You are preparing infrastructure for Microsoft Intune enrollment of Windows 11 devices. The company uses Microsoft Entra ID and requires that devices automatically enroll in Intune when users join them to Microsoft Entra ID. You also need to ensure that only users in a specific security group are allowed to enroll devices. What should you configure?
Automatic MDM enrollment is enabled from the Intune portal, and the Microsoft Entra ID mobility settings include an MDM user scope that can be set to a specific security group. Setting the scope to that group ensures only its members are automatically enrolled in Intune when they join devices to Microsoft Entra ID, meeting both requirements.
Why this answer
Automatic enrollment is turned on in the Intune admin center, while the user scope that determines who is eligible is configured in the Microsoft Entra ID mobility settings. Pointing the MDM user scope at the chosen security group restricts automatic Intune enrollment to those users, which is exactly what the scenario requires.
Exam trap
The trap here is confusing enrollment restrictions or Conditional Access with the MDM user scope, which is the actual control for who can automatically enroll.