AZURE - Mobility (MDM & MAM) - Device Enrollment Manager - Restrictions

Yop 81 Reputation points
2021-06-08T11:40:40.56+00:00

Hi everyone,

I would like to use just a DEM account to enroll the devices and prevent any user to perform the enrollment.

I have created a DEM account and set up into MEM.

In AAD should I:

  • In Intune, configure the MDM scope to "some", select a group where is my DEM account (leave Microsoft Intune Enrollment to "None")?

OR

  • In Intune, select the MDM scope to "All" + in Microsoft Intune Enrollment, select "Some" and select my group where there is my DEM account?

Thanks you in advance for your help,

Regards.

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
0 comments No comments
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,356 Reputation points
    2021-06-11T01:24:12.76+00:00

    @Yop Thanks for your explain.

    I have done the test in my lab. It seems we can use DEM account to enroll the device during OOBE. The following are the steps as a reference:
    1.Add a DEM account in intune portal.
    104551-image.png

    2.Use the DEM account to login the device.
    104552-image.png

    3.Check if the device is enrolled in intune. And I can see the device in intune portal.
    104532-image.png

    104533-image.png

    Based on the test, I think we can use the DEM account to enroll devices during OOBE.

    Hope it will help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,161 Reputation points Microsoft Employee
    2021-06-08T14:04:37.827+00:00

    Are these newly provisioned systems? If not, are you going to manually log into every system to do this?

    Are the systems currently joined to an on-prem AD (if already provisioned)?

    Also, using a DEM account has some restrictions and is not intended for single-user systems.


  2. Yop 81 Reputation points
    2021-07-29T11:55:52.8+00:00

    Dear @Jason Sandys , @Lu Dai-MSFT and @Nick Hogarth ,

    I would like to thank you for your help and apologize for my late reply.

    I have done the following:

    1. Setup a DEM account in MEM
    2. Setup in AAD, Mobility (MDM and MAM) and configure Microsoft Intune / MDM user scope to "Some" and target a group of which my DEM account is a member
    3. Create and Enrollment restristion to allow Windows (MDM) platform and deny "Personally owned" platform.

    So, the accounts the DEM group can auto enroll the machines in MEM during OOBE and no other user account can join/enroll a machine.

    Thanks again for your help,

    Kind regards

    0 comments No comments