Using Intune and Entra ID feature to make sure the device cannot be formatted by the user?

EnterpriseArchitect 5,036 Reputation points
2024-02-19T10:50:00.0333333+00:00

How can I configure Intune for my existing laptop users (Windows 10 and Windows 11) globally in the world, so that when the laptop is formatted by the users it will show the company portal for Intune Onboarding again? As a result, if the laptop is stolen or is ready to be repurposed without official decommissioning by the IT Team, it will be rendered worthless. The existing users are already licensed using M365 E3-E5 with Entra ID Premium P2 tenant-wide.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
371 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,785 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,305 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,669 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,365 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 45,736 Reputation points Microsoft Vendor
    2024-02-20T01:26:41.3633333+00:00

    @EnterpriseArchitect, Thanks for porting in Q&A. To configure Intune for your existing laptop users globally so that when the laptop is formatted by the users it will still do the enroll. Based on my experience, you can do Autopilot register and enroll the device via Autopilot enrollment.

    https://video2.skills-academy.com/en-us/autopilot/tutorial/autopilot-scenarios

    Based as I know, for the device registered with the Windows Autopilot deployment service. Although the end user reset the device, it will still come to Autopilot enrollment stage to ask for entering organization user account to login when it connects to the Internet.

    https://video2.skills-academy.com/en-us/autopilot/registration-overview

    Therefore, I think this is an option for your scenario.

    Meanwhile, you can try to use a remote device action from within the Microsoft Intune admin center to locate a device which is lost or stolen.

    https://video2.skills-academy.com/en-us/mem/intune/remote-actions/device-locate

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful