Skip to content

Commit 35adb65

Browse files
authored
Merge pull request #7024 from CarHern/patch-13
further clarifying min/max OS version scenarios
2 parents e4348f7 + 9f2620e commit 35adb65

1 file changed

Lines changed: 7 additions & 3 deletions

File tree

memdocs/intune/enrollment/enrollment-restrictions-set.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -141,9 +141,13 @@ Intune also blocks personal devices using these enrollment methods:
141141
- **Platform** (Android only): Select **Allow** next to permitted platforms.
142142
- **MDM** (Windows, macOS, and iOS/iPadOS): Select **Allow** next to permitted platforms.
143143
- **Allow min/max range** (Android, Windows, iOS/iPadOS only): Enter the minimum and maximum OS versions allowed to enroll. Supported version formats include:
144-
- Android device administrator and Android Enterprise work profile support major.minor.rev.build.
145-
- iOS/iPadOS supports major.minor.rev. Operating system versions don't apply to Apple devices that enroll with the Device Enrollment Program, Apple School Manager, or the Apple Configurator app.
146-
- Windows supports major.minor.build.rev for Windows 10 and Windows 11 only.
144+
- Windows supports major.minor.build.rev for Windows 10 and Windows 11 only.
145+
- Android device administrator and Android Enterprise work profile support major.minor.rev.build.
146+
- iOS/iPadOS supports major.minor.rev.
147+
148+
> [!TIP]
149+
> The min/max range isn't applicable to Apple devices that enroll with the Device Enrollment Program, Apple School Manager, or the Apple Configurator app. Although Intune doesn't block ADE enrollments that use Company Portal to authenticate, not meeting OS requirements impacts registration because devices can't create the Azure AD device record used to evaluate Conditional Access policies. You can tell that this is the case if a device user receives an error message that says "Couldn't map device record with a user" after they sign in to Company Portal.
150+
147151
- **Personally-owned**: Select **Allow** to permit devices to enroll and operate as personal devices.
148152
- **Device manufacturer**: Enter a comma-separated list of the manufacturers that you want to block.
149153

0 commit comments

Comments
 (0)