what is the difference between User Cred and Device cred in this GPO For MDM Auto Enrolment

Pandiyan S 0 Reputation points
2023-06-08T01:09:08.77+00:00

I am trying to configure Group Policy in AD to auto-enrolling (Hybrid Join) device to Intune.

Can someone explain to me what is the difference between User Cred and Device cred in this GPO? Which one should I use and why?

The current configuration is user credential and it is not working most of the time may be due to MFA.

Microsoft Security | Intune | Configuration
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2023-06-08T03:10:14.16+00:00

    @Pandiyan S, Thanks for posting in Q&A.

    In the context of Microsoft Intune enrollment, the "User Credential" setting in the Group Policy "Enable automatic MDM enrollment using default Azure AD credentials" refers to users logging in with their personal credentials to enroll their devices in Intune. On the other hand, the "Device Credential" setting, which is only available for Microsoft Intune enrollment in scenarios with Co-management or Azure Virtual Desktop multi-session host pools, refers to the use of the computer's machine account to enroll the device in Intune.

    For general scenario, user credential is used. From your description, I know we configure as user credential, but the enroll is failed. And it seems the MFA is required during the enrollment. Could you confirm if we configure for all cloud apps in Conditional Access policy to require MFA. We suggest exclude Intune Enrollment options from your MFA policy. meanwhile, choose one user and disable the MFA for the user to see if the GPO enrollment can work.

    However, if the issue still persists after we disable MFA, you can follow the steps in the following link to troubleshoot.

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-enrollment/troubleshoot-windows-auto-enrollment

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.