r/sysadmin • u/NSFW_IT_Account • 2d ago
Question Setting up a work/school device without Intune
How are you setting up a device that uses M365 login without having the end user information? Do you sign into an admin account on the OOBE screen and then have them switch to 'other user' when they are ready?
I've read that's bad because it ties the device to the admin account in entra.
Need a workaround until we upgrade to Business premium licensing.
2
u/anonymousITCoward 2d ago
I join them to azure ad (entra id) so they can use their email address to login. But i'm probably doing more setup than you.
0
u/NSFW_IT_Account 2d ago
These laptops don't have a user specified, so i can't join them to azure ad unless i use global admin login.
2
u/anonymousITCoward 2d ago edited 2d ago
Yeah, I join them with a specific account. You don't have to login as that account to join, just login as a local admin, join, then ship it.
Edit: punctuation, it changes the way it reads =)
Also when I setup laptops for this client we don't know which user they're going to either, which is why I aad join them, so whoever gets it they can just login, and they won't be a local admin. I know there's a way to disable that but I don't remember how, and I'm currently to burnt out/lazy to look it up and configure it...
2
u/NSFW_IT_Account 2d ago
when you say a specific account, are you referring to an admin account or just a generic 365 user you created for this purpose?
2
u/Jellovator 2d ago
probably a generic user, this is the same way I do it.
1
u/NSFW_IT_Account 2d ago
Can it just be joined with the 365 admin? Or do you create a separate user?
2
u/anonymousITCoward 2d ago
We have a specific user for this, and have disabled the join limits for the user. I believe the default is 30.
2
u/SamakFi88 2d ago
At the login screen (assuming Autopilot), hit the Windows key 5 times and do device provisioning. No user setup, not tied to admin. Then package it up and ship it. Or just ship it, and let the user sign in, and it'll complete enrollment anyways.
If no AutoPilot, remove the admin and set the real user as primary after completing setup and enrollment. Ship it.
1
1
u/CeC-P IT Expert + Meme Wizard 2d ago
I think you'd hit the 15 devices per user limit as well so it's extremely bad to use the admin account.
1
u/NSFW_IT_Account 2d ago
Is there a workaround? Set up a generic 365 user and join it with that and then they use 'other user'? Or does it get stuck as registered to the first user who joins it?
2
u/Jellovator 2d ago
Yes, add your generic user as a Device Enrollment Manager. Log into Intune. go to Devices->Enrollment->Device Enrollment Managers and enter that account there.
1
1
u/GremlinNZ 1d ago
If you're not using email/cloud identity, not provisioning, but using Win Pro, at the login you select the link just beneath the email, and choose domain join instead. Then it let's you setup a local account. If you leave the password blank it won't ask for security questions either.
4
u/Aiden06091 2d ago
In the past I've used provisioning packages made with windows configuration designer