Hi,
Thank you for posting in Microsoft Q&A forum.
CMG is a Configuration Manager feature for device connectivity. You should use a CMG if you have Configuration Manager clients on the internet, if they're co-managed or not. A co-managed client in an environment with no CMG would have to rely on VPN connectivity when it roams outside of the on-premises network.
The scenario to provision Azure AD-joined co-managed devices does require a CMG. It allows an interned-based device to install the Configuration Manager client after the Autopilot process.
For more information, please refer to:
Frequently asked questions about co-management
Thanks for your time. Have a nice day!
Best regards,
Simon
If the response is helpful, please click "Accept Answer" and upvote it. Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.