Are the devices enrolled in Intune? If yes, then you can restrict the number of devices a user can enroll. You can also restrict personal devices getting enrolled.
Restrict Enrollment
Hello
I have Azure AD with all machines enrolled as Azure registered , i already convert most of machines to Azure hybrid AD join but i want to restrict the enrollment for only computer object which has synced from my active directory and avoid any user's personal computers to shown in my azure ad portal.
what is the impact if we have 3 users license with E5 and each user can login for multiple device in my network , is it consume license?
also i notice some users has multiple devices assigned under 1 user , how can restrict one device ( windows 10 ) per user only?
Thanks
3 answers
Sort by: Most helpful
-
-
Jason Sandys 31,311 Reputation points Microsoft Employee
2021-09-30T21:06:12.807+00:00 Are you wanting to restrict Intune enrollment or hybrid/full AAD join? They are two different things.
-
Mr Sb 366 Reputation points
2021-10-03T00:43:35.283+00:00 You can not disable Azure AD device registration. This is enabled by default when using Microsoft365 services. You can however, limit the amount of devices the user can register in Azure AD. Keep in mind that Azure AD registration has nothing to do with ANY enrollment and also has ZERO impact to licenses. It sounds like you and your customer are misunderstanding this concept.
If you want to limit Azure AD registrations and more explanation, take a look here:
https://learn.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal