Enroll devices using Intune Flashcards
What are the four stages of the MDM lifecycle?
Enrol, Configure, Protect, Retire
What must be configured in the ‘Device Enrolment’ section of Intune before devices can enroll?
The MDM authority
Which device types is Intune configured to allow by default?
Windows, Android, and standard Samsung Knox devices
What do iOS and MacOS devices require to be set up in Intune before enrolment can occur?
Apple MDM Push Certificate
What does CSR stand for and what does it do?
Certificate Signing Request
File downloaded from Intune and uploaded to the Apple Certificate Portal
What requirements must a user meet in order to generate a certificate file in the Apple Certificate Portal?
An Apple ID that is a member of the Apple Developer Program
For Windows devices already joined to on-prem AD-DS, how can you automatically enroll them in MDM?
Using Group Policy
What are the manual methods of enrolling Windows devices in MDM?
-Settings app
-Provisioning Packages
-Company Portal app
True or false: automatic enrolment in MDM only works for Windows devices
True
Why does automatic enrolment in MDM only work for Windows devices?
Only Windows devices can be joined to on-prem AD-DS or Entra ID.
What is automatic enrolment for Windows devices?
Devices automatically enrol in MDM when they join or register with Entra ID
What Entra ID license is required for automatic MDM enrollment
Entra ID P1/P2
What does WIP stand for?
Windows Information Protection
True or false: MFA is enabled for automatic enrolment by default
False
What is the earliest Android version Intune supports for device enrolment?
8.0
What is the earliest iOS version Intune supports for device enrolment?
14.0
What is the earliest MacOS version Intune supports through device enrolment?
11.0
True or false: all users with an Intune license are allowed to enrol supported devices by default
True
What Enrolment Restrictions can be configured to allow/deny enrolment for certain devices?
-Maximum number of enrolled devices for a user
-Device platform
-Required OS version
-Restrict enrolment of personally owned devices
What is the default maximum number of enrolled devices for a user?
5
What are the supported Corporate Identifiers you can upload to specify company-owned devices?
Serial number & IMEI
What action would you take in Intune to only allow enrolled devices to access company resources?
Conditional access policy
What is the difference between a Compliance Policy and a Conditional Access Policy?
Compliance Policy - defines the configuration required to be considered compliant
Conditional Access Policy - controls access to company resources (can be based on Compliance Policies).
What Group Policy would you use to MDM-enrol devices joined to an on-prem AD-DS which is synced to Entra?
‘Enable automatic MDM enrolment using default Entra credentials’
Why is it recommended not to use the .onmicrosoft.com domain?
Using a custom domain lets users sign in with the credentials they use to access other domain resources.
Where in the Intune portal can you configure Automatic enrolment?
Devices -> Enroll Devices -> Automatic enrollment
What enrolment method can be used if you don’t have Entra ID P1/P2?
CNAME enrolment