Skip to content

Commit 8ff521f

Browse files
authored
Merge pull request #554 from midineenMSFT/patch-5
Update win10-automatic-enrollment-aad.md
2 parents dbf25af + 8c27430 commit 8ff521f

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

memdocs/intune/includes/win10-automatic-enrollment-aad.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,9 +28,11 @@ Automatic enrollment lets users enroll their Windows 10 devices in Intune. To en
2828
- **All** - All users can automatically enroll their Windows 10 devices
2929

3030
> [!IMPORTANT]
31-
> For BYOD devices, the MAM user scope takes precedence if both MAM user scope and MDM user scope (automatic MDM enrollment) are enabled for all users (or the same groups of users). The device will use Windows Information Protection (WIP) Policies (if you configured them) rather than being MDM enrolled.
31+
> For Windows BYOD devices, the MAM user scope takes precedence if both the MAM user scope and the MDM user scope (automatic MDM enrollment) are enabled for all users (or the same groups of users). The device will not be MDM enrolled, and Windows Information Protection (WIP) Policies will be applied if you have configured them.
3232
>
33-
> For corporate devices, the MDM user scope takes precedence if both scopes are enabled. The devices get MDM enrolled.
33+
> If your intent is to enable automatic enrollment for Windows BYOD devices to an MDM: configure the MDM user scope to **All** (or **Some**, and specify a group) and configure the MAM user scope to **None** (or **Some**, and specify a group – ensuring that users are not members of a group targeted by both MDM and MAM user scopes).
34+
>
35+
>For [corporate devices](../enrollment/enrollment-restrictions-set.md#blocking-personal-windows-devices), the MDM user scope takes precedence if both MDM and MAM user scopes are enabled. The device will get automatically enrolled in the configured MDM.
3436
3537
> [!NOTE]
3638
> MDM user scope must be set to an Azure AD group that contains user objects.

0 commit comments

Comments
 (0)