Tech Accelerator: Microsoft Intune Suite
Apr 11 2023 08:00 AM - Apr 12 2023 11:00 AM (PDT)

Prevent Azure AD & Intune Enrollment


Is there a way to prevent a user from connecting a personal/home PC to Azure AD and, more importantly, to prevent them from enrolling in Intune? We have a growing number of personal systems that show as Azure AD devices and a significant number of those are Intune enrolled.




3 Replies
best response confirmed by DGMalcolm (Contributor)

Hi @DGMalcolm ,


yes it is possible.


To block Intune enrollment you have the option to set  enrollment restrictions


For azure ad you have to option users may join azure ad. And you can allow azure ad join for some users, all users or block (none)


kind regards,



setting up server side prevention by configuring the enrollment restrictions is indeed the way to go
As configuring a registry key for each device (or using a gpo) client side isn't the best method
Thank you for this, it's given me a good start.