Registering devices with Intune for management and policy enforcement
The MDM user scope setting and the Save button are controlled by the Intune/MDM authority configuration and licensing. When the Save button is greyed out even though Global admin permissions are present, the usual causes are:
- Intune/MDM authority not fully configured for the tenant.
- Automatic MDM enrollment already controlled from the Microsoft Entra “Mobility (MDM and MAM)” blade instead of (or in addition to) the Intune admin center.
- Enrollment restrictions or discovery URL configuration issues blocking changes.
Use the following checks and configuration path to resolve it.
- Verify MDM authority and Mobility (MDM and MAM) configuration
In the Azure portal:
- Go to Microsoft Entra ID → Mobility (MDM and MAM) → Microsoft Intune.
- On the Configure page, set MDM user scope to Some or All, then Save.
- Under Mobility (MDM and MAM), also select Microsoft Intune Enrollment and repeat step 2.
This ensures the tenant’s MDM authority and automatic enrollment are correctly configured for Intune and that the MDM user scope is actually set to All or Some at the directory level.
- Confirm automatic enrollment configuration in Intune
In the Intune admin center:
- Go to Devices → Enroll devices (or Windows Enrollment depending on portal layout) → Automatic Enrollment.
- Ensure MDM user scope is set to Some or All and MAM user scope is set appropriately (typically None when managing the device itself).
From the documentation:
- When MDM user scope is Some or All, devices that are joined to Microsoft Entra ID are managed by Intune.
- When MDM user scope is None, devices are not joined to Microsoft Entra ID and are not managed by Intune.
- Check for enrollment restrictions or discovery URL issues
If Cloud PCs or other Windows devices show messages like “ask your administrator to update policy settings” or “remove restrictions preventing Intune from allowing Windows enrollment,” then:
- Review any enrollment restrictions configured in Intune that might prevent Windows enrollment.
- Confirm that the MDM discovery URL is set to the default for Intune as described in the Windows 365 troubleshooting guidance.
- Licensing considerations
Automatic MDM enrollment is a premium Microsoft Entra feature. If automatic enrollment settings are not available or not editable, ensure that:
- The tenant has the required Microsoft Entra ID Premium capability (often surfaced as a prompt to start a trial when opening the Automatic Enrollment page).
- The user accounts that will enroll devices have an Intune license assigned so that user-based policies can be applied.
Once MDM user scope is successfully set to All or Some and saved in the Mobility (MDM and MAM) configuration and in Intune’s Automatic Enrollment blade, OOBE/Autopilot enrollment should proceed past the first stage, and the pre-provisioning (white glove) flow should no longer fail due to automatic enrollment configuration.
References: