Device Enrollment Manager - Enrolling a device in Microsoft Intune

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The Device Enrollment Manager (DEM) is a kind of service account. These accounts have permissions that let authorized users enroll and manage multiple corporate-owned devices. A DEM account requires an Intune user or device license, and an associated Azure AD user.

DEM is an Intune role/permission that can be applied to an Azure AD user account, and they can enroll up to 1000 devices. A DEM account is useful for scenarios where devices are enrolled & prepared before handing them out to the users of the devices. There's a limit of 150 Device Enrollment Manager accounts in Microsoft Intune. DEM enrolls Windows 10/11 devices.

  1. Verify prerequisites for DEM accounts

    Global Administrator or Intune Administrator. An Azure AD user with the above-mentioned role can perform the following tasks:

    • Assign DEM permission to an Azure AD user account
    • See all DEM users
  2. Add a device enrollment manager
    1. Sign in to the Microsoft Endpoint Manager admin center and choose Devices > Enroll devices > Device enrollment managers.
    2. Select Add.
    3. On the Add User, enter a user principal name for the DEM user, and select Add. The DEM user is added to the list of DEM users.
  3. Enroll a device in Microsoft Intune

    Now Switch to your Windows 10 machine to enroll a device

    1. Right-click on Windows > Settings > Accounts
    2. Access Work or School Account and then click Connect.
    3. Click on Join this device to Azure AD Directory and add DEM user credentials and click on Next and Sign In.
    4. Click on Join and then click on Done.
    5. Verify that the DEM user is connected to Azure AD.
    6. Restart the machine with the same user.
    7. Sign in to the Microsoft Endpoint Manager admin center and choose Devices > All devices. You will see your device enrolled and managed by Intune.
    8. Once the device is enrolled, follow this link to deploy MSI to Intune managed device: Deployment of MSI packages through Microsoft Intune

    Only the Intune admin has the capability to perform a wipe or remove any enrolled device and that is through the Microsoft Endpoint Manager admin center only.

  4. Remove a device enrollment manager user (if needed)
    1. Sign in to the Microsoft Endpoint Manager admin center, and choose Devices > Enroll devices > Device enrollment managers.
    2. On Device enrollment managers, select the DEM user and select Delete.

How to deploy the MSI package to an enrolled device through Microsoft Intune.