Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when they are joined to Azure Active Directory. Which configuration should the administrator implement?
- ACreate a provisioning package for Intune enrollment and deploy it via USB.
- BConfigure a Group Policy Object (GPO) to enable automatic MDM enrollment.
- CManually enroll each device from the Company Portal app.
- DEnable MDM user scope and MAM user scope in Azure Active Directory.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable MDM user scope and MAM user scope in Azure Active Directory.
Automatic MDM enrollment for Azure AD joined devices is configured directly within Azure Active Directory settings. Enabling MDM user scope links user accounts to Intune for automatic enrollment during the Azure AD join process.
Why the other options are wrong
- A. Provisioning packages are for bulk enrollment of devices not typically joined to Azure AD or during initial setup, and not for automatic enrollment upon Azure AD join.
- B. GPOs are primarily for on-premises AD joined devices, not Azure AD joined devices for automatic Intune enrollment.
- C. This is a manual process and does not achieve automatic enrollment when devices are joined to Azure AD.
Automatic MDM Enrollment (Azure AD Join)
A feature in Azure Active Directory that automatically enrolls Windows devices into Microsoft Intune when they are joined to Azure AD by a user.
- Configured in Azure AD > Mobility (MDM and MAM).
- Activates when a user joins a device to Azure AD.
- Requires MDM user scope to be set to 'Some' or 'All'.
Memory trick: Auto-Enrollment is like a digital 'welcome wagon' from Azure AD to Intune.