All computers should be joined to Entra ID, and managed by Intune.

  1. Entra registered is not supported.
  2. Intune auto-enrolled should be set, no extra action is needed for MDM enrollment.
  3. Any third-party Antivirus should be removed before enrolling!

To enroll a device through Windows Settings, the device user first adds their Entra account:

  1. On the device, go to Start > settings Settings, then in the Settings window click Accounts > Access work and school.
  2. Click + Connect. A dialog for setting up a work or school account opens.
  3. Authenticate with the Entra account:
    1. Enter the account name:
    2. For a joined device, click Join this device to Microsoft Entra ID. In the Microsoft account dialog, enter the Entra account name, then click Next.Joining to an Entra when enrolling a registered device with Windows Settings.Entering the Entra account name when enrolling a registered device with Windows Settings.
    3. If the account is recognized, both the password prompt and the Knox Manage branding shows in the dialog. Enter the account password and click Sign in.Entering the Entra account password when enrolling with Windows Settings.
  4. Confirm both the Microsoft Entra domain and the username is correct.Confirming the domain when enrolling a registered device with Windows Settings.
  5. If the provisioning succeeds, the dialog reads The device is connected to Intune.
    Click Done. The Entra account is added to the device.
    The success dialog when enrolling with Windows Settings.
  6. Sign out from your local user account, and sign back in with your Microsoft 365 account.
  7. Your device is now enrolled and managed. It is required to be compliant before you can access company resources. Please