Catch 22 with unenrolled devices with conditional access

Chris Templeton 1 Reputation point
2021-02-12T12:48:13.79+00:00

we have a mixture of corporate and BYOD windows devices in our environment. Initially we didn't have any kind of "WIP" policy in place so that any BYOD device wouldn't have been stopped from being able to take data away etc. so we have created an "unenrolled" CA which picks up if a device is enrolled or not and if not access is denied unless they do the whole add work account element.

The problem now is that the corporate windows devices won't finish the autopilot setup because the Unenrolled CA policy stops it from continuing - Essentially a catch-22 as I need it to enroll [in AAD/Intune] to become a corporate device!

I surely can't be the first person to come across this issue and wondered what I can do ?

Windows Autopilot
Windows Autopilot
A collection of Microsoft technologies used to set up and pre-configure new devices and to reset, repurpose, and recover devices.
411 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,258 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,672 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pa_D 1,071 Reputation points
    2021-02-12T18:38:47.807+00:00

    I came across this scenario. You have to take a different approach to this,

    Instead of using CA to blatantly block unmanaged device, do this.

    1) Devices > Enrollment Restrictions > Device Type Restrictions > Properties > for Windows block personally owned
    2) Now you have already exported hardware hash for Windows. Because this Intune treats all your Autopilot devices as "Corporate"

    2 people found this answer helpful.
    0 comments No comments