Enrolling Devices into Microsoft's Intune admin center
🆘 How to Automatically Enroll Hybrid-Joined PCs into Intune Admin Center (Without Using Company Portal)
Hi everyone,
I'm preparing for a large-scale PC Replacement Project and need help streamlining the Intune enrollment process for newly joined devices.
🧩 My Environment:
- On-premises Active Directory
- Microsoft Entra ID (Hybrid Azure AD Join via AD Connect)
- Microsoft Intune (Endpoint Manager)
✅ What Works:
I can successfully enroll devices into Intune using:
- The Company Portal app
- Or Settings > Accounts > Access work or school > Enroll only in device management
However, these methods are manual and limited:
- There's a device enrollment cap per user (15 for Intune, 20 for Entra ID)
- I have over 100 PCs to upgrade and replace
- I need a scalable, automated process that doesn’t rely on user-driven enrollment
❌ What I've Tried:
I attempted to configure Group Policy Objects (GPOs) on my domain controller to trigger automatic enrollment for Hybrid Azure AD joined devices. I followed guidance to:
- Place a PowerShell script in
SYSVOL
to invokems-device-enrollment:?mode=mdmenroll
- Link the GPO to the correct OUs
- Enable Hybrid MDM Auto-Enroll via: Computer Configuration → Administrative Templates → Windows Components → MDM Enable automatic MDM enrollment using default Azure AD credentials → Enabled (Device Credentials)
- Despite this, devices show:
dsregcmd /status PolicyEnabled : NO PreReqResult : WillNotProvision
❓ What I Need:
- A reliable, automated method to enroll newly joined Hybrid Azure AD devices into Intune
- A solution that works at scale (100+ devices)
- Ideally, something that can be triggered via GPO, script, or provisioning package—without requiring user interaction
🙏 Request:
Can someone walk me through a proven method to:
- Automatically enroll Hybrid Azure AD joined devices into Intune
- Avoid hitting the per-user device limit
- Ensure devices appear in the Intune Admin Center as Managed by Microsoft Intune
Any help, scripts, or best practices would be greatly appreciated!
Thanks in advance, Derrick❓ What I Need:
- A reliable, automated method to enroll newly joined Hybrid Azure AD devices into Intune
- A solution that works at scale (100+ devices)
- Ideally, something that can be triggered via GPO, script, or provisioning package—without requiring user interaction
Any help, scripts, or best practices would be greatly appreciated!
Thanks in advance,
Derrick J