|
3 | 3 |
|
4 | 4 | title: Overview of enrollment restrictions |
5 | 5 | titleSuffix: Microsoft Intune |
6 | | -description: Learn about |
| 6 | +description: Learn about the enrollment restrictions available in Microsoft Intune. |
7 | 7 | keywords: |
8 | 8 | author: Lenewsad |
9 | 9 | ms.author: lanewsad |
@@ -45,66 +45,64 @@ ms.collection: |
45 | 45 |
|
46 | 46 | Device enrollment restrictions let you restrict enrollment based on device attributes. When restrictions are applied, users on restricted devices or who exceed the device limit are blocked from enrolling in Microsoft Intune. There are two types of device enrollment restrictions you can configure in Microsoft Intune: |
47 | 47 |
|
48 | | -* *Device platform enrollment restrictions* define which platforms, versions, and management types can enroll. In Intune, you can restrict device platforms, OS versions, manufacturer, and personally owned devices. |
49 | | -* *Device limit enrollment restrictions* define how many devices each user can enroll. |
| 48 | +* *Device platform restrictions* define which platforms, versions, and management types can enroll. In Intune, you can restrict device platforms, OS versions, manufacturer, and personally owned devices. |
| 49 | +* *Device limit restrictions* define how many devices each user can enroll. |
50 | 50 |
|
51 | 51 | Each restriction type comes with one default policy that you can edit and customize as needed. Intune applies the default to all user and userless enrollments until you assign a higher-priority policy. |
52 | 52 |
|
53 | | -This article provides an overview of the available enrollment restrictions. When you're ready to create an enrollment restriction policy, see [Next steps](enrollment-restrictions-set.md)(in this article). |
| 53 | +This article provides an overview of the available enrollment restrictions. When you're ready to create an enrollment restriction policy, see [Next steps](enrollment-restrictions-set.md) (in this article). |
54 | 54 |
|
55 | 55 | ## Available restrictions |
56 | 56 | You can configure the following restrictions in the admin center: |
57 | 57 |
|
| 58 | +* Device limit |
58 | 59 | * Device platform |
59 | 60 | * OS version |
60 | 61 | * Device manufacturer |
61 | | -* Device ownership |
62 | | -* Device limit |
| 62 | +* Device ownership (personally-owned devices) |
63 | 63 |
|
64 | | -### Platform |
65 | | -This restriction blocks devices running on specific device platforms. You can apply this restriction to devices running: |
| 64 | +### Device limit |
| 65 | +Put a limit on the number of devices a person can enroll. You can set the device limit from 1 to 15. |
| 66 | + |
| 67 | +This configuration is in the admin center under **Enrollment device limit restrictions**. |
| 68 | + |
| 69 | +### Device platform |
| 70 | +Block devices running on a specific device platform. You can apply this restriction to devices running: |
66 | 71 |
|
67 | 72 | * Android device administrator |
68 | 73 | * Android Enterprise work profile |
69 | 74 | * iOS/iPadOS |
70 | 75 | * macOS |
71 | | - * Windows |
| 76 | + * Windows 10/11 |
72 | 77 |
|
73 | 78 | In groups where both Android platforms are allowed, devices that support work profile will enroll with a work profile. Devices that don't support work profile will enroll on the Android device administrator platform. Neither work profile nor device administrator enrollment will work until you complete all prerequisites for Android enrollment. |
74 | 79 |
|
75 | | -This configuration is in the admin center under **Enrollment device platform restrictions**. |
| 80 | +This restriction is in the admin center under **Enrollment device platform restrictions**. |
76 | 81 |
|
77 | 82 | ### OS version |
78 | | -This restriction enforces your maximum and minimum OS version requirements. Devices running earlier or later OS versions aren't allowed to enroll. This type of restriction works with the following operating systems: |
| 83 | +This restriction enforces your maximum and minimum OS version requirements. This type of restriction works with the following operating systems: |
79 | 84 |
|
80 | 85 | * Android device administrator\* |
81 | 86 | * Android Enterprise work profile\* |
82 | 87 | * iOS/iPadOS\* |
83 | 88 | * Windows |
84 | 89 |
|
85 | | -\* Version restrictions are supported on these platforms for devices enrolled via Intune Company Portal only. |
86 | | - |
87 | | -This configuration is in the admin center under **Enrollment device platform restrictions**. |
| 90 | +\* Version restrictions are supported on these operating systems for devices enrolled via Intune Company Portal only. |
88 | 91 |
|
89 | | -## Combining restrictions |
90 | | -Since Intune supports two Android platforms, it's important to understand how version restrictions work when used together with device platform restrictions: |
91 | | - * If you allow both platforms for the same group, and then refine it for specific and non-overlapping versions, devices are sent through the Android enrollment flow that's picked for their version. |
92 | | - * If you allow both platforms, but block the same versions, devices running blocked versions can't enroll. Users on these devices are sent through the Android device administrator enrollment flow before they're blocked and prompted to sign out. |
| 92 | +This restriction is in the admin center under **Enrollment device platform restrictions**. |
93 | 93 |
|
94 | 94 | ### Device manufacturer |
95 | | -This restriction blocks devices made by specific manufacturers, and is applicable to Android devices only. |
96 | | - |
97 | | -This configuration is in the admin center under **Enrollment device platform restrictions**. |
| 95 | +This restriction blocks devices made by specific manufacturers, and is applicable to Android devices only. It is in the admin center under **Enrollment device platform restrictions**. |
98 | 96 |
|
99 | 97 | ### Personally-owned devices |
100 | 98 | This restriction helps prevent device users from accidentally enrolling their personal devices, and applies to devices running: |
101 | 99 |
|
102 | 100 | * Android |
103 | 101 | * iOS/iPad OS |
104 | 102 | * macOS |
105 | | -* Windows |
| 103 | +* Windows 10/11 |
106 | 104 |
|
107 | | -This configuration is in the admin center under **Enrollment device platform restrictions**. |
| 105 | +This restriction is in the admin center under **Enrollment device platform restrictions**. |
108 | 106 |
|
109 | 107 | #### Blocking personal Android devices |
110 | 108 | By default, until you manually make changes in the admin center, your Android Enterprise work profile device settings and Android device administrator device settings are the same. |
@@ -148,11 +146,6 @@ Intune also blocks personal devices using these enrollment methods: |
148 | 146 |
|
149 | 147 | \* These won't be blocked if registered with Autopilot. |
150 | 148 |
|
151 | | -### Device limit |
152 | | -This restriction lets you put a limit on the number of devices a person can enroll. In Intune, you can set the device limit from 1 to 15. |
153 | | - |
154 | | -This configuration is in the admin center under **Enrollment device limit restrictions**. |
155 | | - |
156 | 149 | ## Limitations |
157 | 150 |
|
158 | 151 | * Enrollment restrictions are applied to users. For enrollment scenarios that aren't user-driven, such as Windows Autopilot self-deploying mode, bulk enrollment (WCD), or Azure Virtual desktop, Intune enforces the default policy. |
|
0 commit comments