Part 17 – Configure Microsoft Intune – Corporate Device Identifiers

Import a device or multiple devices into Intune based on a CSV file. This is one of the options if you want to block personal devices. With this block the user cannot enroll his device into Intune just like that. The device must first be identified as a corporate owned device. How this trick works in Intune? Please continue, because this time it is about Corporate device identifiers.

Why should I assign the device as corporate-owned?

To refine management and identification. Intune can perform additional management tasks and collect additional information such as the full phone number and an inventory of apps from corporate-owned devices.

When is the device corporate-owned?

Within Intune you have multiple options to enroll the device. You have:

  • For iOS – Device Enrollment Program (DEP), Apple School Manager or Apple Configurator.
  • For Windows – Azure Active Directory join.
  • For Samsung device only – Knox enrollment.

With these options the device will be assigned automatically as corporate-owned.

There are also options to assign manually the device as corporate-owned, which are:

  • By a CSV list. (Mostly if your organization uses different types of Android device)
  • By manually to change the ownership per device to corporate.
  • Enrolled with a Device Enrollment Manager account (for all platforms)

If you have block personally owned in Enrollment restrictions, the user cannot enroll his device into Intune just like that. If the device is enrolled by DEP, Azure AD join or Knox then the device will be assigned automatically as corporate-owned. If you have a device which are not compatible with DEP, Azure AD join or Knox, then you have to use CSV file. By importing from a CSV file, the device will be assigned as corporate-owned and gives also the user permission to enroll the device.

Alrighty then, let’s try this out

First, we have to block personal devices.

Go to the Intune portal -> Device enrollment -> Enrollment restrictions

Click on Default

Click on Properties and then on Configure platforms.

Click on the block button beneath Personally owned. Click on the Ok button.

Click on the save button. Now it is not possible to enroll the device by user itself, because it will identify as a personal. The enrollment must be initiate via Intune, by DEP. Knox or manually by importing the CSV file.

Let’s try on the Android device

If you don’t have the Intune Company Portal app already, please download and install the app from the App store.
Open Intune Company Portal
Sign in.
Enter here your email address/login name.
Enter here your password.
The app is connecting to Intune.
Checking for security requirements
Continue
Continue
Next
Allow
Scroll down for more options.

Activate this device administrator.

Processing, adding your device to Company Portal.
This is the message you get if enrolling the device as a personally device.

Sign out.

You are back at the sign in page.

You see that a personal device is not allowed to enroll into Intune. You must make this device as a corporate owned device. Before you do that, you have to find the serial and/or IMEI number from your device. You will need this for the following steps.

Go to the settings of your device and touch on About phone.
Touch on Status.
Touch on IMEI information.
Here you can find the IMEI numbers. If your device has more than 1 IMEI then you have to use the one which will be used for enrollment.

Note the one which you are going to use.

Now that you have the IMEI number, you have to add this into a CSV file. CSV must be based on a two-column, comma-separate value without a header. The first one is for the serial or IMEI number. The second column is for details. Details are limited to 128 characters and are for administrative use only. Details aren’t displayed on the device. Limit of a CSV file is 5,000 rows per .csv file.

Save as a CSV file on your hard drive.

Go back to the Intune portal.

Go to the Intune portal -> Device enrollment -> Corporate device identifiers. Click on the button Add.

Choose for IMEI and browse to your CSV file. Click on the button Add.

Click on the button Refresh to refresh the list. You see your imported device in the list. Now is your device identified as a corporate device. Please continue with enrolling your device.

Let’s try

Open the Intune Company Portal app.
Sign in.
Enter here your email address/login name.
Enter here your password.
The app is connecting to Intune.
Checking for security requirements
Continue
Continue
Next
Allow
Scroll down for more options.

Activate this device administrator.

Processing, adding your device to Company Portal.
Processing, the final steps.
And the enrollment has finished with success.

Done

Now you are in the Company Portal. You see a number 1 beside the flag. Touch it, this will open notifications.
The ownership is changed to corporate. This is because of the import and identified as corporate.

After enrollment, check All devices in Intune. The device is marked as corporate.

If you go back to Device enrollment -> Corporate device identifiers, then you see that the state is changed into Enrolled.

Final

This is how Corporate Device identifiers works in Intune. This might come in handy if you are using Android devices which are not from Samsung. Samsung is the only one who using Knox for enrollment and MDM solution. With Apple and Windows is the best practice to use DEP and Azure AD join.

Thanks for reading this blogpost. If you have any questions or comments, don’t hesitate to contact me by email or post a comment on this blogpost.

Take care now, bye bye then.

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

w

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.