Many times, I’ve seen companies actively managing personal devices in Microsoft Intune, sometimes intentionally, but most of the time, accidentally without the user’s knowledge. My personal stance on the subject is simple: don’t fully manage a device that isn’t yours.
To solve this issue, I wrote a quick and easy guide for you on how to disable personal device enrollments by configuring enrollment restrictions in Microsoft Intune.
The guide will cover the following sections:
To disable personal device enrollment in Microsoft Intune, please follow the following steps;
Keep in mind that personally-owned devices that were previously enrolled will remain enrolled until you remove or retire them from the Microsoft Intune device overview.
Congratulations, you have successfully prevented users from enrolling personal devices in Microsoft Intune.
If users try to enroll their personal device (accidentally or intentionally), they will receive an error message, like the Windows error message below.
After configuring the enrollment device platform restrictions policy, administrators must use an authorized method to corporately enroll a new device in Microsoft Intune.
For Windows devices, corporate device enrollments are available through;
Secondly, for MacOS or iOS/iPadOS devices, corporate device enrollments are available through;
Lastly, for Android devices, corporate device enrollments are available through;
If you found this post informative or have any questions, please tell me in the comment section.
This post is part of the unmanaged devices blog series; find more posts here. View previous part: Microsoft Defender (MDE) for personal Android & iOS with MAM View next part: How to manage secure access for external admins |
Your email address will not be published. Required fields are marked *
2 Comments