Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in for the first time with their organizational accounts. The devices are currently joined to on-premises Active Directory. Which enrollment method should be configured?
- ABulk enrollment with Windows Autopilot
- BGroup Policy enrollment
- CDevice enrollment manager (DEM)
- DAutomatic MDM enrollment with user credential
Show answer & explanationAnswer & explanation
Correct answer: B. Group Policy enrollment
For devices joined to on-premises Active Directory, Group Policy is the primary method to configure automatic MDM enrollment into Intune when users sign in with their organizational accounts. This bridges the on-premises domain with cloud management.
Why the other options are wrong
- A. Windows Autopilot is for new or reset devices, and while it can integrate with co-management, it's not the direct method for existing AD-joined devices to automatically enroll on user sign-in.
- C. DEM is for enrolling many devices with a single account, not for automatic user-initiated enrollment from AD-joined devices.
- D. While it involves user credentials, this option is too generic and doesn't specify the mechanism for AD-joined devices.
Group Policy MDM Enrollment
A method to automatically enroll existing Active Directory-joined Windows devices into Microsoft Intune when users sign in with their Azure AD credentials.
- Requires Hybrid Azure AD Join
- Configured via Group Policy Objects (GPOs)
- Triggers MDM enrollment for users signing in to AD-joined devices
Memory trick: Many Devices Easily Enroll, Linking On-Prem to Cloud.