question

andreasbright-4989 avatar image
1 Vote"
andreasbright-4989 asked LuDaiMSFT-0289 commented

AzureAD Joined assign MDM management

Hi,

We have existing machines registered in AzureAD as AzureAD joined, and we have MDM = None.
We have now enabled Intune, and configured MDM so new devices will automatically get MDM = Intune.

What is the recommended way to have the existing devices enrolled in Intune without doing a reset of the machine.
Do we have the users download the company portal from Microsoft Store and follow the steps ?

Thanks for reply

/Andy

mem-intune-generalmem-intune-enrollment
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Jason-MSFT avatar image
2 Votes"
Jason-MSFT answered

There is no direct method to do this automatically.

User initiated enrollment methods are listed at https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-methods#user-self-enrollment-in-intune.

Technically, you could also use a local group policy, but that's a catch-22 as there's no easy way to configure the local group policy if the systems aren't already managed.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
2 Votes"
LuDaiMSFT-0289 answered

@andreasbright-4989 Thanks for posting in our Q&A.

For this issue, "MDM = None" means these devices are not enrolled in intune. We suggest to try to enter Azure AD account in settings > accounts > Access work or school. Then check if the MDM = intune.
58477-image.png

For the company portal, I just can give some information. We can download the company portal from Microsoft store store free and sign in the app with work account. We can see the video in the following link as a reference.
https://docs.microsoft.com/en-us/mem/intune/user-help/enroll-windows-10-device

Hope it can help.


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



image.png (79.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

andreasbright-4989 avatar image
1 Vote"
andreasbright-4989 answered LuDaiMSFT-0289 commented

Hi,

Thanks for reply @Jason-MSFT @LuDaiMSFT-0289

One other thing then, the users have today license = Microsoft 365 Business Standard, and we will change this to Microsoft 365 Business Premium. And since we have configured Automatic Enrollment as you can see from the image, wouldn't this cause the machines to then automatically join Intune ?
58468-1.jpg



1.jpg (56.4 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@andreasbright-4989 It will not cause the devices that have joined in AAD to automatically join intune. Automatically join intune just works on when new devices join to AAD

Thanks for understanding and have a nice day.

1 Vote 1 ·
Jason-MSFT avatar image
2 Votes"
Jason-MSFT answered

wouldn't this cause the machines to then automatically join Intune ?

No. The auto enrollment flow is only triggered at the time a system joins AAD.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.