Skip to content

Commit caa92e4

Browse files
Added note under comanagement section
Adding note to deflect future support cases based on users having the default enrollment restriction set to block all windows and the higher priority windows restrictions not being utilized because no user is associated with the request.
1 parent 9138fb9 commit caa92e4

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

memdocs/intune/enrollment/enrollment-restrictions-set.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -109,6 +109,9 @@ The following enrollment methods are authorized for corporate enrollment:
109109
- The device is registered with Windows Autopilot but isn't an MDM enrollment only option from Windows Settings.
110110
- The device enrolls through a [bulk provisioning package](windows-bulk-enroll.md).
111111
- The device enrolls through GPO, or [automatic enrollment from Configuration Manager for co-management](/configmgr/comanage/quickstart-paths#bkmk_path1).
112+
113+
> [!NOTE]
114+
> Since co-managed devices are enrolled in the Microsoft Intune service based on its Azure AD device token, and not a user token, only the default Intune enrollment restriction will apply to the enrollment.
112115
113116
Intune marks devices going through the following types of enrollments as corporate-owned. But Intune blocks devices enrolling since they don't offer the Intune administrator per-device control, they are blocked:
114117
- [Automatic MDM enrollment](windows-enroll.md#enable-windows-automatic-enrollment) with [Azure Active Directory join during Windows setup](/azure/active-directory/device-management-azuread-joined-devices-frx)\*.

0 commit comments

Comments
 (0)