Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in with their Azure AD credentials for the first time. Which configuration is required in Azure AD to achieve this?

  1. ACreate a Windows Autopilot deployment profile.
  2. BConfigure a Device Compliance policy in Intune.
  3. CSet the MDM user scope to 'All' or 'Some' in Azure AD.
  4. DEnable Hybrid Azure AD Join for the devices.
Show answer & explanation

Correct answer: C. Set the MDM user scope to 'All' or 'Some' in Azure AD.

Automatic MDM enrollment is controlled by the MDM user scope setting in Azure AD. When a user signs into a Windows device with an Azure AD account, if the MDM user scope is configured, the device will automatically enroll into Intune.

Why the other options are wrong

  • A. Windows Autopilot is for pre-provisioning and simplifying out-of-box experience, not the direct trigger for MDM enrollment based on user sign-in for existing devices.
  • B. Device Compliance policies evaluate device health post-enrollment, they do not initiate enrollment.
  • D. Hybrid Azure AD Join is for devices joined to on-premises AD and registered with Azure AD, not for automatic Intune enrollment upon first sign-in for cloud-native devices.

Azure AD MDM User Scope

A setting in Azure AD that determines which users' Windows devices will automatically enroll into an MDM solution (like Intune) when they sign in with their Azure AD account.

  • Controls automatic MDM enrollment for Windows devices.
  • Configured in Azure AD > Mobility (MDM and MAM).
  • Can be set to None, Some (specific groups), or All.

Memory trick: Azure AD's scope guides devices to Intune's home.

More Manage devices and apps (55-60%) questions