Intune enrollment with Windows devices

%3CLINGO-SUB%20id%3D%22lingo-sub-1206908%22%20slang%3D%22en-US%22%3EIntune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1206908%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20every%20windows%20devices%20connected%20to%20Azure%20AD%20as%20shown%20below.%20I%20have%20AAD%20group%20(has%20test%20users%20for%20Intune%20test)%20enrolled%20in%20Intune%20as%20shown%20below.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AZURE%20CONNECT.png%22%20style%3D%22width%3A%20321px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F174716iC8AE4AF44556FD5A%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22AZURE%20CONNECT.png%22%20alt%3D%22AZURE%20CONNECT.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20i%20login%20as%20user%20(user%20is%20in%20user%20group%20enrolled%20to%20intune)%2C%20it%20doesn't%20install%20company%20portal.%20In%20Intune%2C%20under%20all%20device%2C%20this%20device%20is%20not%20listed%20but%20listed%20in%20Asuzre%20AD%20Devices%20as%20joined%20type%20'%3CSPAN%3EAzure%20AD%20joined'.%20Apps%20for%20company%20portal.%20Company%20portal%20listed%20as%20'Show%20this%20as%20a%20featured%20app%20in%20the%20Company%20Portal'%20to%20YES..%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWhat%20else%20do%20i%20need%20to%20do%20make%20intune%20MDM%20devices%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1206908%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207284%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207284%22%20slang%3D%22en-US%22%3EHave%20you%20assigned%20the%20company%20portal%20as%20required%20to%20a%20specific%20user%2Fdevice%20group%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207295%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207295%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3Bthnks%20for%20your%20quick%20reply.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%2C%20i%20tried%20to%20assigned%20same%20group%20and%20to%20All%20users.%3C%2FP%3E%3CP%3EThe%20only%20way%20to%20register%20MDM%20device%20(which%20is%20already%20Joined%20AAD%20device)%20is%20to%20disconnect%20and%20rejoined.%3C%2FP%3E%3CP%3EI%20have%20over%205k%20computers%2C%20i%20just%20can't%20do%20manually%20to%20everyone%20(requires%20lots%20of%20manual%20works%2C%20plus%20user%20has%20go%20through%20MFA%20setup%20again).%20Plus%2C%20these%20windows%20devices%20are%20already%20AAD%20joined%20so%20i%20don't%20need%20to...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207349%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207349%22%20slang%3D%22en-US%22%3EDo%20you%20have%20a%20central%20Management%20in%20place%20like%20SCCM%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207350%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207350%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENo%20i%20wish....what%20are%20you%20thinking...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207356%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207356%22%20slang%3D%22en-US%22%3ESo%20the%20issue%20that%20automatic%20enrollment%20wasn't%20enabled%20when%20the%20computers%20AAD%20joined%20right%3F%3CBR%20%2F%3E%3CBR%20%2F%3ENow%20you%20have%20enabled%20it%20and%20want%20to%20enroll.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20thinking%20of%20deploying%20a%20provisioning%20package%20which%20might%20solve%20your%20issues.%20I%20am%20not%20100%25%20sure%20that%20would%20work%2C%20but%20as%20you%20don't%20have%20any%20way%20of%20mass%20deployment%20it%2C%20that's%20not%20an%20option.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20don't%20see%20any%20other%20way%20than%20re%20enrolling%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207376%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207376%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20might%20be%20right.%20But%20on%20my%20test%2C%20as%20soon%20as%20i%20disconnect%20and%20rejoined%2C%20it%20just%20works.%20What%20behavior%20changes%3F%20there%20got%20be%20something%3F%20Microsoft%20needs%20to%20invest%20some%20time%20here%20if%20they%20wants%20Intune%20to%20be%20management%20software%20for%20Cloud%20base%20company...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207397%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207397%22%20slang%3D%22en-US%22%3EThat's%20because%20the%20user%20is%20added%20to%20the%20group%20for%20automatic%20enrollment%20now%20and%20that%20wasn't%20before.%3CBR%20%2F%3EIt's%20the%20only%20explanation.%3CBR%20%2F%3E%3CBR%20%2F%3EAutomatic%20enrollment%20works%20really%20well%20and%20I%20haven't%20seen%20it%20malfunction%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207407%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207407%22%20slang%3D%22en-US%22%3EHave%20you%20seen%20this%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fmdm-enrollment-of-windows-devices%23connecting-to-mdm-using-a-deep-link%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fmdm-enrollment-of-windows-devices%23connecting-to-mdm-using-a-deep-link%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207412%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207412%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20thought%20once%20you%20are%20already%20AAD%20joined%20and%20later%20you%20turn%20automatic%20enrollment%20on%2C%20devices%20should%20be%20in%20MDM...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207420%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207420%22%20slang%3D%22en-US%22%3ENo%3CBR%20%2F%3E%3CBR%20%2F%3EThat's%20not%20how%20it%20works%3CBR%20%2F%3EIt%20only%20triggers%20it%20during%20AAD%20Join%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20you%20need%20to%20manually%20MDM%20enroll%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20can%20be%20done%20either%20through%20the%20deep%20links%20I%20posted%20above.%20Or%20through%20a%20registery%20edit%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fenroll-a-windows-10-device-automatically-using-group-policy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fenroll-a-windows-10-device-automatically-using-group-policy%3C%2FA%3E%3CBR%20%2F%3EYou%20should%20try%20creating%20a%20registery%20file%2C%20sending%20that%20to%20the%20users%2Fhelpdesk%20to%20execute%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207557%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207557%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ecorrect%20me%20if%20i%20am%20wrong%2C%20doesn't%20it%20requires%20user%20to%20be%20local%20admin%20rights%3F%20we%20don't%20give%20local%20admin%20for%20users%20due%20to%20our%20compliance%20and%20security%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207716%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20enrollment%20with%20Windows%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207716%22%20slang%3D%22en-US%22%3EJup%2C%20that's%20right%3CBR%20%2F%3ESo%20a%20manual%20action%20I%20required%3C%2FLINGO-BODY%3E
Contributor

We have every windows devices connected to Azure AD as shown below. I have AAD group (has test users for Intune test) enrolled in Intune as shown below.

AZURE CONNECT.png

 

When i login as user (user is in user group enrolled to intune), it doesn't install company portal. In Intune, under all device, this device is not listed but listed in Asuzre AD Devices as joined type 'Azure AD joined'. Apps for company portal. Company portal listed as 'Show this as a featured app in the Company Portal' to YES..

 

What else do i need to do make intune MDM devices?

12 Replies
Have you assigned the company portal as required to a specific user/device group?

@Thijs Lecomte thnks for your quick reply.

 

Yes, i tried to assigned same group and to All users.

The only way to register MDM device (which is already Joined AAD device) is to disconnect and rejoined.

I have over 5k computers, i just can't do manually to everyone (requires lots of manual works, plus user has go through MFA setup again). Plus, these windows devices are already AAD joined so i don't need to...

Do you have a central Management in place like SCCM?

@Thijs Lecomte 

 

No i wish....what are you thinking...

So the issue that automatic enrollment wasn't enabled when the computers AAD joined right?

Now you have enabled it and want to enroll.

I was thinking of deploying a provisioning package which might solve your issues. I am not 100% sure that would work, but as you don't have any way of mass deployment it, that's not an option.

I don't see any other way than re enrolling

@Thijs Lecomte 

You might be right. But on my test, as soon as i disconnect and rejoined, it just works. What behavior changes? there got be something? Microsoft needs to invest some time here if they wants Intune to be management software for Cloud base company...

That's because the user is added to the group for automatic enrollment now and that wasn't before.
It's the only explanation.

Automatic enrollment works really well and I haven't seen it malfunction

@Thijs Lecomte 

i thought once you are already AAD joined and later you turn automatic enrollment on, devices should be in MDM...

No

That's not how it works
It only triggers it during AAD Join

So you need to manually MDM enroll

This can be done either through the deep links I posted above. Or through a registery edit: https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatica...
You should try creating a registery file, sending that to the users/helpdesk to execute

@Thijs Lecomte 

 

correct me if i am wrong, doesn't it requires user to be local admin rights? we don't give local admin for users due to our compliance and security

Jup, that's right
So a manual action I required