You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?
Device enrollment restrictions in Intune let you control which platforms and personal ownership types can enroll. By blocking personally owned Windows devices while allowing corporate-owned ones, you prevent personal devices from enrolling as managed endpoints. Users can still access email through a browser because browser access is governed by conditional access, not enrollment restrictions, so the requirement is met.
Why this answer
Enrollment restrictions in Intune are the mechanism for controlling whether personally owned devices can enroll for a given platform. By blocking personal Windows ownership while allowing corporate ownership, only corporate devices enroll. Because browser-based email access is controlled separately through conditional access, personal devices can still reach email in a browser without being enrolled.
Exam trap
The trap here is confusing enrollment restrictions, which gate enrollment, with compliance or conditional access policies, which evaluate or gate access after enrollment.