Restrict Enrollment

Moonlight 176 Reputation points
2021-09-30T18:47:35.73+00:00

Hello

I have Azure AD with all machines enrolled as Azure registered , i already convert most of machines to Azure hybrid AD join but i want to restrict the enrollment for only computer object which has synced from my active directory and avoid any user's personal computers to shown in my azure ad portal.

what is the impact if we have 3 users license with E5 and each user can login for multiple device in my network , is it consume license?

also i notice some users has multiple devices assigned under 1 user , how can restrict one device ( windows 10 ) per user only?

Thanks

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,376 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,595 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,151 Reputation points MVP
    2021-09-30T20:36:43.463+00:00

    Are the devices enrolled in Intune? If yes, then you can restrict the number of devices a user can enroll. You can also restrict personal devices getting enrolled.


  2. Jason Sandys 31,166 Reputation points Microsoft Employee
    2021-09-30T21:06:12.807+00:00

    Are you wanting to restrict Intune enrollment or hybrid/full AAD join? They are two different things.


  3. Mr Sbaa 356 Reputation points
    2021-10-03T00:43:35.283+00:00

    You can not disable Azure AD device registration. This is enabled by default when using Microsoft365 services. You can however, limit the amount of devices the user can register in Azure AD. Keep in mind that Azure AD registration has nothing to do with ANY enrollment and also has ZERO impact to licenses. It sounds like you and your customer are misunderstanding this concept.

    If you want to limit Azure AD registrations and more explanation, take a look here:

    https://learn.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal

    0 comments No comments