Share via

Intune Issues and Confusion

Greg D 0 Reputation points
2026-04-30T06:18:09.56+00:00

Hi,

We use Intune for OOBE deployment which is working fine however i have an issue understanding Intune licenses etc.

Firstly, when we do the Intune Deployment, we do so as a single user, say ******@company.com. This account has a Business Premium licence so Intune is included. The user is say for example, DEF456 and has just a Business Standard licence.

When we issue out the PC, eventually it becomes non compliant so we need to do a forced re-enrollment via Powershell however i'd like to ask if you can issue an Intune licence to the user after the deployment?

We roll out new ready to go PC's from the IT Department and then ship to the staff within the company whom can use them right away.

So what i am trying to ask is, how can one change the Intune licence to that of the user after deployment which was done by a different user?

Any deployment tips using Intune with Autopilot for OOBE when you cannot use the end users credentials would be much appreciated.

Cheers.

Microsoft Security | Intune | Enrollment

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-04-30T06:18:31.8066667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Intune licenses are always assigned to users, not to individual enrollments. The account that signs in during OOBE must have an appropriate Intune-eligible license if the device is to be managed by Intune under that user.

    Key points from the scenario:

    1. The deployment account (for example, an IT “staging” account with Business Premium) is used during OOBE/Autopilot.
    2. The eventual primary user (for example, DEF456 with Business Standard only) receives the device later.
    3. The device becomes non‑compliant and a forced re‑enrollment is used.
    4. The goal is to have the device ultimately managed under the end user’s Intune license, not the staging account.

    Behavior and licensing requirements:

    • Users who are assigned a Cloud PC or Intune-managed device must have an Intune license assigned to them to receive user policies and be properly managed. If the user does not have the correct license, enrollment and policy application can fail with errors such as “Your IT admin hasn’t given you access to use this app” or similar licensing messages.
    • If a user signs in and attempts to enroll or use Intune without the correct license, the device can’t be properly enrolled or managed until the correct license is assigned.
    • The MDM authority must be correctly set to Intune; otherwise, enrollment and features such as Enrollment Status Page (ESP) will not function correctly.

    How to assign or change Intune licenses after deployment:

    Licenses can be assigned or changed at any time; they are not permanently tied to the initial enrollment user.

    To assign an Intune license to the eventual user (for example, DEF456):

    1. In the Microsoft Intune admin center, go to Users > All Users.
    2. Select the target user (for example, DEF456).
    3. On the user Profile page, select Licenses.
    4. Select Assignments.
    5. Find Intune (or a plan that includes Intune), select the checkbox, and select Save.

    After this, the user account has permissions to use the service and enroll devices. If the device was previously enrolled under a staging account, the typical pattern is:

    • Wipe or reset the device (or perform a forced re‑enrollment as used today).
    • Re-enroll the device so that it is joined and enrolled under the correct user identity that already has the Intune license assigned.

    This ensures that compliance policies, configuration profiles, and app assignments that are scoped to the end user are applied correctly.

    Deployment tips when end-user credentials cannot be used at OOBE:

    1. Use Windows Autopilot user-driven mode with a dedicated deployment profile:
      • Configure a Windows Autopilot deployment profile in Intune with Deployment mode set to User-driven, Join to Microsoft Entra ID as set to Microsoft Entra joined, and User account type set to Standard.
      • Assign this profile to the device group so that when the device is reset and goes through OOBE, it is ready for user sign-in and enrollment.
    2. Use an Enrollment Status Page (ESP):
      • Create and assign an ESP so that during OOBE, the device remains on the provisioning screen until all required apps and profiles are installed.
      • Configure the ESP to block device use until apps and profiles are installed, and optionally allow reset if installation errors occur.
    3. BYOD or personal device scenarios (if applicable):
      • For personal devices, users can use Settings > Accounts > Access work or school > Connect, then choose Join this device to Azure Active Directory to join the device to Microsoft Entra ID and trigger automatic enrollment into Intune, provided an automatic MDM enrollment policy is configured and the user has an Intune license.
    4. Ensure MDM authority and enrollment configuration are correct:
      • Confirm that the MDM authority is set to Intune. If the tenant is still using the legacy Office 365 MDM authority, features like ESP are not available until the authority is switched to Intune.
      • Verify that automatic MDM enrollment is configured correctly and that the MDM discovery URL is set to the Intune default.

    In practice, for a “ready-to-go” PC model where end-user credentials are not used at OOBE, the recommended pattern is:

    1. Pre-register devices in Windows Autopilot and assign them a user-driven Autopilot profile.
    2. Ship the device to the user.
    3. Ensure the user has the correct Intune license before first sign-in.
    4. The user signs in during OOBE with their own account; the device joins Microsoft Entra ID and enrolls into Intune under that user.

    If a staging account must be used initially, plan to:

    • Assign the Intune license to the final user.
    • Wipe/reset the device and re-run OOBE so the final user signs in and becomes the primary user for Intune management.

    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.