We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and MDM
  2. Device enrollment
Device enrollment in Microsoft Intune

Five of the nine enrollment paths begin by erasing the machine. Learning that after the hardware has shipped costs a week nobody planned for.

What enrollment actually does is install a management certificate and switch on policy enforcement. Which route you take then governs three separate things: whether the machine has to be erased on the way in, how far your policies can reach afterward, and how much the person holding it has to do. Those questions belong to procurement at least as much as to engineering.

Book an enrollment design sessionSee which paths need a reset
Laptops and phones being brought under Intune management
  • Five platformsAndroid, Apple, Linux, macOS and Windows
  • Reset requiredFor iOS, macOS and three Android modes
  • 1,000 devicesWhat a device enrollment manager can enroll
  • 180 daysBefore idle device records are deleted
What enrollment decides

Seven questions to close out before hardware is ordered.

Enrollment is described as installing a mobile device management certificate that talks to the Intune service and turns on policy enforcement, with enrollment, compliance and configuration policies typically arriving during the same process. What follows determines how far that enforcement can actually reach.

Five enrollment paths require a factory reset first

The table is published and unambiguous. Erasure is required for iOS and iPadOS, for macOS, and for three Android Enterprise modes: corporate-owned work profile, fully managed, and dedicated devices. It is not required for the Android Enterprise personally owned work profile, for Android device administrator, for Linux or for Windows. Device logistics for the entire program follow from that one grid.

Corporate-owned gets more control than personal

Devices classified as corporate-owned or organization-owned unlock more granular settings and policies, with additional password settings that allow stricter requirements than a personal device permits. Worth pairing with a second published detail: anything Microsoft Entra registered is marked as personally owned, which is the usual mechanism by which a company laptop ends up filed in the wrong category.

Only the Apple platforms carry an extra prerequisite

The prerequisites table is short. iOS and iPadOS require a mobile device management push certificate from Apple plus an Apple ID; macOS requires the push certificate. Android, Android Enterprise, Linux and Windows carry no additional platform requirement at all. The Apple certificate is also the annual expiry that takes an entire fleet offline whenever its renewal has no owner.

Enrollment restrictions, which default in the permissive direction

Every platform is enabled for enrollment out of the box, and blocking the ones you do not intend to support takes an enrollment restriction policy. Put that alongside the policies capping how many devices, and which types, any one person may bring in, and you have the mechanism that keeps a fleet from accumulating hardware nobody agreed to support.

A device enrollment manager account for bulk work

For staging hardware before it reaches employees, the device enrollment manager account handles up to 1,000 mobile devices, and it is an Intune permission applied to an ordinary Entra user account. One caveat is published clearly: it does not work with every enrollment method, and Apple automated device enrollment is called out by name.

Settings survive on platforms that are not wiped

A quiet detail with loud consequences. On the platforms that skip the reset, devices begin receiving Intune policy at enrollment, but anything you have not explicitly configured in Intune is left exactly as it was. A machine migrated in from another management product can therefore carry its old configuration indefinitely, invisibly, until something behaves oddly.

Idle records are deleted after a defined period

The management certificate renews itself as long as the device keeps talking to the service, and stops renewing once a device is wiped or fails to sync for an extended stretch. Idle devices are then deleted from record 180 days after that certificate expires. Knowing this in advance saves somebody concluding that historical devices vanished through a fault.

The logistics question hiding inside a technical decision

A device already in a user's hands cannot take five of the nine enrollment paths without being wiped.

The reset requirement is published per enrollment method, and no other single fact rewrites more deployment plans after everyone has signed off on them.

  • Erasure required, as published: iOS and iPadOS, macOS, Android Enterprise corporate-owned work profile, Android Enterprise fully managed, and Android Enterprise dedicated devices.
  • Erasure not required: the Android Enterprise personally owned work profile, Android device administrator, Linux and Windows.
  • For hardware already in circulation the implication is severe. Bringing in-use iPhones or Macs under a corporate enrollment means every unit is wiped and rebuilt, which is a communications plan, a data migration and a support surge rather than a configuration change.
  • For hardware still on order the implication runs the other way entirely. New devices enrolled before they are issued take the corporate path at no cost to anybody, which is why this table belongs in the refresh conversation rather than in the technical design that comes afterward.
Ask us to map your enrollment paths
How we approach it

Four practices that turn enrollment into a choice instead of an accident.

No other part of device management touches procurement, logistics, internal communications and the service desk simultaneously. Treating it as purely technical is what generates the surprises.

We bring the erasure requirements into the purchasing discussion

Five of the published paths cannot be taken without erasing the device. On new hardware that costs nothing. On hardware in daily use it becomes a data migration, an internal communications exercise and a spike in tickets. Sorting out which population is which before anybody raises a purchase order converts an expensive retrofit into a decision that costs nothing because it was taken at the right time.

We get the corporate classification right at the start

Corporate-owned classification unlocks more granular settings and stricter password requirements, while anything Entra registered gets marked as personally owned. Devices that land in the wrong bucket are awkward to reclassify and quietly cap what you are able to enforce, so the identification method deserves more attention at the outset than it usually receives.

We clean up what the previous product left behind

Where no wipe occurs, any setting you have not configured in Intune is simply left untouched. A device brought over from another management product carries its previous configuration along indefinitely, and nobody sees it until behavior stops making sense. We inventory and clear that as part of the migration rather than after the first confused ticket.

We use restrictions to keep the estate to what you support

Enrollment stands open on every platform until you close it. Blocking the platforms you never intended to support, and capping how many devices and which types one person can enroll, takes about five minutes and prevents years of accumulated exceptions that nobody ever consciously agreed to.

Where this matters most

Six US situations where the enrollment decision has real consequences.

It presents as a technical step and behaves like a logistics program, because the chosen route dictates whether hardware gets erased, who has to handle it, and what you can enforce once it is in.

A business moving an existing iPhone fleet under management

Because iOS and iPadOS enrollment requires a factory reset, an in-use fleet means every handset wiped and rebuilt. That is a notification plan, a backup and restore path and a wave of support calls, not a configuration change. Aligning it with a hardware refresh, where the devices are new anyway, removes the cost completely.

A remote-first company shipping devices to new hires

A device enrollment manager account covers up to 1,000 mobile devices and exists precisely to enroll and configure hardware before handing it over. When your new hires will never visit an office, that is the difference between a laptop that works the moment it is unboxed and a support call on day one. Note that it does not work with Apple automated device enrollment.

A regulated business tightening controls on company-owned hardware

Devices classified as corporate-owned or organization-owned unlock more granular settings, including additional password settings that allow stricter requirements. When a HIPAA safeguard, an FTC Safeguards Rule control or an insurance condition specifies device requirements, your ability to satisfy it rests on a classification decision taken at enrollment.

An operator deploying shared and single-purpose devices

Android Enterprise dedicated devices are wiped at enrollment and staged centrally, which fits handhelds, scanners and tablets passed between shifts. That is a fundamentally different logistics model from an employee-owned device with a work profile, and running both inside one project produces two incompatible sets of arrangements.

An organization migrating from another management product

Hardware enrolled elsewhere has to be removed from that provider first, and unenrolling typically leaves the features and settings that were configured in place. On the platforms that skip a factory reset, those settings survive into Intune unless Intune explicitly configures them, which accounts for a great deal of otherwise inexplicable behavior after a migration.

An institution wanting to limit what people can enroll

Every platform is open for enrollment by default, and an enrollment restriction policy closes the ones you do not want. Combined with policies capping the number and type of devices any individual may enroll, that stops a large and varied user population from assembling a fleet full of hardware nobody planned to support or secure.

Three positions

How US organizations bring devices under management.

The middle column is what an undesigned enrollment produces. Devices arrive by whichever route each individual happened to find, and the result is a fleet sorted into three categories nobody can account for.
Corporate devices marked as corporate
Designed enrollment modelYes
Whatever path people usedPartly
Unmanaged devicesNot applicable
Stricter policies available where appropriate
Designed enrollment modelYes
Whatever path people usedInconsistent
Unmanaged devicesNo
Unsupported platforms blocked
Designed enrollment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Device count per user limited
Designed enrollment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Bulk enrollment before issue
Designed enrollment modelYes
Whatever path people usedRarely
Unmanaged devicesNo
Old settings from a previous product removed
Designed enrollment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Enrollment failures monitored
Designed enrollment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Apple certificate renewal owned
Designed enrollment modelYes
Whatever path people usedDiscovered when it expires
Unmanaged devicesNot applicable
Stale records understood
Designed enrollment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
User experience at enrollment
Designed enrollment modelDesigned
Whatever path people usedVaries
Unmanaged devicesNot applicable
Feature
Designed enrollment model
Whatever path people used
Unmanaged devices
Corporate devices marked as corporate
YesPartlyNot applicable
Stricter policies available where appropriate
YesInconsistentNo
Unsupported platforms blocked
YesNoNot applicable
Device count per user limited
YesNoNot applicable
Bulk enrollment before issue
YesRarelyNo
Old settings from a previous product removed
YesNoNot applicable
Enrollment failures monitored
YesNoNot applicable
Apple certificate renewal owned
YesDiscovered when it expiresNot applicable
Stale records understood
YesNoNot applicable
User experience at enrollment
DesignedVariesNot applicable
The published requirements

Erasure requirements and platform prerequisites, route by route.

Taken from the two published tables. The final column is our reading of what each requirement means in practice.

Enrollment path

Android Enterprise personally owned with a work profile

Factory reset required
No
Practical consequence
The tidiest route for hardware an employee already owns, with the work side walled off

Enrollment path

Android Enterprise corporate-owned work profile

Factory reset required
Yes
Practical consequence
Suits new stock, or a scheduled wipe and reissue with notice to staff

Enrollment path

Android Enterprise fully managed

Factory reset required
Yes
Practical consequence
Company hardware only, staged before anybody receives it

Enrollment path

Android Enterprise dedicated devices

Factory reset required
Yes
Practical consequence
Shared and single-purpose units, prepared centrally

Enrollment path

Android device administrator

Factory reset required
No
Practical consequence
Legacy, and deprecated wherever Google Mobile Services are present

Enrollment path

iOS and iPadOS

Factory reset required
Yes
Practical consequence
Also depends on an Apple push certificate and an Apple ID

Enrollment path

macOS

Factory reset required
Yes
Practical consequence
Also depends on an Apple push certificate

Enrollment path

Windows

Factory reset required
No
Practical consequence
Machines can enroll where they stand, though old settings may survive the move

Enrollment path

Linux

Factory reset required
No
Practical consequence
Enrollment initiated by the user on supported distributions
Enrollment pathFactory reset requiredPractical consequence
Android Enterprise personally owned with a work profileNoThe tidiest route for hardware an employee already owns, with the work side walled off
Android Enterprise corporate-owned work profileYesSuits new stock, or a scheduled wipe and reissue with notice to staff
Android Enterprise fully managedYesCompany hardware only, staged before anybody receives it
Android Enterprise dedicated devicesYesShared and single-purpose units, prepared centrally
Android device administratorNoLegacy, and deprecated wherever Google Mobile Services are present
iOS and iPadOSYesAlso depends on an Apple push certificate and an Apple ID
macOSYesAlso depends on an Apple push certificate
WindowsNoMachines can enroll where they stand, though old settings may survive the move
LinuxNoEnrollment initiated by the user on supported distributions
How an engagement runs

Five steps, and the pilot is not a formality.

Four to eight weeks gets you to a designed and piloted enrollment model. Building it is quick. Deciding the route for each population, and telling people what to expect, is the actual work.
  1. 1

    Confirm the prerequisites are actually in place

    Management authority set to Intune, which applies even where Configuration Manager runs alongside it in co-management. Licenses assigned. Supported devices confirmed. An Apple push certificate obtained wherever iOS, iPadOS or macOS appear in scope, with a named person accountable for renewing it.

  2. 2

    Decide the path per population

    Personal or corporate ownership, and the enrollment method that follows from it, checked against the published reset requirements. Whether the hardware is new or already in service, since that decides whether erasure is free or expensive. And whether anything currently sits in another management product, which has to be unenrolled first.

  3. 3

    Set restrictions before opening enrollment

    Since every platform starts open, the ones you have no intention of supporting get blocked explicitly. Policies capping how many devices and which types any one person can enroll go in at the same moment, because both are dramatically easier to apply before a fleet exists than to retrofit around one that already does.

  4. 4

    Pilot in stages, starting genuinely small

    The recommended shape is to start small and widen deliberately: assign the enrollment policy to a pilot or test group, add more users to that group once early testing looks clean, then extend to further pilot groups. Following it surfaces problems with the enrollment experience while the affected population is still small enough to call one by one.

  5. 5

    Establish the operational rhythm

    Incomplete user enrollments watched through the published report. Apple push certificate renewal owned by a named person with a reminder well ahead of the date. And a shared understanding that idle records disappear 180 days after the management certificate expires, so Intune should never be mistaken for a permanent asset register.

Straight answers

What organizations ask about device enrollment.

The published table lists five. Erasure is required for iOS and iPadOS, for macOS, and for the Android Enterprise corporate-owned work profile, fully managed and dedicated device modes. It is not required for the Android Enterprise personally owned work profile, for Android device administrator, for Linux or for Windows. In most programs that distinction sets the cost of the entire project.

Intune installs a mobile device management certificate on the device, and that certificate communicates with the Intune service and lets Intune begin enforcing your policies. Alongside it, the policies that typically arrive during enrollment include enrollment policies limiting how many devices and which types a person may bring in, compliance policies, and configuration policies that apply work-appropriate features and settings.

How much you can enforce. Devices classified as corporate-owned or organization-owned expose more granular settings and policies, with additional password settings that allow stricter requirements. It is also documented that anything Microsoft Entra registered is marked personally owned, which is the usual route by which a device ends up classified as something it is not.

The mobile device management authority set to Intune, which holds true even where Intune and Configuration Manager run together in co-management. Intune licenses assigned. Supported devices. And an administrator signed in as a member of the Policy and Profile Manager built-in Intune role, with the caveat that certain enrollment platforms may call for a more privileged Entra role such as Intune Administrator.

Only Apple ones. The published table shows iOS and iPadOS requiring a mobile device management push certificate together with an Apple ID, and macOS requiring the push certificate. Android, Android Enterprise, Linux and Windows list no additional platform requirement whatsoever. Assign an owner to the Apple certificate, because it has an expiry date and the fleet depends on it.

Yes. Enrollment is switched on for every platform by default, and an Intune enrollment restriction policy is what blocks the ones you do not want. There are also enrollment policies that cap how many devices, and which types, a single person may enroll, which is the other half of holding a fleet to the shape you actually intended.

Through the device enrollment manager account, an Intune permission applied to an Entra user account that can enroll up to 1,000 mobile devices, built for configuring hardware before it reaches the people who will use it. The published caveat matters: it is not compatible with every enrollment method, and Apple automated device enrollment is named specifically.

They need unenrolling from the incumbent provider first. Unenrolling typically does not strip the features and settings that were configured there, and most providers offer remote actions for removing organization-specific data. Doing that clean-up before enrolling in Intune is possible rather than mandatory, and depending on the platform a factory reset may be required regardless.

Not automatically, and this trips people up regularly. On the platforms that do not require a factory reset, devices start receiving your Intune policies at enrollment, but any setting you have not configured in Intune is left untouched. Previously configured settings can therefore persist indefinitely on Windows, on Linux, and on the Android routes that skip the wipe.

In deliberate stages. The recommended shape is to begin small, assign the enrollment policy to a pilot or test group, add further users to that group once initial testing holds up, then extend to additional pilot groups. Enrollment is the piece of device management users encounter most directly, so a problem caught at ten people costs a fraction of the same problem found at a thousand.

Record cleanup, working as designed. The management certificate renews itself while a device keeps communicating with the service, stops renewing once the device is wiped or fails to sync for an extended period, and idle devices are then deleted from record 180 days after that certificate expires. Nothing has been lost, but it does mean Intune is not a permanent asset register.

In some scenarios, yes. Application management without enrollment sits alongside the per-platform enrollment guides as its own path. It protects organizational data inside managed applications on hardware that is never enrolled itself, which suits contractors and personal devices where full enrollment would be neither proportionate nor acceptable to the person holding the device.

A published report covers incomplete user enrollments, and there is troubleshooting guidance alongside it. Watching that report during a rollout is how you discover that an entire population is quietly failing to finish, which otherwise emerges weeks later as an unexplained gap between the number of devices issued and the number actually under management.

The management authority still has to point at Intune, and that is stated explicitly for the case where Intune and Configuration Manager operate together. Co-managed and Microsoft Entra hybrid joined devices sit inside the supported device requirement, so they are in scope for enrollment rather than forming a separate track. What co-management alters is which product owns which workload afterward, not whether the device enrolls.

Scoped per engagement, shaped by how many platforms and populations are in play and whether an existing fleet has to be migrated, which is where the reset requirements do their damage. Mapping the paths is quick and is usually the single most valuable output, because it frequently changes when the work ought to happen rather than merely how.
Before the first device

Fifteen decisions that determine the enrollment experience.

Prerequisites come first, the path decision second, and third the operational half that decides whether the fleet stays orderly a year from now.

Prerequisites

  • Is the MDM authority set to Intune?
    Required even where co-management is in play.
  • Are Intune licenses assigned?
    To everyone who will enroll a device.
  • Is the Apple push certificate in place?
    Needed for iOS, iPadOS and macOS.
  • Who renews the Apple certificate?
    It expires, and the fleet expires with it.
  • Which administrative role is being used?
    Policy and Profile Manager is the least privileged fit.

Path decision

  • Are these new or existing devices?
    Five of the paths begin with an erasure.
  • Personal or corporate-owned?
    Corporate unlocks stricter password settings.
  • Are devices already in another MDM?
    Remove them from the incumbent first.
  • Do you need bulk enrollment before issue?
    That is the DEM account, up to 1,000 devices.
  • Is Apple automated device enrollment in scope?
    The DEM account does not work with it.

Keeping it clean

  • Which platforms should be blocked?
    Every one of them is open by default.
  • How many devices may one person enroll?
    Enrollment policies can cap this.
  • Are settings from a previous product still present?
    They persist wherever no wipe occurred.
  • Is there a pilot group?
    A staged approach is the recommended shape.
  • Who watches incomplete enrollments?
    A published report covers exactly this.
Related reading

The pages around this one.

Windows Autopilot

The Windows provisioning route in depth, where enrollment turns into a machine that sets itself up.

Learn more

Android Enterprise management

The Android methods examined closely, including the factory reset table and zero-touch staging.

Learn more

MDM solutions

The cross-platform view of what management looks like once devices are in.

Learn more
Next step

Work out how many of your devices would have to be wiped. That number is the project.

Five of the published routes begin with a factory reset. Where most of the fleet is heading for a refresh anyway, that costs almost nothing. Where it is not, the timing is a decision worth taking deliberately rather than discovering halfway through.

Book an enrollment design sessionSee MDM solutions

Related Services

Explore more solutions that work great with this service

Microsoft Intune

Device management and endpoint security

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA