Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy

A company policy requires that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when a user signs in for the first time with their Azure AD account. You need to configure this automatic enrollment. Which method should you implement?

  1. AGroup Policy Object (GPO) for Hybrid Azure AD Join
  2. BManual MDM enrollment via Company Portal
  3. CAutomatic MDM enrollment via Azure AD Premium
  4. DBulk enrollment using Windows Autopilot
Show answer & explanation

Correct answer: C. Automatic MDM enrollment via Azure AD Premium

Automatic MDM enrollment for Windows devices linked to Azure AD Premium allows devices to automatically enroll in Intune when users sign in with their Azure AD accounts, fulfilling the requirement for corporate-owned devices upon first sign-in.

Why the other options are wrong

  • A. GPO for Hybrid Azure AD Join facilitates device registration but does not inherently trigger automatic MDM enrollment without further configuration through Azure AD Premium.
  • B. Manual enrollment requires user intervention and doesn't meet the 'automatically enroll' requirement.
  • D. Windows Autopilot is for pre-provisioning and zero-touch deployment, which is a different scenario than automatic enrollment upon first user sign-in for already-deployed corporate devices.

Automatic MDM Enrollment (Azure AD Premium)

A feature in Azure AD that allows devices to automatically enroll in a Mobile Device Management (MDM) solution like Intune when they are joined to Azure AD or registered with Azure AD.

  • Requires Azure AD Premium license.
  • Configured in Azure AD > Mobility (MDM and MAM).
  • Applies to devices that are Azure AD joined or Hybrid Azure AD joined.

Memory trick: Enrollment's key: automatic ease for corporate peace.

More Manage identity and compliance (10-15%) questions