Will this scenario trigger the auto MDM enrollment?

SUIKA-5822 120 Reputation points
2025-05-08T14:56:43.61+00:00

Hello everyone!

In the page prompted when signing in the 365 apps like Onedrive with a work account ,

Will Selecting "Yes, all apps" and leaving "Allow my organization to manage this device" unchecked trigger the auto MDM enrollment? (The org has enabled the auto enrollment)

And what about the scenario the auto enrollment hasn't been enabled?

Thanks in advance!

Screenshot of the device registration with device management dialog.

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
3,184 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sakshi Devkante 3,985 Reputation points Microsoft External Staff Moderator
    2025-05-08T15:35:39.8566667+00:00

    Hello SUIKA-5822

    I wanted to share a quick clarification regarding the Microsoft 365 sign-in prompt and its impact on automatic MDM (Mobile Device Management) enrollment.

    • MDM Auto Enrollment Depends on Two Conditions:

    1.The organization has auto MDM enrollment enabled (via Microsoft Entra configuration).

    2.The user or system joins the device to Microsoft Entra ID or registers it and chooses to allow management.

    • What does “Yes, all apps” do?

    1.Registers the device with Entra ID.

    2.Enables SSO across Microsoft apps.

    3.Does NOT trigger MDM if the box “Allow my organization to manage this device” is unchecked.

    -What happens if “Allow my organization to manage this device” is checked?

    1.This triggers MDM auto-enrollment if the organization has it enabled (Intune, or other MDM provider set via Microsoft Entra).

    Now based on your concern You select “Yes, all apps” and You leave the checkbox "Allow my organization to manage this device" unchecked and also Your org has auto MDM enabled

    This gives the result the device will be registered in Entra ID, but will NOT be enrolled in MDM (like Intune). you get SSO benefits and access to enterprise apps, but your IT admin won’t be able to enforce MDM policies or remote controls.

    and if you look in another Scenario if Auto MDM Not Enabled - If your org has not enabled auto-enrollment, then even checking the box won't enroll the device — only Microsoft Entra ID registration happens.

    I hope this clarifies things.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.