Nov 15 2022 02:10 AM
Hi,
I have a question about the enrollment method because something is unclear. Now I try to describe it.
In Intune, I created a new profile under Windows Enrollment > Windows Autopilot Deployment Program > Windows Autopilot deployment profiles > Under Assignments a group where my user is in it.
Now I reset a VM and log in with the account. The device comes after Azure AD and Intune.
However, I notice that the setting regarding "User account type: Standard" has not been adopted and my user is admin.
Is the device joined to Azure via the "normal" enrollment and brought to Intune?
Do I have to register the device in Intune to have the OOBE experience?
What is my goal:
Bring devices that are not synchronized from on-prem to Azure AD without the user admins being on the devices
Nov 15 2022 06:40 AM - edited Nov 15 2022 06:42 AM
Hi... are you 10000% sure the device went through the autopilot enrollment? seeying the esp is something else than the autopilot enrollment (even when its a part of it) 99,9% of the time when a device ends up with being a local admin or the old device name, the device didn't went through the autopilot enrollment
Besides the autopilot standard user setting you could also deploy some additional configuration to make sure the user isnt becoming a local admin
Manage your local administrator with Intune / MDM (call4cloud.nl)
Nov 15 2022 10:14 PM
Nov 15 2022 10:51 PM
Nov 15 2022 11:00 PM
Nov 15 2022 11:02 PM