20user%20can%20always%20change%20policies%20if%20the%20user%20is%20a%20local%20admin%20on%20his%20device.%20With%20this%20enrollment%20method%20this%20is%20always%20the%20case.%3CBR%20%2F%3EI%20would%20strongly%20advise%20that%20a%20user%20isn't%20a%20local%20admin.%20You%20can%20use%20the%20site%20I%20linked%20above%20to%20check%20what%20enrollment%20suits%20you%20best%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1293562%22%20slang%3D%22en-US%22%3EDocumentation%20about%20Inune%20only%20enrollment%20on%20Microsoft%20Docs%20and%20use%20cases%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1293562%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20was%20reading%20this%20doc%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fnzedu%2F10-ways-to-enroll-windows-10-into-intune%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fnzedu%2F10-ways-to-enroll-windows-10-into-intune%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%20to%20view%20all%20of%20the%2010%20ways%2C%20it%20was%20suggested%20to%20go%20to%20this%20page%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fmicroscott%2Fmanaging-windows-10-with-intune-the-many-ways-to-enrol%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Farchive%2Fblogs%2Fmicroscott%2Fmanaging-windows-10-with-intune-the-many-ways-to-enrol%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ebut%20It%20doesn't%20exist.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20looking%20for%20a%20documentation%20on%20Microsoft%20docs%20for%20this%20specific%20scenario%3A%3C%2FP%3E%3CP%3E%3CSTRONG%3EScenario%203%3A%20Enrol%20in%20MDM%20Only%20(User%20Driven)%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ecould%20anyone%20point%20me%20to%20it%3F%20thanks%20in%20advance%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1293562%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Honored Contributor

Hello,

I was reading this doc:

https://docs.microsoft.com/en-us/archive/blogs/nzedu/10-ways-to-enroll-windows-10-into-intune

 

and to view all of the 10 ways, it was suggested to go to this page:

https://docs.microsoft.com/en-us/archive/blogs/microscott/managing-windows-10-with-intune-the-many-w...

 

but It doesn't exist.

 

I'm looking for a documentation on Microsoft docs for this specific scenario:

Scenario 3: Enrol in MDM Only (User Driven)

 

could anyone point me to it? thanks in advance

9 Replies
Highlighted

Looks like it's this:

https://docs.microsoft.com/en-us/windows/client-management/mdm/mdm-enrollment-of-windows-devices#con...

 

can't be sure since that one gives 404 error.

by the way just wanna check and confirm this, if a device is only enrolled in Microsoft MDM and not AAD, Intune or endpoint management can still control that device such as setting policies etc, right? will there be any limitations?

Highlighted
If you would enroll it like #3, the device would also be joined to AAD

To my knowledge, all W10 devices that enroll into Intune are also joined to AAD, no exceptions
Highlighted
Highlighted
I'll test this, I'll let you know when I have tested
But I thought enrollment requires the device in AAD
Highlighted
Highlighted
I just tested
If you use this method, it indeed only joins to Intune. I was mistaken
It does create a device in AAD (on object), but it's not joined to AAD.

As mentioned on the blog post this would only be used in BYOD (personal devices that require management) or if you don't have automatic enrollment.

Why are you planning to use it?

Highlighted
Thank you, appreciate that!
I'm just trying to evaluate different approaches. I think if a device is only joined to MDM and not AAD, it is less secure and less controlled, right? because the user still has full Admin rights.

and more importantly, the group policies that I set in MDM for that device, can be changed by the user of that device, am I right?

Highlighted
Solution
If you don't do an Azure AD join, the user doesn't login with his AAD credentials. This isn't desired

A user can always change policies if the user is a local admin on his device. With this enrollment method this is always the case.
I would strongly advise that a user isn't a local admin. You can use the site I linked above to check what enrollment suits you best