A cloud-based identity and access management service for securing user authentication and resource access
Device joins Workgroup instead of Azure AD when using Windows Bulk Enrollment provisioning package
I created a Windows provisioning package for bulk enrollment, following Microsoft’s documentation:
https://learn.microsoft.com/en-us/intune/intune-service/enrollment/windows-bulk-enroll
Using Windows Configuration Designer (WCD) → Provision desktop devices → Enroll in Azure AD → Get Bulk Token. Authentication is done with my admin account using MFA. The Bulk Enrollment Token is generated successfully, and the package applies without errors.
However, after deployment, the device is not joined to Azure AD — it is only joined to a Workgroup.
A similar issue was discussed here:
https://learn.microsoft.com/en-us/answers/questions/1184368/unable-to-enroll-device-in-azure-ad-using-provisio
where it was mentioned that MFA may cause this behavior.
At the same time, Microsoft has enforced mandatory MFA for all tenants:
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication?tabs=dotnet and it cannot be disabled.
Question: Given that MFA is now mandatory, how can I create a provisioning package that allows Windows workstations to successfully join Azure AD instead of being joined only to a Workgroup?