Registering devices with Intune for management and policy enforcement
Hello,
I found that clicking the blue "Restore default MDM URLs" and "Restore default WIP URLs" links fills in those URL fields automatically, then you will be able to save.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi,
I'm trying to setup OOBE on some laptops for the first time and I have everything working except it won't let me change the MDM User Scope from 'None' to 'All'. Just to be clear, I can actually click on All, but the save button remains greyed out. I am a global admin with a business premium license which I thought would be enough, but it remains greyed out.
Any help on whether something else needs to be configured first or if I don't have a high enough license would be helpful.
Here is more info:
I've setup run the powershell script to get the machine hash, it shows in my Deployment Profiles and my devices list in Intune, but when I go to try and enroll it on the laptop (shift+Ctrl+f3 and choose pre-deployment) it fails in the first stage. I've narrowed that down to the fact that I can't change automatic enrollment settings. The save button stays greyed out.
Thank you,
Mike
Registering devices with Intune for management and policy enforcement
Hello,
I found that clicking the blue "Restore default MDM URLs" and "Restore default WIP URLs" links fills in those URL fields automatically, then you will be able to save.
AI answer
The MDM user scope setting and the Save button are controlled by the Intune/MDM authority configuration and licensing. When the Save button is greyed out even though Global admin permissions are present, the usual causes are:
Use the following checks and configuration path to resolve it.
In the Azure portal:
This ensures the tenant’s MDM authority and automatic enrollment are correctly configured for Intune and that the MDM user scope is actually set to All or Some at the directory level.
In the Intune admin center:
From the documentation:
If Cloud PCs or other Windows devices show messages like “ask your administrator to update policy settings” or “remove restrictions preventing Intune from allowing Windows enrollment,” then:
Automatic MDM enrollment is a premium Microsoft Entra feature. If automatic enrollment settings are not available or not editable, ensure that:
Once MDM user scope is successfully set to All or Some and saved in the Mobility (MDM and MAM) configuration and in Intune’s Automatic Enrollment blade, OOBE/Autopilot enrollment should proceed past the first stage, and the pre-provisioning (white glove) flow should no longer fail due to automatic enrollment configuration.
References: