Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in with their organizational accounts for the first time. Which configuration in Azure Active Directory (Azure AD) should be verified or configured?

  1. ASet the 'Users may join devices to Azure AD' setting to 'Selected'.
  2. BSet the 'Maximum number of devices per user' to 'Unlimited'.
  3. CConfigure the 'MDM user scope' to 'All' or 'Some' and assign users.
  4. DEnable 'Enterprise State Roaming' for all users.
Show answer & explanation

Correct answer: C. Configure the 'MDM user scope' to 'All' or 'Some' and assign users.

To ensure automatic MDM enrollment upon first sign-in, the MDM user scope in Azure AD must be configured to include the relevant users. This setting dictates which users' devices will automatically enroll into Intune.

Why the other options are wrong

  • A. This setting controls device registration with Azure AD, not automatic MDM enrollment.
  • B. This setting limits the number of devices a user can register, but does not trigger automatic MDM enrollment.
  • D. Enterprise State Roaming synchronizes user settings across devices, it does not manage device enrollment.

Azure AD MDM User Scope

The Azure AD MDM user scope setting determines which users' Windows devices are automatically enrolled into a Mobile Device Management (MDM) solution like Microsoft Intune when they join Azure AD or sign in with an organizational account.

  • Configured in Azure AD > Mobility (MDM and MAM).
  • Can be set to 'None', 'Some', or 'All'.
  • Crucial for automatic Intune enrollment for corporate devices.

Memory trick: Enrollment Scope: Users' MDM destiny is in their scope.

More Manage devices and apps (55-60%) questions