So, we’re currently trialing Microsoft EMS in our organization and have set up a trail environment for a pilot program. Our estate is made up of standalone PC’s or a group of PC’s in a LAN/Workgroups
and we do not have any on-prem ADDS or ADFS in place. In short, a cloud only setup.
With that said, we have been trying to set up Self Provisioning and Out-of-Box Enrolment /AD join for our Windows 10 Pro devices (laptops and desktops), in line with the guidance notes provided on
the Docs & Technet portal for setting up Azure AD join for devices, but have had no luck so far.
Here are the key issues we’re facing:
- IF we
let the employees perform Azure AD Join for their corporate owned devices, then the employee is made Administrator and then after the joining happens, rest of MDM Enrolment process kicks in… with all the polices set in the MDM, restrictions etc. The challenge
here is, we cannot let the end user/ non IT staff have elevated permissions as administrator on their work laptops/desktops.
Leaving employee with Admin premissions on the device has 2 key issues:
- The user can install ANY application from anywhere online and run it on the device with elevated permissions,
which is a major risk and there is NO way to prevent this using Intune or any other MDM out there. This is a risk we cannot take.
- Any IT company / Managed Servcie Provider would not take resposibilty if aything happens because they’re
not comfortable with the end user left with Admin permissions on the machine.
OR
- IF we
have an IT Admin perform the AD Join (and MDM enrolment) for all of our devices (before a device is handed over to the end user), then the issue we’re facing when the device is given to the enduser and he logs in as Other User with his Office365 credentials,
is that, the user is not able to access the office365 resources which require conditional access (devcies must be compliant or domain joined).
When attepting to access, say Exchange Online, the user is presented with the error: “Your IT Admin is a ensuring this device is compliant and this may take some time. To check the status check the
company portal”. Now, in the company portal, it says “you must Enrol this device” and shows and Enrol button which is basically a link to download Intune Client. And when we try to download Intune Client, again we’re presented with an error message: “This
device is already managed by an MDM”, i.e. the built in MDM of Windows 10”.
Any guidance / help with this conundrum, will be highly appreciated. Many thanks.