Windows Device Enrollment V2 — Step-by-Step Guide
Microsoft Intune / Microsoft Entra ID
1. Title & Scope
Title: Windows Device Enrollment V2 — Step-by-Step Guide
Scope: This guide provides a complete step-by-step procedure for configuring and validating Windows device enrollment using Microsoft Intune and Microsoft Entra ID. It is intended to provide administrators with a repeatable deployment process and documented proof that Windows devices are successfully enrolled and managed.
Target:
- Microsoft Intune Administrators
- Microsoft Entra ID Administrators
- Endpoint Management Teams
- Systems Administrators
- Help Desk and Desktop Support Teams
- Infrastructure and Security Teams
2. Purpose
- Configure Windows device enrollment through Microsoft Intune.
- Configure the required Windows enrollment settings.
- Define which users are permitted to enroll Windows devices.
- Configure automatic MDM enrollment.
- Validate Microsoft Entra registration and Intune enrollment.
- Provide a repeatable deployment and validation process.
- Establish a consistent troubleshooting process for enrollment issues.
3. Prerequisites
- Microsoft Entra ID tenant.
- Microsoft Intune tenant and active Intune service.
- Appropriate Microsoft licensing assigned to test users.
- Supported Windows 10 or Windows 11 device.
- Internet connectivity from the Windows device.
- Test user account available for enrollment.
- Administrative access to Microsoft Intune.
- Administrative access to Microsoft Entra ID.
- Enrollment restrictions reviewed before deployment.
4. Deployment Procedure
Step 1 — Open Microsoft Intune Admin Center
Sign in to the Microsoft Intune admin center using an authorized administrative account. The Intune admin center is the primary management interface used to configure Windows enrollment, compliance, configuration profiles, applications, and device management.
Step 2 — Navigate to Windows Enrollment
From the Microsoft Intune admin center, navigate to the Windows enrollment section. Review the available enrollment configuration options before making changes.
Microsoft Intune admin center
|
+-- Devices
|
+-- Enrollment
|
+-- Windows
Step 3 — Review Windows Enrollment Settings
Review the Windows enrollment configuration and confirm that the tenant is configured for the organization's intended enrollment method.
Pay particular attention to enrollment restrictions, automatic enrollment, device platform settings, and user enrollment permissions.
Step 4 — Configure Automatic MDM Enrollment
Configure automatic MDM enrollment so that eligible Windows devices are automatically enrolled into Microsoft Intune when the appropriate Microsoft Entra enrollment event occurs.
The configuration should be scoped to the appropriate users or groups rather than automatically applying broad administrative permissions to the entire organization.
Step 5 — Configure Enrollment Restrictions
Review the enrollment restrictions that determine which device platforms and ownership types users are permitted to enroll.
For Windows environments, verify that Windows enrollment is permitted and that the configuration aligns with the organization's security and endpoint management policy.
Step 6 — Configure the Enrollment Device Platform
Verify that Windows devices are enabled under the applicable enrollment platform configuration. Review the minimum supported operating system version and any organization-specific restrictions.
Step 7 — Prepare the Windows Device
Start with a supported Windows device and connect it to the Internet. Sign in using the organizational account intended for enrollment.
For a new device, enrollment may occur during the Windows Out-of-Box Experience (OOBE). For an existing device, enrollment can be initiated through Windows account and access settings.
Step 8 — Connect the Windows Device to Microsoft Entra ID
During the enrollment process, authenticate using the organization's Microsoft Entra credentials. Complete any required authentication controls, including multifactor authentication if configured.
Step 9 — Confirm Device Management Enrollment
After authentication, Windows processes the applicable enrollment configuration. The device establishes a management relationship with Microsoft Intune.
Allow sufficient time for the device to complete initial enrollment and policy processing before beginning validation.
Step 10 — Verify Windows Work or School Account
On the Windows device, open the work or school account settings and verify that the organizational account is connected.
Settings
|
+-- Accounts
|
+-- Access work or school
|
+-- Organizational Account
|
+-- Connected
Step 11 — Verify Microsoft Entra Device Registration
Return to the Microsoft Entra admin center and locate the enrolled Windows device. Verify that the device appears in the organization's device inventory.
Review the device name, ownership information, operating system, registration state, and associated user information as applicable.
Step 12 — Verify the Device in Microsoft Intune
Open Microsoft Intune and navigate to the Windows device inventory. Locate the newly enrolled device and verify that it has been successfully added to Intune.
Step 13 — Review Device Properties
Open the device record and review the available management information. Confirm that the device contains the expected operating system, ownership, primary user, enrollment date, management state, and other applicable properties.
Step 14 — Confirm Policy Synchronization
Initiate a manual synchronization from the Windows device or Intune portal. This confirms that the device can communicate with the Intune management service and receive applicable configuration policies.
Step 15 — Verify Compliance and Configuration Policies
Review the device's assigned configuration and compliance policies. Confirm that the device is receiving the expected policies and that no enrollment-related errors are reported.
Step 16 — Verify Enrollment Status
The final enrollment validation should confirm that the device exists in both Microsoft Entra ID and Microsoft Intune and that the management relationship is operational.
5. Validation & Troubleshooting
- Confirm the Windows device has Internet connectivity.
- Confirm the user's Intune-capable license is active.
- Confirm the user is included in the automatic enrollment scope.
- Confirm Windows enrollment is permitted by enrollment restrictions.
- Confirm the device appears in Microsoft Entra ID.
- Confirm the device appears in Microsoft Intune.
- Confirm the device has a valid management relationship.
- Perform a manual device synchronization.
- Review Intune device and enrollment logs for errors.
- Review Microsoft Entra sign-in activity when authentication problems occur.
Common Enrollment Issues
Device does not appear in Intune:
Verify the user's enrollment scope, licensing, enrollment restrictions, and network connectivity. Allow additional time for initial synchronization before concluding that enrollment failed.
User cannot enroll the device:
Review enrollment restrictions and confirm that the user is permitted to enroll the Windows platform.
Device appears in Entra ID but not Intune:
Review automatic MDM enrollment configuration and confirm that the user is within the configured enrollment scope.
Policies are not applying:
Perform a manual synchronization and review the device's assigned policies. Confirm that the device and user are included in the appropriate policy assignments.
6. Escalation Path
- Level 1 — Help Desk: Confirm connectivity, user licensing, Windows version, account status, and basic enrollment configuration.
- Level 2 — Endpoint Administration: Review Intune enrollment restrictions, automatic enrollment scope, device records, policy assignments, and synchronization status.
- Level 3 — Identity Administration: Review Microsoft Entra device registration, authentication, Conditional Access, MFA, and sign-in activity.
- Level 4 — Microsoft Support: Escalate persistent tenant-level or service-level enrollment issues after collecting device identifiers, timestamps, error messages, enrollment logs, and screenshots.
7. Deployment Evidence Checklist
- Microsoft Intune admin center configuration verified.
- Windows enrollment configuration verified.
- Automatic enrollment configuration verified.
- Enrollment restrictions verified.
- Windows device enrollment completed.
- Microsoft Entra device registration verified.
- Microsoft Intune device record verified.
- Device synchronization completed.
- Policy assignment verified.
- Final successful enrollment state verified.
8. Final Validation
Perform a final review of the Microsoft Entra and Intune device records. Confirm that the device information is consistent across both platforms and that the expected management policies are being applied.