Enforce device enrolment for company devices

%3CLINGO-SUB%20id%3D%22lingo-sub-164066%22%20slang%3D%22en-US%22%3EEnforce%20device%20enrolment%20for%20company%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-164066%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe're%20about%20to%20go%20live%20with%20Microsoft%20Intune%20within%20our%20company%2C%20but%20I%20was%20wondering%20if%20there%20is%20a%20way%20to%20enforce%20device%20enrolment%20for%20users%20who%20have%20a%20company%20device%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20know%20that%20we%20can%20enforce%20enrolment%20into%20Intune%20for%20access%20to%20Office%20365%20services%20(Exchange%20Online%20etc.)%20using%20conditional%20access%2C%20but%20we%20only%20want%20to%20do%20this%20for%20corporate%20devices.%20We%20want%20to%20allow%20BYOD%20users%20to%20continue%20to%20be%20able%20to%20use%20the%20apps%20without%20enrolment%20(MAM).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20have%20preloaded%20all%20known%20corporate%20identifiers%20into%20Intune.%20Is%20there%20any%20way%20to%20create%20a%20dynamic%20group%20that%20would%20include%20all%20these%20devices%20that%20we%20could%20then%20apply%20a%20separate%20conditional%20access%20policy%20too%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-164066%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Super Contributor

Hi All

 

We're about to go live with Microsoft Intune within our company, but I was wondering if there is a way to enforce device enrolment for users who have a company device?

 

I know that we can enforce enrolment into Intune for access to Office 365 services (Exchange Online etc.) using conditional access, but we only want to do this for corporate devices. We want to allow BYOD users to continue to be able to use the apps without enrolment (MAM).

 

We have preloaded all known corporate identifiers into Intune. Is there any way to create a dynamic group that would include all these devices that we could then apply a separate conditional access policy too?