You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-android.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 02/03/2022
10
+
ms.date: 06/08/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -41,7 +41,9 @@ Personal and organization-owned devices can be enrolled in Intune. Once enrolled
41
41
42
42
This article provides recommendations on the Android enrollment methods. It also includes an overview of the administrator and user tasks for each enrollment type.
43
43
44
-
For more specific information, see [Enroll Android devices](../enrollment/android-enroll.md).
44
+
For more specific information, see [Enroll Android devices](../enrollment/android-enroll.md). There's also a visual guide of the different enrollment options for each platform:
45
+
46
+
[](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) <br/> [Download PDF version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) | [Download Visio version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.vsdx)
@@ -71,7 +73,7 @@ These devices are personal or BYOD (bring your own device) Android devices that
71
73
72
74
### Android Enterprise personally owned devices with a work profile administrator tasks
73
75
74
-
This task list provides an overview. For more specific information, see [Set up enrollment of Android Enterprise personally-owned work profile devices](../enrollment/android-work-profile-enroll.md).
76
+
This task list provides an overview. For more specific information, see [Set up enrollment of Android Enterprise personallyowned work profile devices](../enrollment/android-work-profile-enroll.md).
75
77
76
78
- Be sure your devices are [supported](supported-devices-browsers.md).
77
79
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, see [Connect your Intune account to your Managed Google Play account](../enrollment/connect-intune-android-enterprise.md).
-[BYOD: User and Device enrollment](#byod-user-and-device-enrollment)
38
38
39
-
This article provides recommendations on the iOS/iPadOS enrollment method to use. It also includes an overview of the administrator and user tasks for each enrollment type. For more specific information, see [Enroll iOS/iPadOS devices](../enrollment/ios-enroll.md).
39
+
This article provides recommendations on the iOS/iPadOS enrollment method to use. It also includes an overview of the administrator and user tasks for each enrollment type.
40
+
41
+
For more specific information, see [Enroll iOS/iPadOS devices](../enrollment/ios-enroll.md). There's also a visual guide of the different enrollment options for each platform:
42
+
43
+
[](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) <br/> [Download PDF version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) | [Download Visio version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.vsdx)
@@ -201,7 +205,7 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
201
205
202
206
2. Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete. The device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices.
203
207
204
-
At this point, the device isn't fully registered with Azure AD and shows as non-compliant in Azure AD. The device shows it is compliant in the Microsoft Endpoint Manager admin center.
208
+
At this point, the device isn't fully registered with Azure AD and shows as non-compliant in Azure AD. The device shows it's compliant in the Microsoft Endpoint Manager admin center.
205
209
206
210
3. If you **Install Company Portal app with VPP** (recommended), then the Company Portal app automatically installs. Users open the Company Portal app, and sign in with their work or school account (`[email protected]`) again. They complete Azure AD registration in the Company Portal app, which fully registers the device with Azure AD. Users then gain access to corporate resources protected by conditional access policies and the device shows as being compliant in Azure AD.
207
211
@@ -397,7 +401,7 @@ This task list provides an overview. For more specific information, see [Set up
397
401
398
402
- If you install apps before the user enrollment profile is applied, then these apps aren't protected or managed by the user enrollment profile.
399
403
400
-
For example, a user downloads the Outlook app from the Apple app store. The app automatically installs to the user partition on the device. The user configures Outlook for their personal email. When configuring their organization email, they're blocked by conditional access, and asked to enroll. They enroll, and a user enrollment profile deploys.
404
+
For example, a user downloads the Outlook app from the Apple app store. The app automatically installs to the user partition on the device. The user configures Outlook for their personal email. When users configure their organization email, they're blocked by conditional access, and asked to enroll. They enroll, and a user enrollment profile deploys.
401
405
402
406
Since the Outlook app was installed before the user enrollment profile, the user enrollment profile fails. The Outlook app can't be managed because it's installed and configured in the user partition, not the work partition. Users must manually uninstall the Outlook app.
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-macos.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 02/24/2022
10
+
ms.date: 06/08/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -44,7 +44,9 @@ This article:
44
44
- Provides recommendations on the macOS enrollment method to use.
45
45
- Includes an overview of the administrator and user tasks for each enrollment type.
46
46
47
-
For more specific information, see [Enroll macOS devices](../enrollment/macos-enroll.md).
47
+
For more specific information, see [Enroll macOS devices](../enrollment/macos-enroll.md). There's also a visual guide of the different enrollment options for each platform:
48
+
49
+
[](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) <br/> [Download PDF version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) | [Download Visio version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.vsdx)
@@ -162,7 +164,7 @@ This task list provides an overview. For more specific information, see [Automat
162
164
163
165
### ADE end user tasks
164
166
165
-
These tasks depend on how administrators tell users to install the Company Portal app. Typically, the less end users must do to enroll, the higher chance they'll want to enroll.
167
+
These tasks depend on how administrators tell users to install the Company Portal app. Typically, the fewer steps end users must do to enroll, the higher chance they'll want to enroll.
166
168
167
169
For more specific information on the end user steps, see [Enroll your macOS device using the Company Portal app](../user-help/enroll-your-device-in-intune-macos-cp.md).
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-windows.md
+13-9Lines changed: 13 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 03/10/2022
10
+
ms.date: 06/08/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -40,7 +40,11 @@ You have the following options when enrolling Windows devices:
40
40
-[Group policy](#group-policy)
41
41
-[Co-management](#co-management-enrollment)
42
42
43
-
This article provides recommendations on the Windows enrollment method to use. It also includes an overview of the administrator and user tasks for each enrollment type. For more specific information, see [Enroll Windows devices](../enrollment/windows-enrollment-methods.md).
43
+
This article provides recommendations on the Windows enrollment method to use. It also includes an overview of the administrator and user tasks for each enrollment type.
44
+
45
+
For more specific information, see [Enroll Windows devices](../enrollment/windows-enrollment-methods.md). There's also a visual guide of the different enrollment options for each platform:
46
+
47
+
[](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) <br/> [Download PDF version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.pdf) | [Download Visio version](https://download.microsoft.com/download/e/6/2/e6233fdd-a956-4f77-93a5-1aa254ee2917/msft-intune-enrollment-options.vsdx)
@@ -69,7 +73,7 @@ You can also use this enrollment method to automatically bulk enroll devices wit
69
73
| Devices are personal or BYOD. | ✔️ |
70
74
| Devices are owned by the organization or school. | ✔️ |
71
75
| You have new or existing devices. | ✔️ |
72
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ <br/><br/> Bulk enrollment is available for organization-owned devices, not personal/BYOD.|
76
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ <br/><br/> Bulk enrollment is available for organization-owned devices, not personal/BYOD.|
73
77
| Devices are associated with a single user. | ✔️ |
74
78
| Devices are user-less, such as kiosk, dedicated. or shared device. | ✔️ <br/><br/> These devices are organization-owned. This enrollment method requires users to sign in with their organization account. An organization admin can sign in, and automatically enroll. When the device is enrolled, create a [kiosk](../configuration/kiosk-settings.md) profile, and assign this profile to this device. You can also create a profile for [devices shared with many users](../configuration/shared-user-device-settings.md). |
75
79
| You use the optional device enrollment manager (DEM) account. | ✔️ |
@@ -165,7 +169,7 @@ For more information on Windows Autopilot, see [Windows Autopilot overview](../.
165
169
| You have remote workers. | ✔️ <br/><br/> The OEM or partner can send devices directly to your users.|
166
170
| Devices are owned by the organization or school. | ✔️ |
167
171
| You have new or existing devices. | ✔️ <br/><br/> You can update existing desktops running older Windows versions, such as Windows 7, to Windows 10. This option also uses Microsoft Endpoint Configuration Manager. |
168
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
172
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
169
173
| You have Azure AD Premium. | ✔️ <br/><br/> Windows Autopilot uses Automatic enrollment. Automatic enrollment requires Azure AD Premium. |
170
174
| Devices are associated with a single user. | ✔️ |
171
175
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ <br/><br/> These devices are organization-owned. This enrollment method requires users to sign in with their organization account. An organization admin can sign in, and automatically enroll. When the device is enrolled, create a [kiosk](../configuration/kiosk-settings.md) profile, and assign this profile to this device. You can also create a profile for [devices shared with many users](../configuration/shared-user-device-settings.md). |
@@ -245,7 +249,7 @@ With User enrollment, you can "register" the devices with Azure AD or "join" the
245
249
| Devices are personal or BYOD. | ✔️ |
246
250
| Devices are owned by the organization or school. | ✔️ <br/><br/> You can use User enrollment, but it's recommended to use [Windows Autopilot](#windows-autopilot) (in this article) or [Windows Automatic enrollment](#windows-automatic-enrollment) (in this article). They require fewer steps for your users. |
247
251
| You have new or existing devices. | ✔️ |
248
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
252
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
249
253
| Devices are associated with a single user. | ✔️ |
250
254
| Devices are user-less, such as kiosk, dedicated. or shared device. | ❌ <br/><br/> The user enrollment options require a user to sign in with an organization account, and use the Settings app, which isn’t common on shared devices. |
251
255
| You use the device enrollment manager (DEM) account. | ❌ <br/><br/> DEM accounts don't apply to User enrollment. |
@@ -277,7 +281,7 @@ Other than having Intune setup, there are minimal administrator tasks with this
277
281
278
282
Clearly communicate the options users should choose on personal and organization-owned devices. For more information on the end user experience, see [enroll Windows client devices](../user-help/enroll-windows-10-device.md).
279
283
280
-
-**BYOD or personal devices**: These are probably existing devices that are already configured with a personal email account (`[email protected]`). Users must register the device using the Settings app:
284
+
-**BYOD or personal devices**: These devices are probably existing devices that are already configured with a personal email account (`[email protected]`). Users must register the device using the Settings app:
281
285
282
286
1. Connect the device to the internet.
283
287
@@ -297,7 +301,7 @@ Clearly communicate the options users should choose on personal and organization
297
301
298
302
If you want to manage BYOD or personal devices, be sure users select **Join this device to Azure Active Directory**. Users should also know that their personal devices will be managed by their IT.
299
303
300
-
-**Organization-owned devices**: These can be existing devices or new devices. If new devices, users turn on the device, step through the out-of-box experience (OOBE), and sign in with their organization account (`[email protected]`). This step joins the device in Azure AD, and the device is considered organization-owned. The device is fully managed, regardless of who's signed in. Users can open the **Settings** app > **Accounts** > **Access work or school**. It shows they're connected.
304
+
-**Organization-owned devices**: These devices can be existing devices or new devices. If new devices, users turn on the device, step through the out-of-box experience (OOBE), and sign in with their organization account (`[email protected]`). This step joins the device in Azure AD, and the device is considered organization-owned. The device is fully managed, regardless of who's signed in. Users can open the **Settings** app > **Accounts** > **Access work or school**. It shows they're connected.
301
305
302
306
For existing devices, or if users sign in with a personal account during the OOBE, they can join the devices to Azure AD using the following steps:
303
307
@@ -327,7 +331,7 @@ For more specific information, see [Enroll a Windows client device automatically
327
331
| You have remote workers. | ✔️ |
328
332
| Devices are owned by the organization or school. | ✔️ |
329
333
| You have new or existing devices. | ✔️ |
330
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
334
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
331
335
| Devices are associated with a single user. | ✔️ |
332
336
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ <br/><br/> These devices are organization-owned. This enrollment method requires users to sign in with their organization account. An organization administrator can sign in, and automatically enroll. When the device is enrolled, create a [kiosk](../configuration/kiosk-settings.md) profile, and assign this profile to this device. You can also create a profile for [devices shared with many users](../configuration/shared-user-device-settings.md). |
333
337
| Devices are personal or BYOD. | ❌ <br/><br/> For BYOD or personal devices, use [Windows automatic enrollment](#windows-automatic-enrollment) (in this article) or a [User enrollment option](#byod-user-enrollment) (in this article). |
@@ -371,7 +375,7 @@ For more specific information on co-management, see [What is co-management?](../
371
375
| Devices are owned by the organization or school. | ✔️ |
372
376
| Devices are personal or BYOD. | ✔️ |
373
377
| You have new or existing devices. | ✔️ <br/><br/> For devices that aren't running Windows 10/11, such as Windows 7, you'll need to upgrade. For more specific information, see [Upgrade Windows 10 for co-management](../../configmgr/comanage/quickstart-upgrade-win10.md). |
374
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
378
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
375
379
| Devices are associated with a single user. | ✔️ |
376
380
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ <br/><br/> These devices are organization-owned. This enrollment method requires users to sign in with their organization account. An organization admin can sign in, and automatically enroll. When the device is enrolled, create a [kiosk](../configuration/kiosk-settings.md) profile, and assign this profile to this device. You can also create a profile for [devices shared with many users](../configuration/shared-user-device-settings.md). |
377
381
| Devices are managed by another MDM provider. | ❌ <br/><br/> To be co-managed, users need to unenroll from the current MDM provider. They shouldn't be enrolled using the Intune classic agents. |
0 commit comments