Ensure Intune windows users are unable to register or join personal devices to Azure AD

Kuku, Kenny 0 Reputation points
2024-06-05T12:43:32.8133333+00:00

I need to ensure that Intune windows users are unable to register their devices or join their devices to Azure AD other than via windows autopilot. How do I set that up. This should not hamper their mobile devices like iPad and iPhone and Macs

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,143 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 35,621 Reputation points Microsoft Employee
    2024-06-07T00:32:48.0466667+00:00

    @Kuku, Kenny ,

    In order for users to get through autopilot in a user-driven autopilot scenario using their own credentials, they need to be added to "Users may join devices to Azure AD". So you could add device enrollment restrictions within Intune to only import devices into autopilot if they meet your criteria.

    Alternatively you could only allow selected users/groups to Join Devices to Azure under "Device settings" and then add Autopilot users to that group.

    If you would like to leave product feedback to extend these options to fit your scenario, you can do so in the feedback forum. https://feedback.azure.com/

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar quesitons.

    0 comments No comments