Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when they are joined to Azure Active Directory. Which setting in Azure Active Directory (now Microsoft Entra ID) should be configured?
- AMobility (MDM and MAM) for Microsoft Intune
- BDevice settings for 'Users may join devices to Azure AD'
- CConditional Access policies for device compliance
- DDevice registration settings for device ownership
Show answer & explanationAnswer & explanation
Correct answer: A. Mobility (MDM and MAM) for Microsoft Intune
Automatic MDM enrollment is configured within the Mobility (MDM and MAM) settings for Microsoft Intune in Azure AD. This links Azure AD Join with Intune enrollment.
Why the other options are wrong
- B. This setting allows users to join devices but doesn't automatically enroll them into MDM.
- C. Conditional Access policies enforce compliance but do not initiate automatic enrollment.
- D. Device registration is part of the overall device management but doesn't directly configure automatic MDM enrollment.
Azure AD Automatic MDM Enrollment
A feature that automatically enrolls Windows devices into Microsoft Intune when they are joined to Azure Active Directory.
- Requires configuration in Azure AD's Mobility (MDM and MAM) settings.
- Ensures devices are managed by Intune from the moment they join Azure AD.
- Applies to devices joined or registered with Azure AD.
Memory trick: Join Azure AD, then MDM will automatically lead.