Intune Enrollment for Remote Users - No VPN - No Local Admin

%3CLINGO-SUB%20id%3D%22lingo-sub-2390046%22%20slang%3D%22en-US%22%3EIntune%20Enrollment%20for%20Remote%20Users%20-%20No%20VPN%20-%20No%20Local%20Admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2390046%22%20slang%3D%22en-US%22%3E%3CP%3ETrying%20to%20find%20a%20way%20to%20get%20devices%20enrolled%20with%20Endpoint%20Manager%20without%20the%20need%20for%20local%20admin%20or%20VPN.%20Does%20anyone%20have%20suggestions%20on%20how%20to%20get%20devices%20enrolled%20during%20this%20time%20of%20remote%20work%3F%20everything%20i%20have%20checked%20on%20either%20requires%20connection%20to%20the%20local%20network%20or%20local%20admin.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHelp%20is%20greatly%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20i%20have%20done%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Setup%20AutoPilot%20profile%3C%2FP%3E%3CP%3E-%20Imported%20test%20device%3C%2FP%3E%3CP%3E-%20Connected%20work%20account%20through%20Store%20App%3C%2FP%3E%3CP%3E-%20Installed%20Company%20Portal%3C%2FP%3E%3CP%3E-%20Attempted%20enrollment%20(fail%2C%20no%20local%20admin)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tested%20this%20yesterday%20and%20it%20seemed%20to%20work%20by%20adding%20the%20autopilot%20profile%20but%20today%20i%20cant%20get%20it%20to%20work%20at%20all.%26nbsp%3B%20Do%20any%20of%20you%20have%20suggestions%20on%20how%20to%20handle%20enrollment%20of%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnsure%20if%20autopilot%20profile%20assignment%20will%20force%20devices%20to%20enroll%20or%20not.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tested%20the%20above%20yesterday%20and%20it%20seemed%20to%20work%20but%20today%20when%20i%20tried%20to%20reverse%20engineer%20what%20i%20did%2C%20nothing%20seems%20to%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2390046%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2390133%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20Enrollment%20for%20Remote%20Users%20-%20No%20VPN%20-%20No%20Local%20Admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2390133%22%20slang%3D%22en-US%22%3EHi%3CBR%20%2F%3E%3CBR%20%2F%3ECould%20you%20explain%20it%20a%20little%20bit%20better%3F%3CBR%20%2F%3EAre%20the%20devices%20already%20azure%20ad%20joined%20or%20domain%20joined%20or%20standonline%20devices.%20Can't%20tell%20for%20sure%20when%20I%20am%20reading%20your%20question.%3CBR%20%2F%3EDo%20you%20only%20want%20the%20devices%20to%20azure%20ad%20joined%20and%20enrolled%20into%20intune%3F%20Or%20only%20registered%20and%20enrolled%20into%20intune%3F%3CBR%20%2F%3E%3CBR%20%2F%3EAutopilot%20is%20only%20used%2Ftriggered%20when%20you%20reset%2Fwipe%20a%20device%20before%20the%20oobe%20screen%3CBR%20%2F%3E%3CBR%20%2F%3ELocal%20admin%20permissions%20are%20needed%20when%20you%20manually%20want%20to%20enroll%20your%20device%20into%20intune%20by%20usng%20the%20company%20app%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Ftroubleshoot%2Fmem%2Fintune%2Fno-permission-to-enroll-windows-devices%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Ftroubleshoot%2Fmem%2Fintune%2Fno-permission-to-enroll-windows-devices%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%20use%20this%20option%20as%20it%20uses%20the%20local%20system%20account%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fuser-help%2Fuser-help-join-device-on-network%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fuser-help%2Fuser-help-join-device-on-network%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2390136%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20Enrollment%20for%20Remote%20Users%20-%20No%20VPN%20-%20No%20Local%20Admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2390136%22%20slang%3D%22en-US%22%3EDevices%20are%20remote%20domain%20joined%20devices.%20they%20do%20not%20have%20VPN%20are%20not%20in%20the%20office%20and%20are%20not%20AAD%20Joined.%20Hybrid%20Join%20is%20something%20we%20are%20rolling%20out%20but%20again%20that%20requires%20direct%20LoS%20of%20the%20Domain%20Controllers%20for%20the%20SCP.%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20i%20need%20is%20a%20way%20to%20get%20the%20devices%20that%20are%20remote%20and%20not%20connected%20to%20the%20network%20enrolled%20in%20Intune.%20This%20is%20to%20be%20able%20to%20push%20out%20the%20SCCM%20client%20to%20them%20with%20the%20CMG%20configuration.%20I%20know%20there%20are%20ways%20to%20get%20the%20SCCM%20Agent%20installed%20(primarily%20by%20directly%20contacting%20the%20users%20or%20by%20having%20the%20devices%20on%20the%20network).%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20issue%20we%20have%20is%20that%20the%20devices%20will%20not%20have%20VPN%20and%20will%20not%20have%20local%20admin%20access.%20I%20am%20trying%20to%20find%20options%20to%20get%20them%20enrolled%20without%20the%20VPN%20or%20Local%20admin.%3C%2FLINGO-BODY%3E
Occasional Contributor

Trying to find a way to get devices enrolled with Endpoint Manager without the need for local admin or VPN. Does anyone have suggestions on how to get devices enrolled during this time of remote work? everything i have checked on either requires connection to the local network or local admin.

 

Help is greatly appreciated.

 

What i have done:

 

- Setup AutoPilot profile

- Imported test device

- Connected work account through Store App

- Installed Company Portal

- Attempted enrollment (fail, no local admin)

 

I tested this yesterday and it seemed to work by adding the autopilot profile but today i cant get it to work at all.  Do any of you have suggestions on how to handle enrollment of 

 

Unsure if autopilot profile assignment will force devices to enroll or not.

 

I tested the above yesterday and it seemed to work but today when i tried to reverse engineer what i did, nothing seems to work.

 

Thanks

8 Replies
Hi

Could you explain it a little bit better?
Are the devices already azure ad joined or domain joined or standonline devices. Can't tell for sure when I am reading your question.
Do you only want the devices to azure ad joined and enrolled into intune? Or only registered and enrolled into intune?

Autopilot is only used/triggered when you reset/wipe a device before the oobe screen

Local admin permissions are needed when you manually want to enroll your device into intune by usng the company app

https://docs.microsoft.com/en-us/troubleshoot/mem/intune/no-permission-to-enroll-windows-devices

You can use this option as it uses the local system account:

https://docs.microsoft.com/en-us/azure/active-directory/user-help/user-help-join-device-on-network


Devices are remote domain joined devices. they do not have VPN are not in the office and are not AAD Joined. Hybrid Join is something we are rolling out but again that requires direct LoS of the Domain Controllers for the SCP.

What i need is a way to get the devices that are remote and not connected to the network enrolled in Intune. This is to be able to push out the SCCM client to them with the CMG configuration. I know there are ways to get the SCCM Agent installed (primarily by directly contacting the users or by having the devices on the network).

The issue we have is that the devices will not have VPN and will not have local admin access. I am trying to find options to get them enrolled without the VPN or Local admin.

Hi,

-IS there any important data on the devices. IS it okay to reset/wipe the devices

 

-You are telling you want to enroll the devices into Intune and not in azure ad? You are also talking about Autopilot

 

So  if you only want to enroll them into Intune 

https://www.ntweekly.com/2018/12/14/enroll-windows-10-devices-to-intune-without-azure-ad/


-Do the devices have a local admin account that can be used?

 

 

 

@Rudy_Ooms 

 

I appreciate your reply but as i noted the users do not have local admin.  I noted this many times and what i am looking for is a solution that will allow for enrollment of the device without wiping and with minimal impact to the users.  

Hi,
Of course, i have read the users do not have local admin permissions :) , but I didn't read there were no local admin users at all. Do you want them to enrol in Intune only or do you want them also to join Azure Ad and Intune
Chatted with one of my buddies that works at MS and he confirmed that Local admin is required to manually enroll a device with Endpoint Manager. thanks for the replies
HI,

Now you know why I was a little bit hammering on the question about local admins :) .. Nice to hear you have the final answer now
oh i get it, i was basically trying to see if anyone in the community had found a way around this requirement. its really a pain with Covid and all the people that are working remote. Appreciate the replies though.