Steve Winer from GetRubik.com explains a new Microsoft Intune feature designed to prevent personal Windows PCs from inadvertently enrolling into an organization's Intune management. This setting allows users to access work applications on personal devices by registering with Entra ID, without triggering the problematic full MDM enrollment that grants corporate control over personal computers.
0:00 I don't know if you've tried to explain AI to your your parents yet. I mean, this is an incredible experience. And my mom was struggling to understand who was responding from the AI program. She kept referring to them as they. Well, how do they know what you want? Where are they getting the information? There seemed to be a real struggle with the fact that these aren't human beings. Then she hit me with a profound question. Are they the same people that tell me my email password is wrong? Steve Winer here from getrubik.com and today I'm gonna show you a new feature in Intune, one that I think we've all been waiting for. A way to keep personal intrar devices out of intoune. I said, "Mom, forget about AI. Don't worry about what they're telling you. Just just enjoy your baked potato soup at Chili's. Mom and dad are big fans of chili. Get Rubik's [music] solving for the modern workplace.
1:01 >> Okay, so let's talk about a common scenario. I'm on a personal computer here. I want to sign into one drive to maybe get my files from work and I'm going to be prompted to sign in. So let's go ahead and use our credentials. Rubikdev.com. Okay, we got our prompt to sign in. It's all harmless. And then you get this. Uh most folks [music] don't read this and that's kind of been the problem. It's asking me if I want to sign in uh to all apps, websites, and services on this device with my work account. Now, if we read this carefully, if I choose yes, the device will be registered to the organization. So, let's go ahead and check that out. Uh allow your organization to manage your device, right? So, this is part of that uh enrollment. will say yes. The reason I'm clicking yes there is because I think most folks will click yes. We tend to do that on our computer and if someone's not paying attention or reading, they just think, okay, I'll just keep clicking yes till I get my email on my computer or my one drive or sign into office. And this happens all the time because I see the other end of it. All right, so we'll let one drive do its thing. I got what I wanted. I signed in.
2:15 Let's go look in in tune. Type in the name here. The device is here in in tune um with a personal ownership. When we look at the device itself and we want to go to the settings work school there's the account we added managed by Rubik's dev. So if we take a look the inune management extension has been installed and if I do a quick uh command prompt ds cmd status. Yeah we can see I'm already getting the notification for encryption. Yep. So, we've now been enrolled in Intune. So, this is not good because this is our personal device. This is really not what we want. Now, this has been going on for a long time and it's very frustrating because unless you put constraints in front of who can register and things like that, there's really no way to stop this. And and most organizations I work with wind up looking at in tune and wondering why they have all these personally registered devices. And yes, it's more of a problem for the end user because now their personal stuff is managed, but an organization doesn't want just rogue devices showing up. So, what is the answer to this? Uh, there really hasn't been a good one until recently with a new feature that's in public preview uh that you could set in the Intune enrollment settings. So, the new setting is found in devices enrollment and then automatic enrollment. And this is where you would usually scope your Windows [music] enrollment to intoune. Take a look at this. disable MDM enrollment when adding work or school account on [music] Windows. If we turn this on to yes, we're going to have a very different experience. So, let's hit save on that policy. And I'm also going to reset this uh [music] VM which is already gotten company portal and is very much part of the org now. So, we better do something fast here. Okay. So, I'm reapplying the previous checkpoint and I'm going to remove the device from uh from Entra.
4:12 So, it's not there. All right. So, the device has been snapshotted back and we're going to try something different this time. We'll do Outlook. Same thing, right? We're going to sign in with our work school account. We're going to sign in. So, we can say yes just like we normally would. The device is going to register. But notice we didn't get that second prompt, right? Do we want to allow our organization to manage this [music] device? All it did was register. So, let's go back now. We'll refresh the page. And there's our device again. Showed back up. It's registered, but there's no MDM. And let's look at the account settings and see what it looks like from the devices side. So, if we go to accounts and then access worker school. So, the account is there, but notice there's no manage option [music] with an info thing here because it didn't enroll anywhere. So, it's literally just registered. And now I don't have to worry about the device falling into in tune enrollment.
5:18 It'll just stay in this registered state and MDM will remain none. I'm not saying you necessarily want personal registered devices in Entra. Uh obviously you should have policy preventing folks from getting their email accessing one drive if that's what you want which makes a lot of sense. However them ending up in in tune we can completely put a stop to now especially if folks aren't paying attention and they're just clicking yes through the options. So I highly recommend unless you have a good reason for this you go in you switch that option to on. That'll disable that second prompt you see when users are signing into office apps, anything native, if they're adding the account and settings. And uh hopefully this will solve the problem. We'll be seeing you.
6:07 >> [music]