New Windows corporate device identifier feature with Microsoft Intune: Everything you need to know (2024)

By: Madison Holdaas, Sr. Product Manager | Microsoft Intune

How identifying corporate devices has worked in Microsoft Intune

As an administrator, you want to make sure that only authorized and compliant devices can access your organization's resources and data. To do that, you need to identify which devices are corporate-owned and which are personal. However, this isn’t always easy, especially when you have a large and diverse fleet of devices running different operating systems and platforms.

Today, Intune has a variety of methods to identify a device as “corporate” for Windows platform. If a device hasn’t enrolled using one of our true corporate methods,we do our best to determine an unknown device’s ownership by how the user enrolled the device. For instance, if a user automatically enrolls by registering the device toMicrosoft Entra through Windows settings, then we determine that device to be corporate. If a user automatically enrolls by adding a work account from Windows settings instead, then the device is marked personal by Intune.

How enrollment restrictions have worked when blocking personal devices

One way to prevent personal or unknown devices from enrolling in your tenant is to use enrollment restrictions. Enrollment restrictions are policies that you can create and assign to groups of users or devices to control who can enroll which devices and how many. You can create two types of enrollment restrictions: device type restrictions and device limit restrictions.

Device type enrollment restrictions allow you to block or allow specific types of devices from enrolling, such as Windows, iOS, Android, or macOS. You can also block or allow for specific configurations, such as blocking personally owned or unknown devices. The setting to block personally owned devices prevents the following from being enrolled, even though they are assumed corporate by Intune when allowed to enroll:

  • Automatic MDM enrollmentwithMicrosoft Entra join during Windows setup
  • Automatic MDM enrollmentwithMicrosoft Entra join from Windows Settings
  • Automatic MDM enrollmentwith Microsoft Entra join or hybrid Entra join viaWindows Autopilot for existing devices

New corporate device identifiers for Windows

The new Windows corporate identifier feature is a solution that can help you identify and manage your corporate Windows devices more easily and securely. The feature allows you to upload a CSV file with the serial number, manufacturer, and model of your known Windows devices to your tenant. This marks the devices as corporate in the Microsoft Intune admin center and applies the appropriate policies and settings to them once they enroll into your tenant. Note that the feature only works for Windows 11, version 22H2 and later withKB5035942 (OS Builds 22621.3374 and 22631.3374) or newer.

Important: Enrollment device type restrictions are only editable by the Intune Service Administrator or Global Administrator. Corporate device identifiers have their own permission that must be assigned. Since these permissions are not the same, confirm that any existing enrollment restrictions will not be impacted before uploading a corporate device identifier.

To use the new feature, follow these steps:

  1. Create a CSV file with the serial number, manufacturer, and model of your corporate Windows devices. You can use any tool or method to generate the CSV file, as long as it follows the format and requirements specified in the documentation.
  2. In the Intune admin center, upload the CSV file to your tenant. You can find the upload option under Devices > Windows > Corporate identifiers. You can upload up to 5,000 devices or 5MB in a CSV. If you need to upload more, we recommend using PowerShell and interacting with the Microsoft Graph API directly.
  3. Verify that the upload was successful and that the devices are marked as corporate in the Intune admin center. You can view the status and details of the upload under Devices > Windows > Corporate identifiers. You can also view the device ownership and other properties of the devices under Devices > All devices.

New Windows corporate device identifier feature with Microsoft Intune: Everything you need to know (1)A screen capture of adding a corporate identifier in the Intune admin center.

Some enrollment methods will always be considered corporate enrollment because we trust devices enrolling through these methods are known devices. Once an admin has uploaded a single Windows corporate identifier, the way we define Corporate and Personal changes to the following in the table:

Windows enrollment types

Without corporate identifiers

With corporate identifiers

The device enrolls throughWindows Autopilot

Corporate

Corporate

The device enrolls through GPO, orautomatic enrollment from Configuration Manager for co-management

Corporate

Corporate

The device enrolls through abulk provisioning package

Corporate

Corporate

The enrolling user is using adevice enrollment manager account

Corporate

Corporate

The device enrolls through Azure Virtual desktop (non-hybrid)

Corporate

Corporate

Automatic MDM enrollmentwithMicrosoft Entra join during Windows setup(Including new Autopilot device preparation profiles)

Corporate, but blocked by Personal enrollment restriction

Personal

Automatic MDM enrollmentwithMicrosoft Entra join from Windows Settings

Corporate, but blocked by Personal enrollment restriction

Personal

Automatic MDM enrollmentwith Microsoft Entra join or hybrid Entra join viaWindows Autopilot for existing devices

Corporate, but blocked by Personal enrollment restriction

Personal

Automatic MDM enrollmentwithAdd Work Account from Windows Settings

Personal

Personal

MDM enrollment onlyoption from Windows Settings

Personal

Personal

Enrollment using the Intune Company Portal app

Personal

Personal

Enrollment via a Microsoft 365 app, which occurs when users select theAllow my organization to manage my deviceoption during app sign-in

Personal

Personal

Admins that want to use the existing enrollment method logic to determine corporate versus personal (i.e. the “Without corporate identifiers” column) can just delete or remove all Windows corporate identifiers and ownership goes back to behaving as previously done in Intune.

New enrollment restriction experience using model and manufacturer device properties in filters

The new Windows corporate identifier feature also enables a new enrollment restriction experience that allows you to use the model and manufacturer device properties in filters to block devices from enrolling more granularly. You can block specific models or manufacturers of Windows devices from enrolling, such as Manufacturer = Microsoft or Model = VM. Note that model and manufacturer properties only work for Windows 11 version 22H2 and above at enrollment time.

To use the new enrollment restriction experience, navigate to the Intune admin center and follow these steps:

  1. Create a device filter with the model and manufacturer device properties. You can find the device filter option under Devices > Filters. You can create up to 100 device filters per tenant, and each device filter can have up to 10 conditions.
  2. Create an enrollment restriction policy with the device filter. You can find the enrollment restriction option under Devices > Enrollment> Device platform restrictions. You can assign the device filter to your enrollment restriction policy in the Assignments tab.
  3. Assign the enrollment restriction policy to a group of users. You can assign the policy to any group that you have created or synced in your tenant, such as security groups or dynamic groups. You can also assign the policy to the default group, which applies to all users in your tenant. Reminder that enrollment restrictions are user based – so they don’t apply to user-less enrollments.

New Windows corporate device identifier feature with Microsoft Intune: Everything you need to know (2)A screen capture of creating a filter in the Intune admin center, using model and manufacturer device properties.

Note that since model and manufacturer properties only work for Windows 11 version 22H2 and above – to address unsupported versions – we recommend including the null values of manufacturer and model.

Note – Windows 10 will be a supported feature starting July 9th – devices will need to be updated to the following KB: KB5039299.

With this new feature, you can easily distinguish between corporate and personal devices and apply different enrollment policies accordingly. Additionally, you can leverage the model and manufacturer device properties to create more granular filters to block unwanted devices from enrolling.

If you have any questions or feedback, leave a comment below or reach out to us on X @IntuneSuppTeam.

New Windows corporate device identifier feature with Microsoft Intune: Everything you need to know (2024)

FAQs

How does Intune identify devices? ›

Intune reads and records one IMEI per enrolled device. If you import an IMEI that's different from the one already in Intune, Intune will mark the device as personal. If you import multiple IMEI numbers for the same device, the identifiers that haven't been inventoried appear with an unknown enrollment status.

Which 3 features does Microsoft Intune support? ›

Microsoft Intune is a safe and secure cloud-based solution that gives IT administrators control over mobile devices, apps, and data. Intune offers multiple security features like device management, application management, data protection, and conditional access for your organization's devices and information.

What is the unique device ID in Intune? ›

Hardware device details
DetailDescription
UDIDThe device's Unique Device identifier.
Intune Device IDA GUID that uniquely identifies the device.
Serial numberThe device's serial number from the manufacturer.
Shared deviceIf Yes, the device is shared by more than one user.
41 more rows
Nov 29, 2023

How to add corporate device identifiers? ›

You can find the upload option under Devices > Windows > Corporate identifiers. You can upload up to 5,000 devices or 5MB in a CSV. If you need to upload more, we recommend using PowerShell and interacting with the Microsoft Graph API directly.

Can MDM see browsing history? ›

Without the user's approval, the MDM software is not allowed to collect information. Furthermore, it's unable to gain permission secretly. Because the MDM software must comply with app developer policies. Take Android and Apple for instance.

Can Intune company portal wipe my phone? ›

Microsoft Intune, a robust mobile device management (MDM) solution, offers an array of features, including the ability to perform remote device wipes.

What is the difference between personal and corporate devices in Intune? ›

Corporate-owned devices

Microsoft Intune offers more granular settings and policies for devices classified as corporate-owned or organization-owned. There are more password settings available for corporate-owned devices. So, you can enforce stricter password requirements.

How to tell if a device is managed by Intune? ›

To check if your computer is managed by Intune, go to myaccount.microsoft.com and click on Devices. Click on your device name and look for "Device is managed by Intune." This means that your computer is neither joined to Azure AD nor registered in Azure AD as personal device.

How many devices can a user have in Intune? ›

Configure Intune device limit restrictions to limit the number of devices a user can enroll in Microsoft Intune. You can allow a user to enroll up to 15 devices.

How does Intune determine ownership? ›

Some Android and iOS/iPadOS devices have multiple IMEI numbers. Intune only reads one IMEI number per enrolled device. If you import an IMEI number but it is not the IMEI inventoried by Intune, the device is classified as a personal device instead of a corporate-owned device.

What needs to happen before you can begin managing a device with Intune? ›

All aspects of Microsoft Intune devices management begin with the same step: device enrollment. The enrollment process requires Intune to install a mobile device management (MDM) certificate on the device that allows Intune to communicate with it directly.

What do device identifiers do? ›

Device identifiers let Google know which unique device you are using to access our services, which can be used to customise our service to your device or analyse any device issues related to our services. You may be able to view the Android devices you are using here: www.google.com/android/find/.

How does Intune communicate with devices? ›

Users "enroll" their devices, and use certificates to communicate with Intune. As an IT administrator, you push apps on devices, restrict devices to a specific operating system, block personal devices, and more.

How do devices check in with Intune? ›

When you target a device or user with an action, then Intune immediately notifies the device to check in to receive these updates. For example, a notification happens when a lock, passcode reset, app, or policy assignment action runs.

How does Microsoft find my device work? ›

Find your Windows device

Go to https://account.microsoft.com/devices and sign in. Select the Find My Device tab. Choose the device you want to find, and then select Find to see a map showing your device's location.

Can Intune detect whether a device is jailbroken? ›

Intune can enforce compliance policies such as detection of jailbroken devices, weak passwords, unwanted applications, and operating systems that have not been updated.

References

Top Articles
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 5973

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.