Registering devices with Intune for management and policy enforcement
Device naming and grouping behavior depends on how Windows is joined and whether Windows Autopilot is used.
- Why Entra join during OOBE cannot follow a naming convention
When a user installs Windows and signs in with a corporate Entra ID account during OOBE (user‑driven Microsoft Entra join without Autopilot):
- The device is joined directly to Microsoft Entra ID.
- Windows generates the computer name locally (e.g., DESKTOP‑XXXXXXX).
- Intune automatic enrollment (configured under Microsoft Entra ID → Mobility (MDM and WIP) → Microsoft Intune → MDM user scope) only starts after the device is already joined and named.
- There is no built‑in way in Intune or Entra ID to override that initial name pattern for these “plain” Entra‑joined devices.
Renaming after enrollment is possible (e.g., via Intune device configuration or scripts), but the initial name at join time cannot be controlled in this scenario.
- How to get a naming convention and automatic grouping
To enforce a naming convention such as CORP-NEW-***** and then target groups based on that name, Windows Autopilot must be used. Autopilot controls the Out‑of‑Box Experience (OOBE) and can apply:
- A deployment profile (user‑driven Microsoft Entra join or hybrid join).
- A device naming template.
- Automatic assignment to device groups (for apps, policies, etc.).
The high‑level workflow for user‑driven Microsoft Entra join with Autopilot is:
- Set up Windows automatic Intune enrollment
- In the Azure portal, go to Microsoft Entra ID → Mobility (MDM and WIP) → Microsoft Intune.
- Under MDM user scope, select All or Some so that users can automatically enroll their devices in Intune.
- Save the configuration.
- Register devices as Windows Autopilot devices
- Import device hashes or use OEM/partner registration so the devices appear as Autopilot devices.
- Create a device group
- Create a Microsoft Entra device group that will contain the Autopilot devices (static or dynamic).
- Configure and assign Windows Autopilot Enrollment Status Page (optional but recommended)
- In the Intune admin center, configure the Enrollment Status Page so apps and profiles install during OOBE.
- Create and assign a Windows Autopilot profile
- In Intune, create a Windows Autopilot deployment profile (user‑driven Microsoft Entra join).
- On the Out‑of‑box experience (OOBE) page, configure the options as needed.
- Assign the profile to the Autopilot device group on the Assignments page.
- Intune periodically checks the assigned groups and applies the profile to new devices.
Once Autopilot is in place, the naming template in the deployment profile can enforce a pattern. Devices will then be automatically added to groups (for example, via dynamic rules based on device name or Autopilot attributes), and apps/policies can be assigned to those groups.
- Autopilot and VMs (Hyper‑V / ESXi)
Autopilot can be used with virtual machines as long as they are registered as Autopilot devices (device hash captured and imported, or otherwise registered) and meet the same requirements as physical devices:
- For Microsoft Entra join: follow the “Step by step tutorial for Windows Autopilot user‑driven Microsoft Entra join in Intune” workflow:
- Set up Windows automatic Intune enrollment.
- Allow users to join devices to Microsoft Entra ID.
- Register the VM as a Windows Autopilot device.
- Create a device group.
- Configure and assign the Enrollment Status Page.
- Create and assign the Windows Autopilot profile.
- (Optional) Assign the Autopilot device to a user.
- Deploy the device.
- For Microsoft Entra hybrid join: follow the “Step by step tutorial for Windows Autopilot user‑driven Microsoft Entra hybrid join in Intune” workflow:
- Set up Windows automatic Intune enrollment.
- Install the Intune Connector for Active Directory on a domain‑joined server and ensure it shows as Active with a supported version.
- Increase the computer account limit in the target OU if needed.
- Register the VM as a Windows Autopilot device.
- Create a device group.
- Configure and assign the Enrollment Status Page.
- Create and assign the Microsoft Entra hybrid join Autopilot profile.
- Configure and assign a domain join profile.
- (Optional) Assign the Autopilot device to a user.
- Deploy the device.
Autopilot does not depend on whether the device is physical or virtual; it depends on the device being registered as an Autopilot device and able to reach the required cloud services during OOBE.
Summary:
- Plain Entra join during OOBE with just a corporate email cannot enforce an initial naming convention from Intune.
- To control naming and automatic grouping, configure Windows Autopilot with a deployment profile and device naming template, and assign it to Autopilot‑registered devices.
- The same Autopilot workflows apply to VMs in Hyper‑V or ESXi as long as they are properly registered and meet connectivity requirements.
References:
- Deploy Microsoft Entra hybrid joined devices by using Intune and Windows Autopilot
- Step by step tutorial for Windows Autopilot user-driven Microsoft Entra hybrid join in Intune
- Pre-provision Microsoft Entra hybrid join: Set up Windows automatic Intune enrollment
- Step by step tutorial for Windows Autopilot user-driven Microsoft Entra join in Intune
- Pre-provision Microsoft Entra join: Set up Windows automatic Intune enrollment