Device joins Workgroup instead of Azure AD when using Windows Bulk Enrollment provisioning package

Yevhen 85 Reputation points
2025-10-16T16:55:39.69+00:00

I created a Windows provisioning package for bulk enrollment, following Microsoft’s documentation:

https://learn.microsoft.com/en-us/intune/intune-service/enrollment/windows-bulk-enroll

Using Windows Configuration Designer (WCD) → Provision desktop devices → Enroll in Azure AD → Get Bulk Token. Authentication is done with my admin account using MFA. The Bulk Enrollment Token is generated successfully, and the package applies without errors.

However, after deployment, the device is not joined to Azure AD — it is only joined to a Workgroup.
A similar issue was discussed here:
https://learn.microsoft.com/en-us/answers/questions/1184368/unable-to-enroll-device-in-azure-ad-using-provisio
where it was mentioned that MFA may cause this behavior.

At the same time, Microsoft has enforced mandatory MFA for all tenants:

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication?tabs=dotnet and it cannot be disabled.

Question: Given that MFA is now mandatory, how can I create a provisioning package that allows Windows workstations to successfully join Azure AD instead of being joined only to a Workgroup?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.