Device Enrollment Manager - Enrolling a Device in Microsoft Intune (2024)

Article Summary

Share feedback

Thanks for sharing your feedback!

Device Enrollment Manager - Enrolling a device in Microsoft Intune

The Device Enrollment Manager (DEM) is a kind of service account. These accounts have permissions that let authorized users enroll and manage multiple corporate-owned devices. A DEM account requires an Intune user or device license, and an associated Azure AD user.

DEM is an Intune role/permission that can be applied to an Azure AD user account, and they can enroll up to 1000 devices. A DEM account is useful for scenarios where devices are enrolled & prepared before handing them out to the users of the devices. There’s a limit of 150 Device Enrollment Manager accounts in Microsoft Intune. DEM enrolls Windows 10/11 devices.

  1. Pre-requisite to create DEM accounts
  2. Add a device enrollment manager
  3. Enrolling a device in Microsoft Intune
  4. To remove a device enrollment manager user

1. Prerequisite to create DEM accounts

Global Administrator or Intune Administrator. An Azure AD user with the above-mentioned role can perform the following tasks:

  • Assign DEM permission to an Azure AD user account
  • See all DEM users

2. Add a device enrollment manager

  1. Sign in to the Microsoft Endpoint Manager admin center and choose Devices > Enroll devices > Device enrollment managers.
  2. Select Add.
  3. On the Add User, enter a user principal name for the DEM user, and select Add. The DEM user is added to the list of DEM users.
    Device Enrollment Manager - Enrolling a Device in Microsoft Intune (1)
  4. User added as a DEM has Intune license:
    Device Enrollment Manager - Enrolling a Device in Microsoft Intune (2)

3. Enrolling a device in Microsoft Intune

Now Switch to your Windows 10 machine to enroll a device

  1. Right-click on Windows > Settings > Accounts
  2. Access Work or School Account and then click Connect.Device Enrollment Manager - Enrolling a Device in Microsoft Intune (3)
  3. Click on Join this device to Azure AD Directory and add DEM user credentials and click on Next and Sign In.Device Enrollment Manager - Enrolling a Device in Microsoft Intune (4)
  4. Click on Joinand then click on Done.Device Enrollment Manager - Enrolling a Device in Microsoft Intune (5)
  5. In the next window, the DEM user is connected to Azure AD.
    Device Enrollment Manager - Enrolling a Device in Microsoft Intune (6)
  6. Now restart the machine with the same user.
  7. Sign in to the Microsoft Endpoint Manager admin center and choose Devices > All devices. You will see your device enrolled and managed by Intune.Device Enrollment Manager - Enrolling a Device in Microsoft Intune (7)
  8. Once the device is enrolled, follow this link to deploy MSI to Intune managed device: Deployment of MSI packages through Microsoft Intune

Only the Intune admin has the capability to perform a wipe or remove any enrolled device and that is through the Microsoft Endpoint Manager admin center only.

4. To remove a device enrollment manager user

  1. Sign in to the Microsoft Endpoint Manager admin center, and choose Devices > Enroll devices > Device enrollment managers.
  2. On Device enrollment managers, select the DEM user and select Delete.

Device Enrollment Manager - Enrolling a Device in Microsoft Intune (8)

How to deploy the MSI package to an enrolled device through Microsoft Intune.

Was this article helpful?

Device Enrollment Manager - Enrolling a Device in Microsoft Intune (2024)
Top Articles
Latest Posts
Article information

Author: Melvina Ondricka

Last Updated:

Views: 5941

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Melvina Ondricka

Birthday: 2000-12-23

Address: Suite 382 139 Shaniqua Locks, Paulaborough, UT 90498

Phone: +636383657021

Job: Dynamic Government Specialist

Hobby: Kite flying, Watching movies, Knitting, Model building, Reading, Wood carving, Paintball

Introduction: My name is Melvina Ondricka, I am a helpful, fancy, friendly, innocent, outstanding, courageous, thoughtful person who loves writing and wants to share my knowledge and understanding with you.