Enroll devices using Microsoft Intune - Explore device enrollment manager Flashcards
What is a Device Enrollment Manager (DEM) account?
A special user account that can enroll up to 1,000 devices in Intune
The DEM account is useful for scenarios where devices are enrolled and prepared before handing them out to users.
What is the maximum number of devices a DEM account can enroll?
1,000 devices
What must users have in order to be added as device enrollment managers?
They must exist in the Azure portal
What are the 8 limitation of devices enrolled with a DEM account?
- No per-user access. Because devices don’t have an assigned user, the device has no email or company data access. VPN configurations, for example, could still be used to provide device apps with access to data.
- The DEM user can’t unenroll DEM-enrolled devices on the device itself by using the Company Portal. The Intune admin can unenroll.
- Only the local device appears in the Company Portal app or website.
- Users can’t use Apple Volume Purchase Program (VPP) apps with user licenses because of per-user Apple ID requirements for app management.
- (iOS only) If you use DEM to enroll iOS devices, you can’t use the Apple Configurator, Apple Device Enrollment Program (DEP), or Apple School Manager (ASM) to enroll devices. This means that you can’t put the device in supervised mode and thus won’t have access to some configuration options.
- (Android only) There’s a limit to the number of Android work profile devices that can be enrolled with a single DEM account. **Up to 10 Android work profile devices may be enrolled per DEM account. **This limitation doesn’t apply to legacy Android enrollment.
- Devices can install VPP apps if they have device licenses.
- An Intune device license isn’t required to use DEM.
True or False: A DEM user can unenroll DEM-enrolled devices on the device itself.
False
What type of devices can a DEM user enroll?
Shared devices
What happens if a user requires individual configuration such as e-mail profiles?
The user should enroll the device themselves
What is required for optimal security regarding the DEM user?
The DEM user shouldn’t also be an Intune admin
Which enrollment methods cannot be used with DEM?
- Apple Configurator with Setup Assistant
- Apple Configurator with direct enrollment
- Apple School Manager (ASM)
- Device Enrollment Program (DEP)
Describe a scenario where a DEM might be used.
A restaurant provides 50 point-of-sale tablets for staff, with the supervisor using a DEM account to enroll them
What can a DEM user do?
- Enroll up to 1000 devices in Intune
- Sign in to the Company Portal to get company apps
- Configure access to company data by deploying role-specific apps
What is a limitation specific to iOS devices enrolled with a DEM account?
You can’t use Apple Configurator, DEP, or ASM to enroll devices
What is a limitation specific to Android devices enrolled with a DEM account?
Up to 10 Android work profile devices may be enrolled per DEM account
3 steps
What is required to add a device enrollment manager?
- Sign in to Microsoft Intune admin center
- In the left navigation, select Devices - Enroll devices - Device enrollment managers.
- Select Add. On the Add User panel, enter a user principal name for the DEM user, and select Add.
The DEM user is added to the list of DEM users.
What roles are required for completing tasks related to DEM enrollment?
Global or Intune Service Administrator Microsoft Entra roles
What can users without Global Administrator or Intune Service Administrator roles do?
Access only the DEM users they created
Fill in the blank: A DEM account is useful for scenarios where devices are _______.
[enrolled and prepared before handing them out to users]
A retailer wants to provide 25 tablets to floor staff to capture orders and complete card transactions. The Intune admin creates a new Device Enrollment Manager (DEM) account for the restaurant supervisor.
What functionality does the DEM user account have?
- Enroll in Intune, access email, and configure access to company data
- Enroll in Intune, unenroll in Intune, get company applications, and configures access to company data by deploying role-specific applications
- Enroll in Intune, get company applications, and configure access to company data by deploying role-specific applications
Enroll in Intune, get company applications, and configure access to company data by deploying role-specific applications
You must have Intune admin role assigned to unenroll in Intune