Back to blog
IntunePublished on July 15, 20268 min read

Enrolling Windows PCs into Intune

Microsoft Entra join, automatic MDM enrollment, group tags and BYOD: the clean ways to bring your Windows PCs under Intune management without duplicates.

A Windows PC does not exist for Intune until it is enrolled. As long as it is not, no configuration profile, no endpoint security policy and no Conditional Access rule actually applies: the PC stays invisible, non-compliant and out of reach of your audits. Enrollment is the first building block of any ISO 27001, NIS2 or GDPR compliance effort, and yet it is also the stage where silent mistakes pile up the fastest.

Whether the PC is brand new, already in service, or owned by an employee, the enrollment method changes. Understanding these paths spares you two very common problems: duplicate device records that clutter the console and skew your license counts, and enrollments that never complete for lack of scope, licensing or preparation. This guide is for administrators and SMB owners as much as for MSSPs who run several tenants and want a clean fleet from day one.

Microsoft Entra join and automatic MDM enrollment

The cleanest path for a corporate machine is Microsoft Entra join. The PC becomes a full object in your Microsoft Entra ID directory, and if automatic MDM enrollment is enabled, it enrolls into Intune right away, with no manual step. You centralize identity and management in a single operation, which simplifies Conditional Access and compliance reporting down the line.

Enable automatic enrollment at the tenant level

Automatic enrollment is not magic: it relies on a user scope defined in the Windows device enrollment settings in Intune. If that scope does not cover the user joining the PC, the Entra join succeeds but the Intune enrollment never fires. This is the number one cause of "joined but unmanaged" machines.

  1. 1In the Intune admin center, open Windows device enrollment and confirm that the MDM user scope is set to "All" or to a group that contains your users.
  2. 2Make sure each affected user holds a license that includes Intune (for example through a Microsoft 365 plan or standalone Intune).
  3. 3For a new PC, run the out-of-box experience (OOBE) and choose "Set up for an organization", then sign in with the work account.
  4. 4For an existing PC, go to Settings > Accounts > Access work or school > Connect, then "Join this device to Microsoft Entra".
  5. 5Let the PC finish enrolling and confirm it appears in the Intune devices list a few minutes later.
Entra join then automatic MDM enrollment: the PC checks into Intune on its own.

The role of the Enrollment Status Page

When you provision new machines with Windows Autopilot, the Enrollment Status Page shows the user the progress of policy application, BitLocker encryption and app installs before they can reach the desktop. Configured well, it guarantees a PC is only handed over once it is genuinely compliant. Configured poorly, it can trap the user on an app that will never install: reserve blocking for apps that are truly essential.

Microsoft Entra registration for personal devices

For a personal device (BYOD), prefer registration (Entra registered) over a full join. The user keeps control and ownership of their machine, while the organization applies a deliberately limited management scope. It is the right compromise when the company does not own the hardware but still wants to gate access to its resources behind a baseline of security.

In this mode you often rely on app management (MAM) and Conditional Access rather than full device management. The user is reassured about their privacy: the administrator cannot see their personal data and cannot wipe the whole machine, only the corporate data on it.

  • Company-provided corporate PC: Entra join plus full MDM enrollment.
  • Occasional consultant's personal PC: Entra registration plus Conditional Access requiring a compliant device or a protected app.
  • Shared self-service machine: consider a dedicated deployment and a restrictive profile instead, as personal registration is not a good fit.
  • Contractor's off-domain machine: grant access only after checking its security posture through Conditional Access.
A clean enrollment is not a technical formality: it is what makes your policies genuinely enforceable and your audits credible.

Group tags and dynamic targeting

Group tags are used mainly in the Windows Autopilot context: they let you classify devices automatically and attach them to Entra dynamic groups, and therefore to different policy sets. Clean targeting from enrollment onward saves you from reclassifying machines by hand later, and it keeps your assignments predictable as the fleet grows.

  1. 1Define a consistent tag naming scheme, for example by site, by department or by device role (laptop, desktop, kiosk).
  2. 2Create dynamic groups whose membership rule filters on the group tag.
  3. 3Attach the right configuration profile, endpoint security policies and expected Windows Update for Business policies to each group.
  4. 4Regularly check that no machine lands in two groups with contradictory policies.
Consistent tags, dynamic groups, targeted policies: targeting you can read at a glance.

Avoiding duplicate device records

A single PC that has been reset and re-enrolled sometimes leaves a stale object behind, which inflates your counters and blurs compliance. To keep an honest read of the fleet, aim for a single record per physical machine.

  • Regularly purge inactive devices and stale objects in both Intune and Microsoft Entra ID.
  • Watch out for PCs joined both through a hybrid method and a native Entra join, a classic source of duplicates.
  • After a hardware swap, explicitly remove the old device rather than letting it expire on its own.

How AuPoint simplifies enrollment and tracking

Tracking enrollment state and diagnosing a stuck PC often means cross-referencing several Intune views and decoding cryptic error codes. AuPoint gives a clear, plain-language read of the enrolled fleet and automatically applies the right policies to the right groups, with no PowerShell. You preview the impact of each change before applying it, keep a break-glass safety account, and can roll policies back if needed, which sharply reduces the risk of locking out part of your fleet.

Impact preview and reversible policies: security without nasty surprises.

FAQ

Do I need a specific license to enroll a Windows PC?

Yes. The user enrolling the PC must hold a license that includes Microsoft Intune, for example through an appropriate Microsoft 365 plan or standalone Intune. Without a license, the Entra join may succeed but the MDM enrollment will fail or stay incomplete.

Entra join or Entra registration: how do I choose?

Choose Entra join for machines the company owns and wants to manage fully. Choose Entra registration for personal devices (BYOD), when you only want to gate access to resources without taking full control of the machine.

Why is my PC joined but missing from Intune?

Most often, the automatic MDM enrollment user scope does not cover the user, or the user has no Intune license. Check the scope in the Windows enrollment settings, the license assignment, then re-trigger enrollment from the PC's settings.

Ready to see your Windows fleet in a clear light and apply the right policies in a few clicks? Connect your Microsoft tenant and start free at aupoint.io.

Secure your tenant in 15 minutes

Free trial