Configure enrollment restrictions

While setting up your organization's environment to support Windows 365 Link, you should make sure that your environment's enrollment restrictions don't block Windows 365 Link devices from enrolling in Intune.

The first time a user signs in to their Windows 365 Link, the Out of Box Experience (OOBE) joins the device to Microsoft Entra and enrolls it in Microsoft Intune for management. This is the first time the device is introduced to Intune, and thus it's an Unknown device. Because the device is Microsoft Entra joined, Intune sets the ownership to Corporate owned after the Intune enrollment process completes.

If a device platform restriction blocks personally owned devices, Windows 365 Link devices are prevented from completing Intune enrollment. To avoid this prevention, make sure to allow Windows 365 Link devices to enroll in Intune using one of the following methods:

Windows 365 Link devices don't currently support Autopilot.

If there's a policy that blocks personally owned Windows devices from enrolling in Intune it also blocks Windows 365 Link devices. You can create another policy with higher priority to allow Windows 365 Link devices to enroll in Intune while still blocking other personally owned Windows devices.

Follow these steps to create a policy to allow users to enroll Windows 365 Link devices in Intune:

  1. Sign in to the Microsoft Intune admin center > Devices > Enrollment > Windows > Device platform restriction > Windows restrictions.
  2. Under Windows restrictions, select Create restriction.
  3. On the Basics page, type a Name (like Allow enrollment of Windows 365 Link devices) and an optional Description > Next.
  4. On the Platform settings page, set the following options:
    • MDM: Allow
    • Personally owned devices: Allow
  5. Select Next.
  6. On Scope tags page, select Next.
  7. On Assignments page, select Add all users > Edit filter.
  8. On the Filters pane, select Include filtered devices in assignment > Windows 365 Link > Select.
  9. Select Next.
  10. On the Review + create page, select Create.
  11. On the Enrollment restrictions > Windows restrictions page, make sure the new policy is above any block policy in priority order.

For more information about Intune platform enrollment restrictions, see Create device platform restrictions.

Next steps

Suppress single sign-on consent prompt.