Managing user and Windows 10/11 computer not joined to AD domain with Intune?

EnterpriseArchitect 5,296 Reputation points
2023-12-01T12:12:19.96+00:00

I need some advice on best practices and the steps involved in utilizing Intune to onboard and register a user with a Windows 10 or 11 OS PC.

These are remote users with M365 E3 and M365 F3 licences assigned who are not connected to my on-premise AD DS.

Each individual has a personal computer running Windows 10 or 11 and is connected to the internet from their home.

My goal here is to be able to onboard and enrol their computer with Intune to deploy software and enforce some security policy to use M365 platform and other resources in Azure.

I would be very grateful for any assistance.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
399 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,863 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,337 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,902 questions
0 comments No comments
{count} votes

Accepted answer
  1. Rudy Ooms 611 Reputation points MVP
    2023-12-01T13:00:07.6033333+00:00

    If you dont have an additional rmm tool or something to manage the device ,it would be up to the end user to manually enroll the device.

    https://video2.skills-academy.com/en-us/mem/intune/user-help/enroll-windows-10-device

    But... "personal computer" please beware of what you are getting yourself into! Maybe a better idea would be to use MAM for windows (edge) to access company resources from those devices or give those users a cloud PC.

    But restricting their personal devices... i wouldn't be okay with that if it was my own device ... let alone think of what happens when somehow the device gets bitlocker encrypted, reboots ask for the recovery key but somehow that key isn't uploaded to azure... guess who they will blame :) ... not me :P

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Crystal-MSFT 47,216 Reputation points Microsoft Vendor
    2023-12-04T01:37:04.6866667+00:00

    @EnterpriseArchitect , Thanks for posting in Q&A. For Autopilot enrollment, if the new device includes Autopilot service when purchasing it, then you can ask OEM Reseller or partner to do the Autopilot registration. If the Autopilot service is not included, then we need to manually do Autopilot registration.

    https://video2.skills-academy.com/en-us/autopilot/registration-overview

    To do Windows Autopilot user-driven Microsoft Entra join, we can refer the steps in the following link:

    https://video2.skills-academy.com/en-us/autopilot/tutorial/user-driven/azure-ad-join-workflow

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.