We have been testing Entra and Intune as a solution for our company. We have configured devices to auto-enroll into Intune. If we remove the auto-enroll MDM URLs from Intune (by setting the MDM User Scope to None instead of All), can we re-enable them if needed?

And what is the effect to workstations already enrolled? I would imagine it wouldn’t do anything. But I wanted to know. We are asking this cause we have a user that has an Azure AD Premium Plan 1 license, but not an Intune license. So when they go to log into a brand new laptop, we receive a message about not being able to contact the MDM Terms of use URL. We figured it was cause they do not have an Intune license.

5 Spice ups

You can set those to none and then re-enable them later, if you need to for testing.

The machine should ignore any later commands to enroll, as it’s already enrolled.