Intune with Autopilot, Kiosk Mode and device only licenses

Copper Contributor

Hi team...I've been searching high and low for the answers to these questions, but I can't quite seem to find the right info for exactly what I want to do. I seem to be running into some licensing issues (needing Premium AAD for automatic MDM enrollment, but I'm not sure if that's the option I need to do to reach my goal anyway). 

 

I have a fleet of a few hundred windows tablets running Windows 10 arriving soon. These will be distributed to different business units, and I may have the need to deploy different apps to the different units, or have slightly varying configs, and I'm satisfied setting up different security groups look like the way to go here to logically separate them.

 

I would like to use device only Intune licenses because when these tablets are turned on, we want them auto logging in to no particular user, just booting up with maybe a browser and a couple of applications we need to publish on there. Seems simple enough.

 

When we turn the devices on for the first time to configure them I'd like for us to do the bare minimum. So basically choose locale, keyboard layout, join to WiFi, and then register the tablet for our organisation. Once the device is registered, we would manually place it into one of the security groups we've made. Once it's manually put into one of the security groups I'm hoping we can have an automated process which sets up the tablet with my settings, pops it into kiosk mode and adds our apps on there.  

 

Can anyone help me solve this problem? I seem to be running into licensing issues, but maybe I'm not doing it right, or I'm missing some key information? Or I actually can't do what I want to do with device only licenses?

 

 

3 Replies

Hi @DamoTechNZ! You can only use device licensing in a couple of scenarios. As you are using this for Windows devices, you're even limited to only one scenario: Autopilot Self-Deploying mode

 

Luckily, self-deploying mode does exactly what you are trying to achieve. After selecting language et cetera, and connecting to a network, it takes care of AAD joining, Intune enrollment et cetera. Please be aware that this is still in public preview!

 

As to how you're going to manage the differences between personas, I would suggest you take a look at dynamic groups based on Autopilot's group tags.

 

If you need any more help, please don't be afraid to ask. 

@NielsScheffers thanks for this! For someone new to Intune (I'm not new to Azure AD or M365), those documents sure aren't too helpful from M$.

 

I've managed to create my autopilot profile, Kiosk profile and have assigned it to my group, but I can't get my device to show up in Intune. It's in Azure AD as "unassigned". Reading between the lines I need to create a CSV to import it from Azure AD to Intune. Is that correct? How do I do that?

I think your looking to register your device(s) in Autopilot (with the hardware hash)? That, indeed, needs to be done first to 'link' your device(s) to your tenant. Without it, Windows has no way of knowing that it needs to get an Autopilot profile from your tenant.