Session Objective

I logged the full handoff in Notion here: Intune Enrollment Pilot Handoff — 2026-04-24

What I already verified

Open These In Notion On The Windows Side

Inline Handoff

  1. Pick pilot Windows 10/11 workstation. Do not start with servers.
  2. On the pilot, run:

dsregcmd /status

  1. What we want:
  2. If DomainJoined : YES but AzureAdJoined : NO, stop there. Hybrid join is the missing prerequisite.
  3. In Entra, confirm the pilot user is inside the automatic MDM enrollment scope.
  4. In Group Policy, enable: