Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard

A Microsoft 365 Endpoint Administrator needs to ensure that all corporate-owned Windows 11 devices automatically enroll into Microsoft Intune when they are joined to Azure AD. A group of pilot users has been assigned an Intune license, and the administrator wants to limit automatic enrollment to only these pilot users initially. Which two settings must be configured to achieve this?

  1. AIntune > Device enrollment > Automatic Enrollment > MDM user scope: All, and MAM user scope: None.
  2. BAzure AD > Mobility (MDM and MAM) > Microsoft Intune > MDM user scope: Some, and select the pilot user group.
  3. CIntune > Device enrollment > Enrollment restrictions > Device type restrictions: Configure Windows (MDM) to allow personal devices.
  4. DAzure AD > Devices > Device settings > Users may join devices to Azure AD: Selected, and select the pilot user group.
Show answer & explanation

Correct answer: B. Azure AD > Mobility (MDM and MAM) > Microsoft Intune > MDM user scope: Some, and select the pilot user group.

To control which users can automatically enroll devices into Intune when joining Azure AD, the 'MDM user scope' setting under Azure AD's Mobility (MDM and MAM) for Microsoft Intune must be set to 'Some' and then specific user groups (like the pilot group) must be selected. This governs the automatic MDM enrollment for Azure AD joined devices.

Why the other options are wrong

  • A. Setting MDM user scope to 'All' would enroll all users, not just the pilot group, contradicting the requirement.
  • C. Enrollment restrictions control *types* of devices allowed, not which *users* can enroll their devices via Azure AD Join.
  • D. This setting controls who can *join* devices to Azure AD, not who can *automatically enroll* into Intune. While related, it's not the direct control for MDM enrollment scope.

Azure AD Automatic MDM Enrollment Scope

Configuring the 'MDM user scope' in Azure AD's Mobility (MDM and MAM) settings to control which user groups are eligible for automatic device enrollment into Microsoft Intune upon Azure AD Join.

  • Crucial for staged rollouts of Intune enrollment.
  • Located in Azure AD under Mobility (MDM and MAM).
  • Options are None, Some (with group selection), or All.

Memory trick: Mobility scope controls the 'Move' to Intune.

More Manage devices and apps (55-60%) questions