Skip to content

Commit 2e17f55

Browse files
authored
Update device-enrollment-manager-enroll.md
DEM updates per GitHub issue
1 parent c1756de commit 2e17f55

1 file changed

Lines changed: 60 additions & 33 deletions

File tree

memdocs/intune/enrollment/device-enrollment-manager-enroll.md

Lines changed: 60 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -31,38 +31,73 @@ ms.collection:
3131
- highpri
3232
---
3333

34-
# Enroll devices in Intune by using a device enrollment manager account
34+
# Add device enrollment managers
3535

36-
You can enroll up to 1,000 devices with a single Azure Active Directory account by using a device enrollment manager (DEM) account. DEM is an Intune permission that can be applied to an Azure AD user account and lets the user enroll up to 1,000 devices. A DEM account is useful for scenarios where devices are enrolled and prepared before handing them out to the users of the devices. By design, there's a limit of 150 Device Enrollment Manager (DEM) accounts in Microsoft Intune.
36+
A device enrollment manager is a non-administrator user who can enroll devices in Intune. DEMS are useful to have when you need to enroll and prepare devices before handing them out to . DEM users can enroll up to 1,000 devices, while a standard non-admin account in Intune can only enroll 15.
3737

38-
## Limitations of devices that are enrolled with a DEM account
38+
A DEM account requires an Intune user or device license. To enable the feature for someone in you organization, you must assign the Intune device enrollment manager permissions to their Azure AD account. This article provides an overview of device enrollment manager accounts, limitations, and how to manage permissions.
3939

40-
DEM user accounts and devices that are enrolled with a DEM user account have the following limitations:
40+
## Supported enrollment methods
4141

42-
- A DEM account user must be assigned an Intune license.
43-
- Wipe can't be done from the Company Portal. Wiping a device enrolled by a DEM user account can be done from the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
44-
- Only the local device appears in the Company Portal app or website.
45-
- DEM user accounts cannot use Apple Volume Purchase Program (VPP) apps with Apple VPP user licenses because of per-user Apple ID requirements for app management.
46-
- Microsoft Intune does not support the use of DEM accounts when enrolling devices via Apple Automated Device Enrollment (ADE).
47-
- DEM accounts cannot support conditional access because conditional access is intended for per-user scenarios.
48-
- Devices can install VPP apps if they have Apple VPP device licenses.
49-
- Every device enrolled with DEM accounts needs to be properly licensed to be managed by Intune. The license could be an Intune user license or an Intune device license.
50-
- If you're [enrolling Android Enterprise personally-owned devices with work profile](android-work-profile-enroll.md) using a DEM account, there is a limit of 10 devices that can be enrolled per account.
51-
- [Enrolling Android Enterprise fully managed devices](android-fully-managed-enroll.md) with DEM accounts isn't supported.
52-
- [Enrolling Android Enterprise corporate owned work profile devices](android-corporate-owned-work-profile-enroll.md) with DEM accounts isn't supported.
53-
- Applying an Azure AD device restriction to a DEM account will prevent you from reaching the 1,000 device limit that the DEM account can enroll.
54-
55-
>[!NOTE]
56-
>For additional details regarding enrollment capabilities for Windows and the use of DEM accounts, please refer [Intune enrollment method capabilities for Windows devices](./enrollment-method-capab.md).
57-
58-
## Enrollment methods supported by DEM accounts
59-
60-
You can use the following methods to enroll devices using DEM accounts:
42+
A device enrollment manager can use the following methods to enroll devices in Intune:
6143

6244
- [Windows Autopilot](../../autopilot/enrollment-autopilot.md)
6345
- [Windows devices bulk enrollment](windows-bulk-enroll.md)
6446
- DEM initiated via Company Portal
65-
- DEM initiated via Azure AD join
47+
- DEM initiated via Azure AD join
48+
49+
> [!TIP]
50+
> To compare DEM best practices and capabilities alongside other Windows enrollment methods, see [Intune enrollment method capabilities for Windows devices](./enrollment-method-capab.md).
51+
52+
53+
## Account permissions
54+
55+
Users assigned the Global Administrator or Intune Service Administrator role in Azure AD can:
56+
57+
- Assign DEM permissions
58+
- See all DEM users in the admin center
59+
60+
DEMs assigned read-only permissions in Azure AD can only see the DEM users they've created.
61+
62+
## Limitations
63+
64+
This section describes the limitations that comes with enrolling devices from your DEM account.
65+
66+
### Android Enterprise
67+
You can enroll up to 10 personally-owned devices with work profiles.
68+
69+
The following types of devices can't be set up with a DEM account:
70+
71+
* Corporate-owned with a work profile
72+
* Fully managed
73+
74+
### Automated Device Enrollment
75+
DEM is not compatible with Apple Automated Device Enrollment (ADE).
76+
77+
### Azure AD
78+
Applying an Azure AD device restriction to a DEM account will prevent you from reaching the 1,000 device limit that the DEM account can enroll.
79+
80+
### Conditional access
81+
Conditional access is only supported with DEM on devices running:
82+
83+
* Windows 10, version 1803 and later
84+
* Windows 11
85+
86+
### Device limit restrictions
87+
DEM enrolls Windows 10/11 devices in shared device mode, so device limit restrictions won't work on them. Instead, you can configure a hard limit for these devices in the Azure AD admin center. For more information, see [Manage device identities by using the Azure portal](/azure/active-directory/devices/device-management-azure-portal#configure-device-settings).
88+
89+
### Device wipe
90+
Enrolled devices can't be wiped from Company Portal. You have to sign in to [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) to wipe a device you enrolled.
91+
92+
### Intune Company Portal
93+
Only the local device appears in the Company Portal app or Company Portal website.
94+
95+
### Number of accounts
96+
There's a limit of 150 Device Enrollment Manager (DEM) accounts in Microsoft Intune.
97+
98+
### Volume purchased apps
99+
* You can't use apps purchased through Apple VPP with Apple VPP user licenses, because of per-user Apple ID requirements for app management.
100+
* Devices can install VPP apps if they have Apple VPP device licenses.
66101

67102
## Add a device enrollment manager
68103

@@ -72,14 +107,6 @@ You can use the following methods to enroll devices using DEM accounts:
72107

73108
3. On the **Add User** blade, enter a user principal name for the DEM user, and select **Add**. The DEM user is added to the list of DEM users.
74109

75-
## Permissions required to create DEM accounts
76-
77-
Global Administrator or Intune Service Administrator Azure AD roles are required to
78-
79-
- Assign DEM permission to an Azure AD user account
80-
- See all DEM users
81-
82-
If a user doesn't have the Global Administrator or Intune Service Administrator role assigned to them, but has read permissions enabled for the Device Enrollment Managers role assigned to them, they can see only the DEM users they've created.
83110

84111
## Remove device enrollment manager permissions
85112

@@ -88,4 +115,4 @@ Removing a device enrollment manager doesn't affect enrolled devices.
88115
### To remove a device enrollment manager
89116

90117
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), choose **Devices** > **Enroll devices** > **Device enrollment managers**.
91-
2. On the **Device enrollment managers** blade, select the DEM user, and select **Delete**.
118+
2. On the **Device enrollment managers** blade, select the DEM user, and select **Delete**.

0 commit comments

Comments
 (0)