Windows Device Enrollment V2 — Step-by-Step Guide

Windows Device Enrollment V2 — Step-by-Step Guide

Microsoft Intune / Microsoft Entra ID

1. Title & Scope

Title: Windows Device Enrollment V2 — Step-by-Step Guide

Scope: This guide provides a complete step-by-step procedure for configuring and validating Windows device enrollment using Microsoft Intune and Microsoft Entra ID. It is intended to provide administrators with a repeatable deployment process and documented proof that Windows devices are successfully enrolled and managed.

Target:

  • Microsoft Intune Administrators
  • Microsoft Entra ID Administrators
  • Endpoint Management Teams
  • Systems Administrators
  • Help Desk and Desktop Support Teams
  • Infrastructure and Security Teams

2. Purpose

  • Configure Windows device enrollment through Microsoft Intune.
  • Configure the required Windows enrollment settings.
  • Define which users are permitted to enroll Windows devices.
  • Configure automatic MDM enrollment.
  • Validate Microsoft Entra registration and Intune enrollment.
  • Provide a repeatable deployment and validation process.
  • Establish a consistent troubleshooting process for enrollment issues.
Tip: Before beginning deployment, confirm that the administrator account has the required Microsoft Intune and Microsoft Entra permissions and that the organization's licensing supports Intune device management.

3. Prerequisites

  • Microsoft Entra ID tenant.
  • Microsoft Intune tenant and active Intune service.
  • Appropriate Microsoft licensing assigned to test users.
  • Supported Windows 10 or Windows 11 device.
  • Internet connectivity from the Windows device.
  • Test user account available for enrollment.
  • Administrative access to Microsoft Intune.
  • Administrative access to Microsoft Entra ID.
  • Enrollment restrictions reviewed before deployment.

4. Deployment Procedure

Step 1 — Open Microsoft Intune Admin Center

Sign in to the Microsoft Intune admin center using an authorized administrative account. The Intune admin center is the primary management interface used to configure Windows enrollment, compliance, configuration profiles, applications, and device management.

Step 2 — Navigate to Windows Enrollment

From the Microsoft Intune admin center, navigate to the Windows enrollment section. Review the available enrollment configuration options before making changes.

Microsoft Intune admin center
    |
    +-- Devices
        |
        +-- Enrollment
            |
            +-- Windows

Step 3 — Review Windows Enrollment Settings

Review the Windows enrollment configuration and confirm that the tenant is configured for the organization's intended enrollment method.

Pay particular attention to enrollment restrictions, automatic enrollment, device platform settings, and user enrollment permissions.

Step 4 — Configure Automatic MDM Enrollment

Configure automatic MDM enrollment so that eligible Windows devices are automatically enrolled into Microsoft Intune when the appropriate Microsoft Entra enrollment event occurs.

The configuration should be scoped to the appropriate users or groups rather than automatically applying broad administrative permissions to the entire organization.

Step 5 — Configure Enrollment Restrictions

Review the enrollment restrictions that determine which device platforms and ownership types users are permitted to enroll.

For Windows environments, verify that Windows enrollment is permitted and that the configuration aligns with the organization's security and endpoint management policy.

Step 6 — Configure the Enrollment Device Platform

Verify that Windows devices are enabled under the applicable enrollment platform configuration. Review the minimum supported operating system version and any organization-specific restrictions.

Step 7 — Prepare the Windows Device

Start with a supported Windows device and connect it to the Internet. Sign in using the organizational account intended for enrollment.

For a new device, enrollment may occur during the Windows Out-of-Box Experience (OOBE). For an existing device, enrollment can be initiated through Windows account and access settings.

Step 8 — Connect the Windows Device to Microsoft Entra ID

During the enrollment process, authenticate using the organization's Microsoft Entra credentials. Complete any required authentication controls, including multifactor authentication if configured.

Step 9 — Confirm Device Management Enrollment

After authentication, Windows processes the applicable enrollment configuration. The device establishes a management relationship with Microsoft Intune.

Allow sufficient time for the device to complete initial enrollment and policy processing before beginning validation.

Step 10 — Verify Windows Work or School Account

On the Windows device, open the work or school account settings and verify that the organizational account is connected.

Settings
    |
    +-- Accounts
        |
        +-- Access work or school
            |
            +-- Organizational Account
                |
                +-- Connected

Step 11 — Verify Microsoft Entra Device Registration

Return to the Microsoft Entra admin center and locate the enrolled Windows device. Verify that the device appears in the organization's device inventory.

Review the device name, ownership information, operating system, registration state, and associated user information as applicable.

Step 12 — Verify the Device in Microsoft Intune

Open Microsoft Intune and navigate to the Windows device inventory. Locate the newly enrolled device and verify that it has been successfully added to Intune.

Step 13 — Review Device Properties

Open the device record and review the available management information. Confirm that the device contains the expected operating system, ownership, primary user, enrollment date, management state, and other applicable properties.

Step 14 — Confirm Policy Synchronization

Initiate a manual synchronization from the Windows device or Intune portal. This confirms that the device can communicate with the Intune management service and receive applicable configuration policies.

Step 15 — Verify Compliance and Configuration Policies

Review the device's assigned configuration and compliance policies. Confirm that the device is receiving the expected policies and that no enrollment-related errors are reported.

Step 16 — Verify Enrollment Status

The final enrollment validation should confirm that the device exists in both Microsoft Entra ID and Microsoft Intune and that the management relationship is operational.

Expected Result: The Windows device is successfully enrolled, registered with Microsoft Entra ID, visible in Microsoft Intune, and capable of receiving management policies.

5. Validation & Troubleshooting

  • Confirm the Windows device has Internet connectivity.
  • Confirm the user's Intune-capable license is active.
  • Confirm the user is included in the automatic enrollment scope.
  • Confirm Windows enrollment is permitted by enrollment restrictions.
  • Confirm the device appears in Microsoft Entra ID.
  • Confirm the device appears in Microsoft Intune.
  • Confirm the device has a valid management relationship.
  • Perform a manual device synchronization.
  • Review Intune device and enrollment logs for errors.
  • Review Microsoft Entra sign-in activity when authentication problems occur.

Common Enrollment Issues

Device does not appear in Intune:

Verify the user's enrollment scope, licensing, enrollment restrictions, and network connectivity. Allow additional time for initial synchronization before concluding that enrollment failed.

User cannot enroll the device:

Review enrollment restrictions and confirm that the user is permitted to enroll the Windows platform.

Device appears in Entra ID but not Intune:

Review automatic MDM enrollment configuration and confirm that the user is within the configured enrollment scope.

Policies are not applying:

Perform a manual synchronization and review the device's assigned policies. Confirm that the device and user are included in the appropriate policy assignments.

Tip: Capture screenshots during each major configuration stage. This creates an auditable deployment record and makes it significantly easier to troubleshoot enrollment issues after the deployment has been completed.

6. Escalation Path

  1. Level 1 — Help Desk: Confirm connectivity, user licensing, Windows version, account status, and basic enrollment configuration.
  2. Level 2 — Endpoint Administration: Review Intune enrollment restrictions, automatic enrollment scope, device records, policy assignments, and synchronization status.
  3. Level 3 — Identity Administration: Review Microsoft Entra device registration, authentication, Conditional Access, MFA, and sign-in activity.
  4. Level 4 — Microsoft Support: Escalate persistent tenant-level or service-level enrollment issues after collecting device identifiers, timestamps, error messages, enrollment logs, and screenshots.

7. Deployment Evidence Checklist

  • Microsoft Intune admin center configuration verified.
  • Windows enrollment configuration verified.
  • Automatic enrollment configuration verified.
  • Enrollment restrictions verified.
  • Windows device enrollment completed.
  • Microsoft Entra device registration verified.
  • Microsoft Intune device record verified.
  • Device synchronization completed.
  • Policy assignment verified.
  • Final successful enrollment state verified.
Deployment Completion Criteria: The Windows device enrollment is considered successful when the device is properly registered with Microsoft Entra ID, enrolled in Microsoft Intune, visible within the Intune device inventory, and capable of receiving the organization's management policies.

8. Final Validation

Perform a final review of the Microsoft Entra and Intune device records. Confirm that the device information is consistent across both platforms and that the expected management policies are being applied.