設定註冊限制Set enrollment restrictions

身為 Intune 系統管理員,您可以建立和管理註冊限制,定義可以註冊使用 Intune 管理的裝置數目和類型。As an Intune administrator, you can create and manage enrollment restrictions that define the number and types of devices that can enroll into management with Intune. 您可以建立多項限制,並將它們套用至不同的使用者群組。You can create multiple restrictions and apply them to different user groups. 您可以設定不同限制的優先順序You can set the priority order for your different restrictions.

注意

註冊限制不是安全性功能。Enrollment restrictions are not security features. 遭盜用的裝置可以冒用身分。Compromised devices can misrepresent their character. 這些限制是非惡意使用者的最佳屏障。These restrictions are a best-effort barrier for non-malicious users.

注意

正陸續針對所有 Intune 客戶推出本文所述的群組指派註冊限制和優先權功能。The group-assigned enrollment restrictions and priority functionality mentioned in this article are in the process of being rolled out across the Intune customer base. 完成推出前,您可能無法存取群組,也沒有優先順序功能。Until this rollout is complete, you might not have access to the group and priority features.

您可以建立的特定註冊限制包括:The specific enrollment restrictions that you can create include:

  • 已註冊裝置的數目上限。Maximum number of enrolled devices.
  • 可以註冊的裝置平台:Device platforms that can enroll:
    • Android。Android.
    • Android 工作設定檔。Android work profile.
    • iOS。iOS.
    • macOS。macOS.
    • Windows.
  • iOS、Android、Android 工作設定檔和 Windows 的平台作業系統版本。Platform operating system version for iOS, Android, Android work profile, and Windows. (只能使用 Windows 10 版本。(Only Windows 10 versions can be used. 如果允許 Windows 8.1,請保留空白。)Leave this blank if Windows 8.1 is allowed.)
    • 最低版本。Minimum version.
    • 最高版本。Maximum version.
  • 限制個人擁有的裝置 (僅限 iOS、Android、Android 工作設定檔、macOS)。Restrict personally owned devices (iOS, Android, Android work profile, macOS only).

預設限制Default restrictions

裝置類型和裝置限制註冊限制都會自動提供預設限制。Default restrictions are automatically provided for both device type and device limit enrollment restrictions. 您可以變更預設選項。You can change the options for the defaults. 預設限制適用於所有使用者和無使用者註冊。Default restrictions apply to all user and userless enrollments. 您可以使用較高的優先順序建立新的限制,覆寫這些預設值。You can override these defaults by creating new restrictions with higher priorities.

建立限制Create a restriction

  1. 登入 Azure 入口網站。Sign in to the Azure portal.
  2. 選取 [更多服務] 並搜尋 Intune,然後選擇 [Intune]。Select More Services, search for Intune, and then choose Intune.
  3. 選取 [裝置註冊] > [註冊限制]。Select Device enrollment > Enrollment restrictions.
  4. 選取 [建立限制]。Select Create restriction.
  5. 提供限制的名稱和描述。Give the restriction a name and description.
  6. 選擇 [限制類型],然後選取 [建立]。Choose a Restriction type, and then select Create.
  7. 針對裝置限定限制,請選取 [裝置限制] 設定使用者能夠註冊的裝置數上限。For device limit restrictions, select Device limit to set the maximum number of devices that a user can enroll.
  8. 針對裝置類型限制,請選取 [平台] 和 [平台設定] 允許或封鎖各種平台和版本。For device type restrictions, select Platforms and Platform configurations to allow or block various platforms and versions.
  9. 選取 [指派] > [+ 選取群組]。Select Assignments > + Select groups.
  10. 在 [選取群組] 下,選取一或多個群組,然後選擇 [選取]。Under Select groups, select one or more groups, and then choose Select. 限制只適用於指派的群組。The restriction applies only to groups to which it's assigned. 如果限制不指派給至少一個群組,就不會產生任何效果。If you don't assign a restriction to at least one group, it won't have any effect.
  11. 選取 [儲存]。Select Save.
  12. 新建立的限制優先順序剛好在預設值前。The new restriction is created with a priority just above the default. 您可以變更優先順序You can change the priority.

設定裝置類型限制Set device type restrictions

您可以遵循下列步驟變更裝置類型限制的設定:You can change the settings for a device type restriction by following these steps:

  1. 登入 Azure 入口網站。Sign in to the Azure portal.
  2. 選取 [更多服務] 並搜尋 Intune,然後選擇 [Intune]。Select More Services, search for Intune, and then choose Intune.
  3. 選取 [裝置註冊] > [註冊限制]。Select Device enrollment > Enrollment restrictions.
  4. 在 [裝置類型限制] 下選擇您想要設定的限制。Under Device Type Restrictions, choose the restriction that you want to set.
  5. 在限制名稱下 (預設限制為 [所有使用者]),選取 [平台]。Under the restriction name (All Users for the default restriction), select Platforms. 為每個列出的平台選擇 [允許] 或 [封鎖]。Choose Allow or Block for each platform listed.
  6. 選取 [儲存]。Select Save.
  7. 在限制名稱下 (預設限制為 [所有使用者]),選取 [平台設定]。Under the restriction name (All Users for the default restriction), select Platform Configurations. 然後選取所列平台的最低和最高版本Then select the minimum and maximum Versions for the platforms listed. 支援的版本包括:Supported versions include:
    • Android 工作設定檔支援 major.minor.rev.build。Android work profile support major.minor.rev.build.
    • iOS 支援 major.minor.rev。iOS supports major.minor.rev.
    • Windows 支援 major.minor.rev.build,僅限 Windows 10。Windows supports major.minor.rev.build for Windows 10 only. 作業系統版本不適用於以裝置註冊計劃、Apple School Manager 或 Apple Configurator 應用程式註冊的 Apple 裝置。Operating system versions don't apply to Apple devices that enroll with the Device Enrollment Program, Apple School Manager, or the Apple Configurator app.
  8. 指定要 [允許] 還是 [封鎖] 每個平台列出的個人所有裝置。Specify whether to Allow or Block Personally owned devices for each platform listed. 顯示設定個人所擁有設定之預設裝置平台設定的裝置限制工作區Device restrictions workspace with the default device platform configurations showing personally owned settings configured
  9. 選取 [儲存]。Select Save.

注意

  • 若您從註冊封鎖個人擁有的 Android 裝置,則個人擁有的 Android 工作設定檔裝置仍可以註冊。If you block personally owned Android devices from enrollment, personally owned Android work profile devices can still enroll.
  • 根據預設,Android 工作設定檔裝置設定與您的 Android 裝置設定相同。By default, your Android work profile devices settings are the same as your settings for your Android devices. 變更 Android 工作設定檔設定後,就不再是那麼回事了。After you change your Android work profile settings, that's no longer the case.
  • 若您封鎖個人的 Android 工作設定檔註冊,則只有公司的 Android 裝置可以註冊為 Android 工作設定檔。If you block personal Android work profile enrollment, only corporate Android devices can enroll as Android work profile.

設定裝置限制Set device limit restrictions

您可以遵循下列步驟變更裝置限制的設定:You can change the settings for a device limit restriction by following these steps:

  1. 登入 Azure 入口網站。Sign in to the Azure portal.
  2. 選取 [更多服務] 並搜尋 Intune,然後選擇 [Intune]。Select More Services, search for Intune, and then choose Intune.
  3. 選取 [裝置註冊] > [註冊限制]。Select Device enrollment > Enrollment restrictions.
  4. 在 [裝置限制] 下選擇您想要設定的限制。Under Device Limit Restrictions, choose the restriction that you want to set.
  5. 選取 [裝置限制],然後在下拉式清單中,選取使用者可以註冊的裝置數目上限。Select Device Limit, and then in the drop-down list, select the maximum number of devices a user can enroll. 具有裝置限制的 [device limit restrictions] (裝置數量限制) 刀鋒視窗Device limit restrictions blade with the device limit restrictions
  6. 選取 [儲存]。Select Save.

使用者會看到通知,告訴他們何時符合其已註冊裝置的限制。Users see a notification that tells them when they've met their limit of enrolled devices. 例如,在 iOS 上,它看起來會像這樣:For example, on iOS, it looks like this:

iOS 裝置限制通知

變更註冊限制優先順序Change enrollment restriction priority

當使用者屬於多個指派限制的群組時,會使用優先順序。Priority is used when a user exists in multiple groups that are assigned restrictions. 使用者只受制於所屬群組被指派的最高優先順序限制。Users are subject only to the highest priority restriction assigned to a group that they are in. 例如,Joe 屬於指派了優先順序 5 限制的群組 A,也屬於指派了優先順序 2 限制的群組 B。For example, Joe is in group A assigned to priority 5 restrictions and also in group B assigned to priority 2 restrictions. Joe 只受制於優先順序 2 限制。Joe is subject only to the priority 2 restrictions.

當您建立一項限制時,它會新增至清單,剛好高預設值一階。When you create a restriction, it's added to the list just above the default.

裝置註刪包括裝置類型和裝置限制的預設限制。Device enrollment includes default restrictions for both device type and device limit restrictions. 除非為更高的優先順序限制所覆寫,否則這兩項限制適用於所有使用者。These two restrictions apply to all users unless they're overridden by higher-priority restrictions.

您可以變更任何非預設限制的優先順序。You can change the priority of any non-default restriction.

  1. 登入 Azure 入口網站。Sign in to the Azure portal.
  2. 選取 [更多服務] 並搜尋 Intune,然後選擇 [Intune]。Select More Services, search for Intune, and then choose Intune.
  3. 選取 [裝置註冊] > [註冊限制]。Select Device enrollment > Enrollment restrictions.
  4. 將滑鼠停留在優先順序清單的限制上。Hover over the restriction in the priority list.
  5. 使用三個垂直點,將優先順序拖曳到所要的清單位置。Using the three vertical dots, drag the priority to the desired position in the list.