I have revoked the enrollment restriction now and solved the problem with a scope tag for corporate and one for personal devices.
Registering a device as "Azure Ad registered" but block as a personal device in Intune
We wand to prevent a user with an Intune License from register his privat device to intune. So we created a "Enrollment restriction" for personal devices in intune.
Now, also no user can register devices to Azure AD as "Azure AD registered".
I do not understand it... is there a other, better way?
You can block user joining personal devices by setiing an enrollment restriction. However aftershave that users can only enroll AutoPilot devices.
Good read non-microsoft article https://www.anoopcnair.com/block-personal-windows-devices/#How_to_Block_Personal_Windows_Devices
Sign in to comment