Wes Ellis./ a personal notebook
Technology. Stories. Side projects.
A few things worth writing down.
← Back to Engineering

Engineering

How to Enroll a Windows Device in Intune by Hand

Part 2 of the thread Getting devices into Intune

THE SHORT VERSION4 points
  • Enroll as the person who'll use the device, with an Intune license. Not as you, the admin.
  • For a company-owned PC, click Join this device to Microsoft Entra ID instead of typing the email address.
  • The email route marks the device Personal, and fails outright if personal Windows devices are blocked.
  • dsregcmd /status and the DeviceManagement-Enterprise-Diagnostics-Provider log tell you what really happened.

Autopilot and Group Policy are how you enroll devices at scale. But sometimes you've got one machine in front of you (a test box, a loaner, a laptop that missed the rollout) and you just want it in Intune in the next five minutes. Windows can do that from the Settings app.

It's quick. It's also easy to pick the wrong option, and the difference matters more than the screens let on.

Before you start

A few things have to be true, or the enrollment fails with an unhelpful error:

  • The user has an Intune license. Enrollment happens as the user, not as an admin. Use the account of the person who'll actually use the device.
  • The MDM user scope includes them. In the Entra admin center, check Mobility (MDM and WIP) > Microsoft Intune. The MDM user scope has to be All or a group that contains the user.
  • Enrollment restrictions allow it. In the Intune admin center, under Devices > Enrollment > Device platform restriction, make sure Windows is allowed. And if personally owned Windows devices are blocked, hold that thought.
  • The user hasn't hit their device limit. The default is 15 per user, which sounds like plenty until you meet a developer.

Heads up

The old version of this post said to enter your Intune admin credentials, and that's a good way to end up with a laptop whose primary user is you.

The three doors in Settings

Go to Settings > Accounts > Access work or school, then click Connect. On Windows 11 it's the same place, just a slightly different layout.

What happens next depends on what you click:

Type the email address and click Next. This registers the device with Microsoft Entra ID and enrolls it in Intune. The local Windows account stays as-is. This is the bring-your-own-device path, and Intune marks the device as Personal.

"Join this device to Microsoft Entra ID" (a link at the bottom of the dialog). This joins the device to your tenant, so people sign in to Windows with their work account. If the MDM user scope is set up, Intune enrollment happens automatically as part of the join. For a company-owned machine, this is usually the one you want. It does need a local admin to start, and it'll ask you to confirm the organization before it commits.

"Enroll only in device management" (another link at the bottom). Intune enrollment with no Entra registration at all. It exists, but it's rarely what you want. Things like Conditional Access and single sign-on depend on the device's Entra identity, and they won't work.

Side by side:

What you click Entra identity Intune ownership Good for
Email address + Next Registered Personal Bring your own device
Join this device to Microsoft Entra ID Joined Corporate Company-owned machines
Enroll only in device management None - Rarely the right answer

The "Personal" surprise

Here's what catches people. A device enrolled through the first option shows up as Personal, and if your platform restrictions block personal Windows devices, the enrollment simply fails.

There are two clean fixes:

  1. Use the Entra join option instead. Entra-joined devices are treated as corporate.
  2. Add the device as a corporate identifier in Intune (under Devices > Enrollment) before you enroll. On recent Windows 11 builds that means manufacturer, model and serial number.

You can also flip ownership to Corporate on the device's page in Intune after the fact. But if enrollment was blocked outright, there's nothing to flip yet.

Checking it worked

Back in Access work or school, click the connected account and then Info. If you see a Sync button and a list of management details, the device is enrolled. Hit Sync to pull policies right away instead of waiting for the next check-in.

From a command prompt, dsregcmd tells you the join state:

dsregcmd /status | Select-String 'AzureAdJoined|WorkplaceJoined|DomainJoined'

AzureAdJoined : YES means Entra joined, and WorkplaceJoined : YES means registered. In the Intune admin center, the device should appear under Devices > Windows within a few minutes.

If it doesn't, the event log is where the real error lives: Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin.

Tip

The error code in that log is far more searchable than whatever the Settings app told you.