You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/device-enrollment-manager-enroll.md
+59-34Lines changed: 59 additions & 34 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ keywords:
8
8
author: Lenewsad
9
9
ms.author: lanewsad
10
10
manager: dougeby
11
-
ms.date: 07/02/2021
11
+
ms.date: 05/10/2022
12
12
ms.topic: how-to
13
13
ms.service: microsoft-intune
14
14
ms.subservice: enrollment
@@ -31,38 +31,71 @@ ms.collection:
31
31
- highpri
32
32
---
33
33
34
-
# Enroll devices in Intune by using a device enrollment manager account
34
+
# Add device enrollment managers
35
35
36
-
You can enroll up to 1,000 devices in total with a single Azure Active Directory account by using a device enrollment manager (DEM) account. DEM is an Intune permission that can be applied to an Azure AD user account and lets the user enroll up to 1,000 devices. A DEM account is useful for scenarios where devices are enrolled and prepared before handing them out to the users of the devices. By design, there's a limit of 150 active DEM accounts in Microsoft Intune.
36
+
A device enrollment manager (DEM) is a non-administrator user who can enroll devices in Intune. Device enrollment managers are useful to have when you need to enroll and prepare many devices for distribution. People signed in to a DEM account can enroll and manage up to 1,000 devices, while a standard non-admin account can only enroll 15.
37
37
38
-
## Limitations of devices that are enrolled with a DEM account
38
+
A DEM account requires an Intune user or device license, and an associated Azure AD user. Global Administrators and Intune Service Administrators can add and manage device enrollment managers in the Microsoft Endpoint Manager admin center.
39
39
40
-
DEM user accounts and devices that are enrolled with a DEM user account have the following limitations:
40
+
This article describes the limits and specifications of enrollment manager and how to manage permissions.
41
41
42
-
- A DEM account user must be assigned an Intune license.
43
-
- Wipe can't be done from the Company Portal. Wiping a device enrolled by a DEM user account can be done from the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
44
-
- Only the local device appears in the Company Portal app or website.
45
-
- DEM user accounts cannot use Apple Volume Purchase Program (VPP) apps with Apple VPP user licenses because of per-user Apple ID requirements for app management.
46
-
- Microsoft Intune does not support the use of DEM accounts when enrolling devices via Apple Automated Device Enrollment (ADE).
47
-
- DEM accounts cannot support conditional access because conditional access is intended for per-user scenarios.
48
-
- Devices can install VPP apps if they have Apple VPP device licenses.
49
-
- Every device enrolled with DEM accounts needs to be properly licensed to be managed by Intune. The license could be an Intune user license or an Intune device license.
50
-
- If you're [enrolling Android Enterprise personally-owned devices with work profile](android-work-profile-enroll.md) using a DEM account, there is a limit of 10 devices that can be enrolled per account.
51
-
-[Enrolling Android Enterprise fully managed devices](android-fully-managed-enroll.md) with DEM accounts isn't supported.
52
-
-[Enrolling Android Enterprise corporate owned work profile devices](android-corporate-owned-work-profile-enroll.md) with DEM accounts isn't supported.
53
-
- Applying an Azure AD device restriction to a DEM account will prevent you from reaching the 1,000 device limit that the DEM account can enroll.
42
+
## Supported enrollment methods
54
43
55
-
>[!NOTE]
56
-
>For additional details regarding enrollment capabilities for Windows and the use of DEM accounts, please refer [Intune enrollment method capabilities for Windows devices](./enrollment-method-capab.md).
57
-
58
-
## Enrollment methods supported by DEM accounts
59
-
60
-
You can use the following methods to enroll devices using DEM accounts:
44
+
A device enrollment manager can use the following methods to enroll devices in Intune:
> To compare DEM best practices and capabilities alongside other Windows enrollment methods, see [Intune enrollment method capabilities for Windows devices](./enrollment-method-capab.md).
53
+
54
+
55
+
## Account permissions
56
+
57
+
These Azure AD roles can manage device enrollment managers:
58
+
59
+
* Global Administrator
60
+
* Intune Service Administrator role in Azure AD
61
+
62
+
They can add and delete device enrollment managers, and view all DEM users in the Microsoft Endpoint Manager admin center.
63
+
64
+
## Limitations
65
+
66
+
The device enrollment manager account can't be used with all features in Microsoft Intune and has some limitations when used with others. This section describes the limitations you could encounter while setting up devices from a DEM account.
67
+
68
+
### Android Enterprise
69
+
You can enroll up to 10 personally owned devices with work profiles.
70
+
71
+
The following types of Android Enterprise devices can't be set up via DEM:
72
+
73
+
* Corporate-owned with a work profile
74
+
* Fully managed
75
+
76
+
### Apple Automated Device Enrollment
77
+
DEM isn't compatible with Apple Automated Device Enrollment (ADE).
78
+
79
+
### Apple volume purchased apps
80
+
DEM-enrolled devices can install VPP apps if they have Apple VPP device licenses. You can't use apps purchased through Apple VPP with Apple VPP user licenses, because of per-user Apple ID requirements for app management.
81
+
82
+
### Azure AD
83
+
Applying an Azure AD device restriction to a DEM account will prevent you from reaching the 1,000 device limit that the DEM account can enroll.
84
+
85
+
### Conditional access
86
+
Conditional access is only supported with DEM on devices running:
87
+
88
+
* Windows 10, version 1803 and later
89
+
* Windows 11
90
+
91
+
### Device limit restrictions
92
+
DEM enrolls Windows 10/11 devices in shared device mode, so device limit restrictions won't work on them. Instead, you can configure a hard limit for these devices in the Azure AD admin center. For more information, see [Manage device identities by using the Azure portal](/azure/active-directory/devices/device-management-azure-portal#configure-device-settings).
93
+
94
+
### Intune Company Portal
95
+
Only the local device appears in the Company Portal app or Company Portal website. Device users can't wipe DEM-enrolled devices from Company Portal. You have to sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) to wipe these devices.
96
+
97
+
### Number of accounts
98
+
There's a limit of 150 DEM accounts in Microsoft Intune.
66
99
67
100
## Add a device enrollment manager
68
101
@@ -72,14 +105,6 @@ You can use the following methods to enroll devices using DEM accounts:
72
105
73
106
3. On the **Add User** blade, enter a user principal name for the DEM user, and select **Add**. The DEM user is added to the list of DEM users.
74
107
75
-
## Permissions required to create DEM accounts
76
-
77
-
Global Administrator or Intune Service Administrator Azure AD roles are required to
78
-
79
-
- Assign DEM permission to an Azure AD user account
80
-
- See all DEM users
81
-
82
-
If a user doesn't have the Global Administrator or Intune Service Administrator role assigned to them, but has read permissions enabled for the Device Enrollment Managers role assigned to them, they can see only the DEM users they've created.
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/windows-enrollment-methods.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@
3
3
4
4
title: Intune enrollment methods for Windows devices
5
5
titleSuffix: Microsoft Intune
6
-
description: Learn the different ways you can enroll Windows devices in Intune
6
+
description: Learn the different ways you can enroll Windows devices in Intune.
7
7
keywords:
8
8
author: Lenewsad
9
9
ms.author: lanewsad
@@ -70,7 +70,7 @@ Administrators can set up the following methods of enrollment that require no us
70
70
71
71
-[Hybrid Azure AD Join](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy) lets administrators configure Active Directory group policy to automatically enroll devices that are hybrid Azure AD joined.
72
72
-[Configuration Manager Co-management](/configmgr/comanage/overview) lets administrators enroll their existing Configuration Manager managed devices into Intune to get the dual benefits of Intune and Configuration Manager.
73
-
-[Device enrollment manager](device-enrollment-manager-enroll.md) (DEM) is a special service account. DEM accounts have permissions that let authorized users enroll and manage multiple corporate-owned devices. These types of devices are good for point-of-sale or utility apps, for example, but not for users who need to access email or company resources. Be aware that there are some limitations with DEM accounts as documented [here](./device-enrollment-manager-enroll.md#limitations-of-devices-that-are-enrolled-with-a-dem-account).
73
+
-[Device enrollment manager](device-enrollment-manager-enroll.md) (DEM) is a special service account. DEM accounts have permissions that let authorized users enroll and manage multiple corporate-owned devices. These types of devices are good for point-of-sale or utility apps, for example, but not for users who need to access email or company resources. Be aware that there are some limitations with DEM accounts as documented [here](./device-enrollment-manager-enroll.md#limitations).
74
74
-[Bulk enroll](windows-bulk-enroll.md) lets an authorized user join large numbers of new corporate-owned devices to Azure Active Directory and Intune. You create a provisioning package with the Windows Configuration Designer (WCD) app. Then, using USB media during initial Windows OOBE experience or from existing Windows PC, you install the provisioning package to automatically enroll the devices into Intune.
75
75
-[Enrolling Windows IoT Core devices](/windows/iot-core/manage-your-device/intunedeviceenrollment) is accomplished by using the Windows IoT Core Dashboard to prepare the device, and then using Windows Configuration Designer to create a provisioning package. Then, using SD Card media during initial boot up, it installs the provisioning package to automatically enroll the devices into Intune.
Copy file name to clipboardExpand all lines: memdocs/intune/user-help/sync-your-device-manually-macos.md
+10-6Lines changed: 10 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,12 +2,12 @@
2
2
# required metadata
3
3
4
4
title: Manually sync your macOS device with Intune Company Portal
5
-
description: Sync your Mac from the Intune Company Portal to get the latest updates and requirements from your organization.
5
+
description: Sync your personal Mac from the Intune Company Portal to get the latest updates and requirements from your organization.
6
6
keywords:
7
7
author: lenewsad
8
8
ms.author: lanewsad
9
9
manager: dougeby
10
-
ms.date: 02/16/2021
10
+
ms.date: 05/31/2022
11
11
ms.topic: end-user-help
12
12
ms.prod:
13
13
ms.service: microsoft-intune
@@ -32,13 +32,15 @@ ms.collection:
32
32
33
33
# Manually sync macOS device with Intune
34
34
35
-
A manual sync forces your device to connect with Intune to get the latest updates, requirements, and communications from your organization. Company Portal regularly syncs devices as long as you have a Wi-Fi connection. However, if you ever need to disconnect for an extended period of time, the sync feature ensures that you can get any updates you missed when you return.
35
+
You can force your personal Mac to sync with Intune for the latest updates, requirements, and communications from your organization. The Intune Company Portal app regularly syncs devices when they're connected to Wi-Fi. However, if you ever need to disconnect for an extended period of time, you can use the Company Portal sync feature to reconnect and bring your device up-to-date.
36
36
37
37
Syncing can also help resolve work-related downloads or other processes that are in progress or stalled. If you're experiencing slow or unusual behavior while installing or using a work app, try syncing your device to see if an update or requirement is missing.
38
38
39
-
## Sync device
39
+
The sync feature is not available on corporate-owned devices. Contact your support person for help with syncing a corporate-owned Mac.
40
40
41
-
To force a sync:
41
+
## Sync personal Mac
42
+
43
+
To force a sync on your personal Mac:
42
44
43
45
1. Open the Company Portal app.
44
46
@@ -56,5 +58,7 @@ Syncing can also help resolve work-related downloads or other processes that are
56
58

57
59
58
60
## Next steps
59
-
Once you've completed these steps, check to see if your initial problem is resolved. If it's not, it may help to restart the stalled installation or task. Still need help? Contact your company support. For contact information, check the [Company Portal website](https://go.microsoft.com/fwlink/?linkid=2010980).
61
+
Once you've completed these steps, check to see if your initial problem is resolved. If it's not, it may help to restart the stalled installation or task.
62
+
63
+
Still need help? Contact your support person. Sign in to the [Company Portal website](https://go.microsoft.com/fwlink/?linkid=2010980) for your organization's contact information.
0 commit comments