join an already configured Windows 10 device

MIke 1 Reputation point
2022-08-11T16:19:03.583+00:00

I have users all over the world and need to get computers added to Azure AD with intune to manage the computers.

On the Set up a work or school account screen, select Join this device to Azure Active Directory.

only shows when login as a local admin account.

I don't want to users to Join with user type: Administrator

The users are not and should not be local Administrator.

How do i join computer to intune with mdm?

The computers are already OOBE so i can't use the

https://support.microsoft.com/en-us/account-billing/join-your-work-device-to-your-work-or-school-network-ef4d6adb-5095-4e51-829e-5457430f3973

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,267 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jason Sandys 31,176 Reputation points Microsoft Employee
    2022-08-11T19:04:52.213+00:00

    Users must be a local admin to join a domain (any kind of domain including AAD) and must also be local admins to enroll in MDM management. If this were not the case, anyone could take over your devices, i.e., it would be really, really, really ... really bad security wise.

    Are the devices currently joined to an on-prem AD domain? Are they currently managed in any way?