Restrict Enrollment to a Group

%3CLINGO-SUB%20id%3D%22lingo-sub-1112234%22%20slang%3D%22en-US%22%3ERestrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1112234%22%20slang%3D%22en-US%22%3EHi%20All%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20there%20any%20way%20to%20restrict%20enrollment%20to%20a%20group%3F%3CBR%20%2F%3EInfo%20appreciated%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1112234%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1117166%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1117166%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eyou%20can%20restrict%20the%20MDM%20user%20scope%20to%20a%20AAD%20group%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20492px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F166059i3579A9A63A7410F2%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22AAD-MDM.png%22%20title%3D%22AAD-MDM.png%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20884px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F166060iF891BE1B983BCBD3%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22MDM-user-scope.png%22%20title%3D%22MDM-user-scope.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20way%20only%20users%20in%20that%20AAD%20groups%20can%20enroll%20into%20MDM%20(Intune).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1117327%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1117327%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20also%20restrict%20by%20creating%20new%20restriction%20policy%20under%20enrollment%20restrictions%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20661px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F166085i46363FA0D13F15F4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Capture.JPG%22%20title%3D%22Capture.JPG%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F166086i6A71DBACEFAA516C%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Capture2.JPG%22%20title%3D%22Capture2.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1117694%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1117694%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%2C%20that's%20the%20method%20I'm%20using.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20know%20what%20the%20UX%20is%20here%3F%20Especially%20if%20the%20device%20is%20an%20iOS%20DEP%20%2F%20Supervised%20one%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EClient%20is%20expecting%20the%20device%20to%20stay%20in%20Single%20App%20Mode%20if%20a%20user%20outwith%20the%20enrollment%20group%20tries%20to%20enroll.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EInfo%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1118277%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1118277%22%20slang%3D%22en-US%22%3EI%20would%20recommend%20use%20the%20policy%20without%20single%20app%20mode%2C%20as%20I%20didn%E2%80%99t%20have%20great%20experience%20with%20Single%20App%20mode.%3CBR%20%2F%3E%3CBR%20%2F%3EHaven%E2%80%99t%20test%20it%20but%20expect%20this%20what%20happens%20with%20Single%20app%20mode%3A%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20will%20boot%20the%20device%20to%20Portal%20app%2C%20you%20enter%20user%20and%20password%2C%20then%20you%20get%20message%20that%20you%20can%E2%80%99t%20enroll%20then%20you%20get%20stuck.%3CBR%20%2F%3E%3CBR%20%2F%3ECurious%20to%20know%20your%20experience%20with%20single%20app%20mode%2C%20thanks%20Stuart!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1118294%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1118294%22%20slang%3D%22en-US%22%3EHi%20Buddy%3CBR%20%2F%3E.Single%20App%20Mode%20is%20client%20requirement%20and%20MUST%20be%20used.%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20I'm%20looking%20for%20clarification%20on%20is%20the%20user%20experience%20on%20entering%20the%20WRONG%20credentials%20or%20credentials%20of%20a%20user%20outside%20of%20the%20assigned%20groups.%3CBR%20%2F%3E%3CBR%20%2F%3EStuart%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1118611%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Enrollment%20to%20a%20Group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1118611%22%20slang%3D%22en-US%22%3EI%20think%20the%20user%20will%20be%20stuck%20on%20the%20portal%20app%20and%20can%E2%80%99t%20navigate%20to%20anything%20else.%3CBR%20%2F%3E%3CBR%20%2F%3EMoe%3C%2FLINGO-BODY%3E
Regular Contributor
Hi All

Is there any way to restrict enrollment to a group?
Info appreciated
6 Replies

Hey @Stuart King,

 

you can restrict the MDM user scope to a AAD group:

 

AAD-MDM.pngMDM-user-scope.png

 

This way only users in that AAD groups can enroll into MDM (Intune).

 

best,

Oliver

@Stuart King 

 

You can also restrict by creating new restriction policy under enrollment restrictions: 

 

Capture.JPGCapture2.JPG

@Moe_Kinani 

 

Yes, that's the method I'm using.

 

Do you know what the UX is here? Especially if the device is an iOS DEP / Supervised one?

 

Client is expecting the device to stay in Single App Mode if a user outwith the enrollment group tries to enroll.

 

Info appreciated

I would recommend use the policy without single app mode, as I didn’t have great experience with Single App mode.

Haven’t test it but expect this what happens with Single app mode:

You will boot the device to Portal app, you enter user and password, then you get message that you can’t enroll then you get stuck.

Curious to know your experience with single app mode, thanks Stuart!
Hi Buddy
.Single App Mode is client requirement and MUST be used.

What I'm looking for clarification on is the user experience on entering the WRONG credentials or credentials of a user outside of the assigned groups.

Stuart
I think the user will be stuck on the portal app and can’t navigate to anything else.

Moe