Share via

Allow my organization to manage my device

Virtual Tech 106 Reputation points
Apr 1, 2022, 8:13 PM

Hi Forum

I've been searching in different fodums and seem to find a different answer on to what is the prompt "Allow my organization to manage my device" in windows 10. From my understanding is to manage the devices and deploy applications/policies. We use other methods like sccm to deploy apps and policies via GPO.

Is there any harm in blocking this prompt?
Just curious does your organization allow this prompt?

I applied the registry below and so far all my office outlook 2016,excel, word are working fine.
HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
DWORD: BlockAADWorkplaceJoin
Value: 1

Link allow-my-organization-to-manage-my-device-what-it-means

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,781 Reputation points MVP
    Apr 1, 2022, 10:28 PM

    There prompt allows the device to get enrolled into Intune which Microsoft cloud service for device management. There is no harm in blocking the prompt. However, if you are managing devices using SCCM then consider enrolling your devices in Co-management.

    1 person found this answer helpful.

  2. Virtual Tech 106 Reputation points
    Apr 11, 2022, 8:09 PM

    @Anonymous - Your right, there is probably a lot of value in ConfigMGR that I haven't discovered. I already have the users & computers syncing with AAD connect. Maybe in the future there will be an opportunity to registry the devices as Azure AD joined. That's got to be an easier way, then a prompt. Perhaps thru AAD connect to Group Policy Management. Why do you say it doesn't stop them from registering? If I turn off 'users may join devices to Azure AD'.

    0 comments No comments

  3. Rahul Jindal [MVP] 10,781 Reputation points MVP
    Apr 11, 2022, 8:56 PM

    Because it doesn't. To stop them from registering, you need to select the 2nd option 'Users may register their devices with Azure AD' to None. However, this will be greyed out if you have enrollment with Microsoft Intune or mobile device management for Microsoft 365 configured.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.