MDM vs MAM Windows Auto Enrollment
Greetings -
I have a question on the setting of Windows Automatic Enrollment in Intune. First, understanding that Windows Autopilot REQUIRES that the MDM auto-enroll be set as enabled but should it be "SOME" or "ALL"? Any reason we wouldn't allow "ALL" here for corporate owned Windows PC's? Second, I have seen documentation where the MAM setting is set to "NONE". We do not want any personal/BYOD Windows devices in Intune. However, that is also BLOCKED by the Enrollment Device Platform Restrictions set to "BLOCK" personal devices. I have also read MSFT documentation on WIP and/or App Protection Policies, which seem to indicate that the setting for MAM should be enabled - set to Some or All. In addition, MSFT states that by default, Windows auto-enrollment using MDM would take preference if both settings are targeting the same users. Thanks MSFT - it's as clear as mud in your documentation. Can someone clarify? Again - we do not want personal Windows devices enrolling, and no BYOD MAM scenario for Windows PC's. We DO want to enable App Protection Policies however, so what is the recommended setting for MAM then? Thanks!