
These configurations help improve and simplify the enrollment experience for you and device users, and help you stay organized in the admin center. Prepare devices for enrollment by configuring enrollment features, such as enrollment restrictions, device categorization, and device enrollment managers. Users on these devices authenticate by signing in to the device using their Azure AD work account.


Registration in Azure AD is a required step for Intune management. For more information and suggestions, see the Planning guide: Step 5 - Create a rollout plan. If everything is going well, assign the enrollment profile to more pilot groups. After initial testing, add more users to the pilot group.

Assign the enrollment profile to a pilot or test group. If this is your first time deploying enrollment profiles with Intune, or you're trying a new configuration, start small and use a staged approach.

How-to prepare enrollment in Microsoft Intune for corporate-owned and user-owned devices.In the final phase of deployment, devices are registered or joined in Azure Active Directory (Azure AD), enrolled in Microsoft Intune, and checked for compliance.ĭuring enrollment, Microsoft Intune installs a mobile device management (MDM) certificate on the device, which enables Intune to enforce enrollment profiles, enrollment restrictions, and the policies and profiles you created earlier in this guide.
