設定註冊限制Set enrollment restrictions

適用對象:Azure 入口網站的 IntuneApplies to: Intune in the Azure portal
您需要傳統入口網站的 Intune 相關文件嗎?Looking for documentation about Intune in the classic portal? 請移至這裡Go here.

身為 Intune 系統管理員,您可以建立和管理註冊限制,定義可以註冊使用 Intune 管理的裝置數目和類型。As an Intune administrator, you can create and manage enrollment restrictions which define the number and types of devices that can enroll into management with Intune. 您可以建立多項限制,並將它們套用至不同的使用者群組。You can create multiple restrictions and apply them to different user groups. 您可以設定不同限制的優先順序You can set the priority order for your different restrictions.

注意

註冊限制不是安全性功能。Enrollment restrictions are not security features. 遭盜用的裝置可以冒用身分。Compromised devices can misrepresent their character. 這些限制是非惡意使用者的最佳屏障。These restrictions are a best-effort barrier for non-malicious users.

您可以建立的特定註冊限制包括:The specific enrollment restrictions that you can create include:

  • 已註冊裝置的數目上限Maximum number of enrolled devices
  • 可以註冊的裝置平台:Device platforms that can enroll:
    • AndroidAndroid
    • Android for WorkAndroid for Work
    • iOSiOS
    • macOSmacOS
    • WindowsWindows
  • iOS、Android、Android for Work 和 Windows 的平台作業系統版本 (只會使用 Windows 10 版本,如果允許 Windows 8.1 此項請留白)Platform operating system version for iOS, Android, Android for Work, and Windows (only Windows 10 versions may be used, leave this blank if Windows 8.1 is allowed)
    • 最低版本Minimum version
    • 最高版本Maximum version
  • 限制個人擁有的裝置 (僅限 iOS、Android、Android for Work、macOS)Restrict personally owned devices (iOS, Android, Android for Work, macOS only)

預設限制Default restrictions

裝置類型和裝置限制註冊限制都會自動提供預設限制。Default restrictions are automatically provided for both device type and device limit enrollment restrictions. 您可以變更預設選項。You can change the options for the defaults. 預設限制適用於所有使用者和無使用者註冊。Default restrictions apply to all user and userless enrollments. 您可以使用較高的優先順序建立新的限制,覆寫這些預設值。You can override these defaults by creating new restrictions with higher priorities.

建立限制Create a restriction

  1. 登入 Azure 入口網站。Sign into the Azure portal.
  2. 選擇 [更多服務],搜尋 [Intune],然後選擇 [Intune]。Choose More Services, search for Intune, and then choose Intune.
  3. 選擇 [裝置註冊] > [註冊限制]。Choose Device enrollment > Enrollment restrictions.
  4. 選擇 [建立限制]。Choose Create restriction.
  5. 提供限制的名稱和描述。Give the restriction a name and description.
  6. 選擇 [限制類型],然後按一下 [建立]。Choose a Restriction type and then click Create.
  7. 如需限定裝置限制,請按一下 [裝置限制] 設定使用者能夠註冊的裝置數上限。For device limit restrictions, click Device limit to set the maximum number of devices that a user can enroll.
  8. 如需裝置類型限制,請按一下 [平台] 和 [平台設定] 允許或封鎖各種平台和版本。For device type restrictions, click Platforms and Platform configurations to allow or block various platforms and versions.
  9. 按一下 [指派] > + [選取群組]。Click Assignments > + Select groups.
  10. 在 [選取群組] 下,選取一或多個群組,然後按一下 [選取]。Under Select groups, select one or more groups, and then click Select. 限制只適用於指派限制的群組。The restriction only applies to groups to which it is assigned. 如果限制不指派給至少一個群組,就不會產生任何效果。If you don't assign a restriction to at least one group, it won't have any effect.
  11. 按一下 [儲存]Click Save.
  12. 新建立的限制優先順序剛好在預設值前。The new restriction is created with a priority just above the default. 您可以變更優先順序You can change the priority.

設定裝置類型限制Set device type restrictions

您可以遵循下列步驟變更裝置類型限制的設定:You can change the settings for a device type restriction by following these steps:

  1. 登入 Azure 入口網站。Sign into the Azure portal.
  2. 選擇 [更多服務],搜尋 [Intune],然後選擇 [Intune]。Choose More Services, search for Intune, and then choose Intune.
  3. 選擇 [裝置註冊] > [註冊限制]。Choose Device enrollment > Enrollment restrictions.
  4. 在 [裝置類型限制] 下選擇您想要設定的限制。Under Device Type Restrictions, choose the restriction that you want to set.
  5. 在限制名稱下 (預設限制為 [所有使用者]),選取 [平台]。Under the restriction name (All Users for the default restriction), select Platforms. 為每個列出的平台選擇 [允許] 或 [封鎖]。Choose Allow or Block for each platform listed.
  6. 按一下 [儲存]Click Save.
  7. 在限制名稱下 (預設限制為 [所有使用者]),選取 [平台設定] 並選取所列平台的 [版本] 最小值及最大值。Under the restriction name (All Users for the default restriction), select Platform Configurations and select the minimum and maximum Versions for the platforms listed. 支援的版本包括:Supported versions include:
    • Android 和 Android for Work 支援 major.minor.rev.build。Android and Android for Work support major.minor.rev.build.
    • iOS 支援 major.minor.rev。iOS supports major.minor.rev.
    • Windows 支援 major.minor.rev.build,僅限 Windows 10。Windows supports major.minor.rev.build for Windows 10 only. 作業系統版本不適用於以裝置註冊計劃、Apple School Manager 或 Apple Configurator 應用程式註冊的 Apple 裝置。Operating system versions don't apply to Apple devices enrolling with Device Enrollment Program, Apple School Manager, or the Apple Configurator app.
  8. 指定要 [允許] 還是 [封鎖] 每個平台列出的個人所有裝置。Specify whether to Allow or Block Personally owned devices for each platform listed.

    顯示設定 [個人所擁有] 設定之預設裝置平台設定的裝置限制工作區螢幕擷取畫面。

  9. 按一下 [儲存]Click Save.

注意

  • 如果您從註冊封鎖個人擁有的 Android 裝置,則個人擁有的 Android for Work 裝置仍可以註冊。If you block personally owned Android devices from enrollment, personally owned Android for Work devices can still enroll.
  • 根據預設,Android for Work 裝置設定會與您的 Android 裝置設定相同。By default, your Android for Work devices settings will be the same as your settings for your Android devices. 不過,變更 Android for Work 設定後,就不再是那麼回事了。However, after you change your Android for Work settings that will no longer be the case.
  • 如果您封鎖個人的 Android for Work 註冊,只有公司的 Android 裝置可以註冊為 Android for Work。If you block personal Android for Work enrollment, only corporate Android devices can enroll as Android for Work.

設定裝置限制Set device limit restrictions

您可以遵循下列步驟變更裝置限制的設定:You can change the settings for a device limit restriction by following these steps:

  1. 登入 Azure 入口網站。Sign into the Azure portal.
  2. 選擇 [更多服務],搜尋 [Intune],然後選擇 [Intune]。Choose More Services, search for Intune, and then choose Intune.
  3. 選擇 [裝置註冊] > [註冊限制]。Choose Device enrollment > Enrollment restrictions.
  4. 在 [裝置限制] 下選擇您想要設定的限制。Under Device Limit Restrictions, choose the restriction that you want to set.
  5. 選擇 [裝置限制],然後在下拉式清單中,選取使用者可以註冊的裝置數目上限。Choose Device Limit and then, in the drop-down list, select the maximum number of devices a user can enroll. 有裝置數量限制之 [device limit restrictions] (裝置數量限制) 刀鋒視窗的螢幕擷取畫面。Screenshot of the device limit restrictions blade with the device limit restrictions.
  6. 按一下 [儲存]Click Save.

變更註冊限制優先順序Change enrollment restriction priority

當使用者屬於多個指派限制的群組時,會使用優先順序。Priority is used when a user exists in multiple groups that are assigned restrictions. 使用者只受制於所屬群組被指派的最高優先順序限制。Users are subject only to the highest priority restriction assigned to a group that they are in. 例如,Joe 屬於指派了優先順序 5 限制的群組 A 與指派了優先順序 2 限制的群組 B。For example, Joe is in a group A assigned to priority 5 restrictions and group B assigned to priority 2 restrictions. Joe 只受制於優先順序 2 限制。Joe is only subject to the priority 2 restrictions.

當您建立一項限制時,它會新增至清單,剛好高預設值一階。When you create a restriction, it is added to the list just above the default.

裝置註刪包括裝置類型和裝置限制的預設限制。Device enrollment includes default restrictions for both device type and device limit restrictions. 除非為更高的優先順序限制所覆寫,否則這兩項限制適用於所有使用者。These two restrictions apply to all users unless they are overridden by higher-priority restrictions.

您可以變更任何非預設限制的優先順序。You can change the priority of any non-default restriction.

變更限制優先順序To change restriction priority

  1. 登入 Azure 入口網站。Sign into the Azure portal.
  2. 選擇 [更多服務],搜尋 [Intune],然後選擇 [Intune]。Choose More Services, search for Intune, and then choose Intune.
  3. 選擇 [裝置註冊] > [註冊限制]。Choose Device enrollment > Enrollment restrictions.
  4. 將滑鼠停留在優先順序清單的限制上。Hover over the restriction in the priority list.
  5. 使用三個垂直點,將優先順序拖曳到所要的清單位置。Using the three vertical dots, drag the priority to the desired position in the list.