Need some help with Intune understanding and configure Entra joined devices

Borislav Vitanov 111 Reputation points
2026-02-26T08:57:57.6733333+00:00

Hi guys,

I need your help with understanding how it works and some help about configuration in Intune.

We are currently with Hybrid but we are moving to Azure and one part of it is the new installation of devices. Currently, during the test, both options are available - Hybrid Join and Azure join.

In Entra we have:

Entra hybrid joined for corporate devices

Entra registered for BYODs

Entra joined for new corporate devices joined directly to Entra with an email address during an OS installation.

In Intune we have by Windows:

  • Automatic enrollment - which works as well for BYODs and corporate Entra joined devices
  • Windows Autopilot - never tested so far and only some settings are prepared

I would like to achieve the following:

When there is a new OS installation and user gives his corporate email address and logon, currently, the computer is joined with some custom windows name. I would like to have at least sort of naming convention for newly joined device. Something like CORP-NEW-*****, and then based on this name, to be automatically added to a group. A renaming after this is not problem. I already created a group, and assign list of apps to be installed at first. My problem is that devices don't get "proper" computername. I've tried to find something useful in Intune to achieve it, but couldn't find anything.

Regarding Autopilot, I wonder how this should work with a VM in Hyper-V or VM in ESXi?

Thanks in advance

Microsoft Security | Intune | Enrollment

1 answer

Sort by: Newest
  1. AI answer

    2026-02-26T08:58:32.7933333+00:00

    Device naming and grouping behavior depends on how Windows is joined and whether Windows Autopilot is used.

    1. Why Entra join during OOBE cannot follow a naming convention

    When a user installs Windows and signs in with a corporate Entra ID account during OOBE (user‑driven Microsoft Entra join without Autopilot):

    • The device is joined directly to Microsoft Entra ID.
    • Windows generates the computer name locally (e.g., DESKTOP‑XXXXXXX).
    • Intune automatic enrollment (configured under Microsoft Entra ID → Mobility (MDM and WIP) → Microsoft Intune → MDM user scope) only starts after the device is already joined and named.
    • There is no built‑in way in Intune or Entra ID to override that initial name pattern for these “plain” Entra‑joined devices.

    Renaming after enrollment is possible (e.g., via Intune device configuration or scripts), but the initial name at join time cannot be controlled in this scenario.

    1. How to get a naming convention and automatic grouping

    To enforce a naming convention such as CORP-NEW-***** and then target groups based on that name, Windows Autopilot must be used. Autopilot controls the Out‑of‑Box Experience (OOBE) and can apply:

    • A deployment profile (user‑driven Microsoft Entra join or hybrid join).
    • A device naming template.
    • Automatic assignment to device groups (for apps, policies, etc.).

    The high‑level workflow for user‑driven Microsoft Entra join with Autopilot is:

    1. Set up Windows automatic Intune enrollment
      • In the Azure portal, go to Microsoft Entra ID → Mobility (MDM and WIP) → Microsoft Intune.
      • Under MDM user scope, select All or Some so that users can automatically enroll their devices in Intune.
      • Save the configuration.
      This step is described in the “Set up Windows automatic Intune enrollment” sections for Autopilot workflows.
    2. Register devices as Windows Autopilot devices
      • Import device hashes or use OEM/partner registration so the devices appear as Autopilot devices.
    3. Create a device group
      • Create a Microsoft Entra device group that will contain the Autopilot devices (static or dynamic).
    4. Configure and assign Windows Autopilot Enrollment Status Page (optional but recommended)
      • In the Intune admin center, configure the Enrollment Status Page so apps and profiles install during OOBE.
    5. Create and assign a Windows Autopilot profile
      • In Intune, create a Windows Autopilot deployment profile (user‑driven Microsoft Entra join).
      • On the Out‑of‑box experience (OOBE) page, configure the options as needed.
      • Assign the profile to the Autopilot device group on the Assignments page.
      • Intune periodically checks the assigned groups and applies the profile to new devices.
      For hybrid join scenarios, the workflow is similar but includes installing and validating the Intune Connector for Active Directory and configuring a domain join profile.

    Once Autopilot is in place, the naming template in the deployment profile can enforce a pattern. Devices will then be automatically added to groups (for example, via dynamic rules based on device name or Autopilot attributes), and apps/policies can be assigned to those groups.

    1. Autopilot and VMs (Hyper‑V / ESXi)

    Autopilot can be used with virtual machines as long as they are registered as Autopilot devices (device hash captured and imported, or otherwise registered) and meet the same requirements as physical devices:

    • For Microsoft Entra join: follow the “Step by step tutorial for Windows Autopilot user‑driven Microsoft Entra join in Intune” workflow:
      1. Set up Windows automatic Intune enrollment.
      2. Allow users to join devices to Microsoft Entra ID.
      3. Register the VM as a Windows Autopilot device.
      4. Create a device group.
      5. Configure and assign the Enrollment Status Page.
      6. Create and assign the Windows Autopilot profile.
      7. (Optional) Assign the Autopilot device to a user.
      8. Deploy the device.
    • For Microsoft Entra hybrid join: follow the “Step by step tutorial for Windows Autopilot user‑driven Microsoft Entra hybrid join in Intune” workflow:
      1. Set up Windows automatic Intune enrollment.
      2. Install the Intune Connector for Active Directory on a domain‑joined server and ensure it shows as Active with a supported version.
      3. Increase the computer account limit in the target OU if needed.
      4. Register the VM as a Windows Autopilot device.
      5. Create a device group.
      6. Configure and assign the Enrollment Status Page.
      7. Create and assign the Microsoft Entra hybrid join Autopilot profile.
      8. Configure and assign a domain join profile.
      9. (Optional) Assign the Autopilot device to a user.
      10. Deploy the device.

    Autopilot does not depend on whether the device is physical or virtual; it depends on the device being registered as an Autopilot device and able to reach the required cloud services during OOBE.

    Summary:

    • Plain Entra join during OOBE with just a corporate email cannot enforce an initial naming convention from Intune.
    • To control naming and automatic grouping, configure Windows Autopilot with a deployment profile and device naming template, and assign it to Autopilot‑registered devices.
    • The same Autopilot workflows apply to VMs in Hyper‑V or ESXi as long as they are properly registered and meet connectivity requirements.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.