Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when users sign in for the first time with their organizational accounts. The devices are currently joined to on-premises Active Directory. Which enrollment method should be configured?

  1. ABulk enrollment with Windows Autopilot
  2. BGroup Policy enrollment
  3. CDevice enrollment manager (DEM)
  4. DAutomatic MDM enrollment with user credential
Show answer & explanation

Correct answer: B. Group Policy enrollment

For devices joined to on-premises Active Directory, Group Policy is the primary method to configure automatic MDM enrollment into Intune when users sign in with their organizational accounts. This bridges the on-premises domain with cloud management.

Why the other options are wrong

  • A. Windows Autopilot is for new or reset devices, and while it can integrate with co-management, it's not the direct method for existing AD-joined devices to automatically enroll on user sign-in.
  • C. DEM is for enrolling many devices with a single account, not for automatic user-initiated enrollment from AD-joined devices.
  • D. While it involves user credentials, this option is too generic and doesn't specify the mechanism for AD-joined devices.

Group Policy MDM Enrollment

A method to automatically enroll existing Active Directory-joined Windows devices into Microsoft Intune when users sign in with their Azure AD credentials.

  • Requires Hybrid Azure AD Join
  • Configured via Group Policy Objects (GPOs)
  • Triggers MDM enrollment for users signing in to AD-joined devices

Memory trick: Many Devices Easily Enroll, Linking On-Prem to Cloud.

More Manage devices and apps (55-60%) questions