@guiot quentin, Thanks for posting in Q&A. From your description, I notice you want the device to be AAD joined and enroll into Intune. And don't want to wipe these devices.
For this situation, you can consider to automatic enrollment via the following steps:
- Enable Automatic enrollment and set MDM user scope as all.
- Assign the users with both Azure AD Premium license and Microsoft Intune license.
- On device side, go to Settings->Accounts-> Access work or school, Connect with Azure AD user account to join to Azure AD and automatically enroll into Intune.
For this enrollment method, the user will be a local admin on the device. If you want to change it, you can configure Account protection policy to change it.
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy
For new devices, you can consider Autopilot enrollment which can define the user as a standard user. Here is a link with more details:
https://learn.microsoft.com/en-us/mem/autopilot/profiles
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.