Endpoint/Intune Device Enrollment Authorization

Flavia 240 Reputation points
2024-05-16T15:44:17.4266667+00:00

Is there a way to create a script in Intune/Endpoint that when a device is trying enrolled with company portal to the tenant, sends or requires an authorization from an admin before completing the enrollment or compliant process? Or a conditional access that gives us time to double check the device that is trying to connect to our tenant?

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
7,511 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,365 questions
Microsoft Configuration Manager
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,646 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
17 questions
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 14,870 Reputation points Microsoft Vendor
    2024-05-17T06:24:38.73+00:00

    @Flavia, Thanks for posting in Q&A.

    I have done some research about this issue my, currently there is no such feature in Intune, nor is there a related script that could be the implementation of sending or requesting an administrator's authorization before completing the registration or compatibility process, and that the process of registering to Intune is done automatically.

    If you want to implement a restriction that certain devices cannot be registered to Intune, you can try the device platform restriction setting.

    https://learn.microsoft.com/en-us/mem/intune/enrollment/create-device-platform-restrictions

    Hope this can be helpful.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.