How to Automatically Enroll Users in Microsoft Intune
Your organization uses Microsoft 365 Business Premium. You need to ensure that when a user is assigned an Intune license, the device automatically enrolls in Microsoft Intune. What should you configure?
⚠ Common exam trap
Many exam-takers confuse device compliance policies or configuration profiles with the enrollment trigger, but only the Microsoft Entra ID device settings control the automatic MDM enrollment behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Microsoft Entra ID device settings to enable MDM automatic enrollment
Microsoft Entra ID (formerly Azure AD) device settings include an option to enable automatic MDM enrollment for users assigned an Intune license. When enabled, any device that signs in with a licensed user account will automatically enroll in Microsoft Intune, satisfying the requirement without additional configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure Microsoft Entra ID device settings to enable MDM automatic enrollment
Why this is correct
In Microsoft Entra ID, under Device settings, the 'Enable automatic enrollment for MDM' option (also known as MDM user scope) directs the identity provider to register and enroll devices into the configured MDM authority, Intune, as part of the user sign-in flow. Because every user in the organization holds a Microsoft 365 Business Premium license that includes Intune, toggling this setting causes their devices to automatically enroll upon authentication and license assignment. This is the only option that actively triggers enrollment; the other options are post-enrollment or pre-enrollment controls that do not initiate the enrollment process.
- ✗
Create a device compliance policy to require enrollment
Why it's wrong here
Compliance policies evaluate the compliance state of devices that are already enrolled in Intune. A policy that 'requires enrollment' might flag a device as noncompliant if it isn't enrolled, but it does not contain any logic or mechanism to perform the actual enrollment. Enrollment is a prerequisite for compliance evaluation; therefore, creating such a policy will not cause devices to enroll and is not a valid solution.
- ✗
Create a device enrollment restriction in Intune to block personal devices
Why it's wrong here
Device enrollment restrictions in Intune, such as platform or user restrictions, are enforced only when a device attempts to enroll. Configuring a restriction to block personal devices would actually prevent those devices from enrolling; it would not trigger any enrollment for other devices. These restrictions are evaluated after the enrollment request begins, not before, so they cannot initiate automatic enrollment on their own.
- ✗
Deploy a device configuration profile with enrollment settings
Why it's wrong here
Device configuration profiles in Intune are delivered to devices only after they have successfully enrolled; they manage settings, features, and security policies on already managed devices. The phrase 'enrollment settings' in a configuration profile refers to settings applied post-enrollment, not an enrollment trigger. Since enrollment must happen first for any configuration profile to reach the device, deploying such a profile cannot be used to automatically enroll devices.
Go deeper
Related to this question
Learn chapter
Tenant-Wide Settings and Org Profile
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft 365 Business Premium. You need to ensure that all Windows 10 devices are enrolled in Microsoft Intune and comply with a device compliance policy that requires BitLocker encryption and a minimum OS version. What should you do first?
easy- ✓ A.Configure automatic enrollment in Microsoft Entra ID for Windows 10 devices.
- B.Install the Intune Connector for Active Directory on a domain controller.
- C.Deploy a configuration profile to enable BitLocker.
- D.Create a device compliance policy in Microsoft Intune.
Why A: To enforce Intune compliance policies on Windows 10 devices, the devices must first be enrolled in Intune. Automatic enrollment in Microsoft Entra ID (formerly Azure AD) is the prerequisite step that enables Windows 10 devices to automatically enroll in Intune when they join or are registered with Entra ID. Without this enrollment configured, no Intune policies—including compliance policies—can be applied to the devices.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.