Intune enrollment method capabilities for Windows devices
There are several methods to enroll your workforce's devices in Intune. Each method has different best practices and capabilities, as shown in the tables below.
Best practices by enrollment method
Best practices | Azure AD joined | Azure AD joined with Autopilot (User driven mode) | Azure AD joined with Autopilot (Self deploying mode) | Bulk | DEM | BYOD | GPO | Co-management |
---|---|---|---|---|---|---|---|---|
Commonly used in EDU | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Devices can be used as shared devices | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Personal devices must access company resources | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Self-servicing of apps | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Capabilities by enrollment method
Capabilities | Azure AD joined | Azure AD joined with Autopilot (User driven mode) | Azure AD joined with Autopilot (Self deploying mode) | Bulk | DEM | BYOD | GPO | Co-management |
---|---|---|---|---|---|---|---|---|
Conditional Access | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
User gets associated with the device | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Requires Azure AD Premium | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Device can assess resources protected by CA | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Users must not be admins on their devices | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Ability to configure the device setup experience | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Ability to enroll devices without user interaction | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Ability to run PowerShell scripts | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Supports automatic enrollment after AD domain join | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Supports automatic enrollment after Hybrid Azure AD join | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Supports automatic enrollment after Azure AD join | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
* Client apps workloads in Configuration Manager must be moved to Intune Pilot or Intune.
Next steps
Feedback
Submit and view feedback for