question

Andreas-9700 avatar image
0 Votes"
Andreas-9700 asked AndyLiu-MSFT answered

Auto Enrollment Intune devices already azure AD joined

Hi,

We have many machines joined to Azure AD, and we would now like to have these joined to Intune
How would we solve this without having to reset the machines ?

I tried to enable Azure AD > Mobility and hoped that would be enough, but guess not ?

20117-1.jpg


20196-2.jpg


mem-intune-enrollment
1.jpg (73.2 KiB)
2.jpg (42.4 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndyLiu-MSFT avatar image
1 Vote"
AndyLiu-MSFT answered

You don't need to reset the device. If the device has already been joined in Azure AD, you can sign in to the Windows with the user account with local administrator permissions. Then, you can perform the enrollment just as @NickHogarth-MVP suggested.

You can open the Settings app, and go to Accounts > Access work or school, then click Enroll only in device management. Plus, if there is no Enroll only in device management option, you can click Connect, and add the Azure AD account again.

20302-most-used.png

20326-3.png



most-used.png (61.3 KiB)
3.png (41.5 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

NickHogarth-MVP avatar image
0 Votes"
NickHogarth-MVP answered

Those settings are only for when Azure AD join is performed. There is no easy way to do this unfortunately.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Andreas-9700 avatar image
0 Votes"
Andreas-9700 answered

Hi,

Thanks for reply.
So as I understand this, the users have 2 choices ?

  1. Do a reset

  2. Create a local admin account, disconnect Azure AD and then do a rejoin


Correct ?


Second question, what exactly does does the settings in the image above do ?

/Regards
Andreas



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

NickHogarth-MVP avatar image
1 Vote"
NickHogarth-MVP answered tjgruber commented

Those settings above are for Auto enrollment into Intune. So when you join Azure AD (at the OOBE or Autopilot) it will enroll into Intune, also used for other enrollments like using a GPO for Intune enrollment, or Co-management with ConfigMgr etc.

Have you had a user go to Settings > Accounts > Access work or school > Enroll only in device management? (they will need admin rights for this)

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.