Azure AD enrollment

Configure > MDM Configurations > Microsoft > Azure AD enrollment (Autopilot)

By linking Azure Active Directory and your CSA, you can automatically enroll corporate-owned Windows 10 devices during device setup and pre-configure them with policies and settings for a custom out-of-box experience. You can also enroll devices owned by users defined in your Azure AD at any time. For information about configuring the device setup process with Azure AD, see Microsoft's Autopilot Profiles Guide.

NOTE: A CSA can only connect to a single Azure AD account. If you have multiple Azure AD accounts you would like you use with Autopilot, you will need to set up an additional CSA for each account.

To configure Azure Active Directory enrollment

1.Log in to the Azure AD Portal.

2.Navigate to Azure Active Directory > Mobility (MDM and MAM).

3.Click Add application.

4.Click On-premises MDM application settings.

5.Enter a name for the application, and click Add.

6.Use the MDM user scope slider to select which users this configuration applies to. If you select Some, you can select which Azure AD user groups you would like to include. For information about creating users and user groups, see Microsoft's documentation Add or delete users using Azure Active Directory.

7. In both the MDM terms of use URL field and the MDM discovery URL field, enter the following address with the information for your CSA and core.

https://[CSA]:444/rtc/[Core]/MDM/api/v1/enroll/WindowsDiscovery

8.Click Save.

9.Click On-premises MDM application settings.

10.Click the Application ID URI and enter the following address with your CSA information.

https://[CSA]:444

11.Copy the Directory (tenant) ID.

12.In the Endpoint Manager console, navigate to Tools > Modern Device Management > MDM configurations > Microsoft > Azure AD (Autopilot).

13.In the App ID URI field, enter the following address with your CSA information.

https://[CSA]:444

14.In the Directory ID field, paste the ID you copied from the Azure AD Portal.

15.In the MDM Configurations navigation tree, click Enrollment Agreement.

16.Click Upload to select your enrollment agreement .html file, then click Save. For more information about enrollment agreements, see Enrollment agreements.

You can also create a deep link for Azure AD enrollment. For more information, see Deep link enrollment.

For information about deploying the agent after MDM enrollment, see Installing the agent for hybrid management.

User Experience

Out-of-box experience. During the initial device setup, the user enters their corporate credentials on the Sign in with Microsoft work or school account screen. They are shown the enrollment agreement configured in Endpoint Manager. If they accept the agreement, the device enrolls and walks them through the rest of the Windows setup.

Bring your own device. The user navigates to Windows Settings > Accounts > Access work or school. They click Connect and enter their corporate credentials. They are shown the enrollment agreement configured in Endpoint Manager. If they accept the agreement, the device enrolls.