PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteFor a current deployment, use Configuration Manager’s Cloud Attach Configuration Wizard and Microsoft’s current co-management guidance—not setup instructions written for SCCM Current Branch 1709/1710. You can enroll a pilot of eligible devices in Intune while leaving every management workload with Configuration Manager; switch a workload only after its Intune policies are ready and tested.
What Configuration Manager and Intune co-management does
Co-management lets a supported Windows device be managed by both the Configuration Manager client and Microsoft Intune. It does not automatically transfer policies or applications, and enabling it does not require you to move any workload on day one. Configuration Manager remains authoritative for workloads you have not switched; Intune manages a workload only after you assign that authority to Intune. See Microsoft’s co-management overview.
Co-management is different from tenant attach, which connects a Configuration Manager environment to cloud experiences without, by itself, enrolling a device in Intune or changing its workload authority. It is also different from Microsoft Entra hybrid join: hybrid join gives a domain-joined device a cloud identity, but is not co-management. The original HTMD guide documents an early implementation and uses historical terminology; its 1709/1710-era setup should not be treated as a current runbook (HTMD’s original guide).
Current terms for older guides
| Older term | Current meaning |
|---|---|
| SCCM or SCCM CB | Configuration Manager, or Configuration Manager current branch |
| Azure AD | Microsoft Entra ID |
| Microsoft Endpoint Manager admin center | Microsoft Intune admin center and its current experiences |
| Co-management wizard | Cloud Attach Configuration Wizard or the current co-management enablement workflow |
| Cloud DP or CDP | Legacy Cloud Distribution Point terminology; do not assume one is required |
| Intune workload | A supported management area whose authority has been moved to Intune |
Since Configuration Manager version 2111, the Cloud Attach Configuration Wizard provides the newer onboarding experience. Use a supported current-branch release and check the guidance for your installed version; do not plan around Windows 10 version 1709 as a current requirement. Microsoft’s enablement procedure describes the current workflow.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Choose an onboarding path
Existing Configuration Manager clients
This is the usual route for domain-joined or hybrid-joined corporate devices already receiving Configuration Manager policy. Ensure existing Active Directory domain-joined clients are Microsoft Entra hybrid joined, configure Intune automatic MDM enrollment, and use Configuration Manager to enroll a selected collection. The clients can remain under Configuration Manager workload authority while you validate enrollment and prepare Intune policies. Microsoft describes the existing-client scenario in its co-manage clients tutorial.
New or Intune-managed internet devices
For cloud-native devices, the device can join Microsoft Entra ID and enroll in Intune first; Intune can then deploy the Configuration Manager client. A Cloud Management Gateway (CMG) is relevant when an internet-based device must install or communicate with the Configuration Manager client without reaching on-premises infrastructure. It is not a universal co-management prerequisite, and a Cloud Distribution Point is not a blanket requirement. The current wizard’s generated installation command depends on the scenario and prerequisites. See Microsoft’s new-device tutorial and the CMG overview.
Windows Autopilot
Autopilot into co-management is a distinct provisioning scenario, not simply another name for existing-client onboarding. Review its requirements—including supported Windows, Microsoft Entra join, Intune profiles, Configuration Manager 2111 or later, and CMG—in Microsoft’s Autopilot co-management guidance.
Check prerequisites before enabling enrollment
| Area | What to confirm |
|---|---|
| Licensing | Appropriate Intune, Microsoft Entra ID P1 or P2, and Windows licensing. The administrator account accessing Intune needs an Intune license. Confirm entitlements against your organization’s agreement; bundles and eligibility vary. |
| Configuration Manager | A supported current-branch release, healthy site systems and management points, functioning clients on pilot devices, required administrative permissions, and tenant connection/service-principal configuration. |
| Microsoft Entra ID | Correct tenant and cloud, device identity and join state, synchronization for hybrid-joined devices, join restrictions, user sign-in configuration, and no stale or duplicate device objects. |
| Intune enrollment | Intune is the tenant’s MDM authority; Windows automatic MDM enrollment is configured; the correct MDM user scope includes the pilot; licenses are assigned; enrollment and platform restrictions permit the devices. |
| Windows and client health | Devices run supported Windows 10 or Windows 11 releases and have a healthy Configuration Manager client. Do not use the old Windows 10 1709 baseline as a current target. |
| Network | Determine whether devices can reach Configuration Manager over LAN or VPN, or need CMG for internet-based client installation and communication. |
| Permissions | Have Configuration Manager Full Administrator rights for enablement and the Microsoft Entra permissions required by the workflow. Use least privilege where the current procedure permits it; do not leave a highly privileged account in routine use. |
Microsoft lists current requirements in its overview and prerequisites. For automatic MDM enrollment, follow Microsoft’s Windows enrollment setup. Clean up duplicate Microsoft Entra device objects before auto-enrollment; duplicates can make enrollment and policy reporting ambiguous.
Prepare a pilot and a rollback plan
Inventory Configuration Manager version, Windows releases, identity state, client health, existing Intune enrollment, remote-access patterns, and current policy owners. Record which systems deploy software, updates, security settings, certificates, Wi-Fi, and VPN. Identify overlaps among Group Policy, Configuration Manager, and Intune before assigning a workload to a new authority.
Create separate, clearly scoped collections—for example, CoMgmt - Enrollment - Pilot, CoMgmt - Workload - Compliance - Pilot, and CoMgmt - Rollback. These are example names, not required Microsoft labels. Include representative device models, Windows releases, remote and on-premises users, VPN patterns, security software, and important applications. Keep the enrollment pilot distinct from workload pilots so Intune enrollment does not accidentally become a policy migration.
Define who can approve expansion, what successful enrollment and policy application look like, how long a workload will be observed, and who can return it to Configuration Manager. Automatic enrollment in a large environment may be staggered rather than immediate. Pilot groups can be used without a mandatory time limit, according to Microsoft’s enablement guidance.
Configure identity and automatic enrollment
- Confirm device identity. For the existing domain-joined client path, verify Microsoft Entra hybrid join and synchronization. For cloud-native devices, verify Microsoft Entra join. Resolve duplicate objects and sign-in or synchronization problems before troubleshooting Intune enrollment.
- Set up Windows automatic MDM enrollment. In the Microsoft Intune admin center, configure the MDM user scope to include the pilot users or groups, then check licenses and enrollment restrictions. The precise labels may vary as the admin center changes; use the current automatic enrollment instructions.
- Review Conditional Access carefully. Do not block the identity, enrollment, or bootstrap steps needed to bring a device under management. Compliance-based Conditional Access is often introduced after enrollment and compliance reporting work in a pilot, not as the first production change.
Enable Cloud Attach and co-management
- Open the Configuration Manager console and go to the cloud-attach or cloud-services area available in your installed current-branch version.
- Start the Cloud Attach Configuration Wizard and sign in with an account that has the permissions required for the workflow. Select the appropriate Microsoft cloud and configure the tenant connection.
- Choose the automatic enrollment scope: None to avoid enrolling clients, Pilot to enroll eligible devices in the selected Intune Auto Enrollment collection, or All to enroll all eligible clients.
- Complete the wizard with workloads left assigned to Configuration Manager for the initial rollout. Verify the selected collection and monitor which devices actually enroll before expanding scope.
Enabling enrollment and changing workload authority are separate decisions. Keep them separate unless a specific workload is already configured, assigned, and approved for an immediate switch. The Cloud Attach instructions and co-management procedure provide version-specific detail.
Validate enrollment before moving any workload
- On the Windows device: Check its Microsoft Entra identity and Intune enrollment, the work or school account connection in Windows Settings, Configuration Manager client health and properties, and whether assigned policy arrives. Company Portal visibility may also help where applicable.
- In Configuration Manager: Check collection membership, client activity and communication, co-management status in the console or reports, and management point or CMG communication as appropriate.
- In Intune: Check that the device record is present, its last check-in is current, its enrollment and compliance state are understood, and assigned policies report their status.
Do not infer workload authority from enrollment alone. Confirm the device is co-managed and inspect the applicable workload setting and reports. Microsoft’s FAQ also describes co-managed device visibility and cloud management experiences.
Move workloads one at a time
Supported co-management workloads include compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run apps, and client apps. Microsoft advises configuring and deploying the corresponding Intune workload before switching authority; each workload should have a clear management owner. The sequence below is a planning pattern, not a mandated order.
Compliance policies
Compliance is often a contained first move and can support compliance reporting and Conditional Access. Define the requirements and verify reporting freshness before using compliance to control access: stale or conflicting results can block users. Where supported, configure how Configuration Manager compliance information contributes to Intune compliance.
Resource access
Wi-Fi, VPN, and certificate profiles can reduce dependence on older resource-access policies, but a profile or certificate failure can cut off connectivity. Validate certificate issuance and connector health, use distinct profile assignments, and test remote access before broadening the collection.
Rank #3
- Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
- ABIS BOOK
- Packt Publishing
Endpoint Protection
Map existing antimalware, firewall, Defender, attack-surface-reduction, and security-baseline settings before switching. Avoid duplicate or contradictory configurations and verify expected policy precedence; removing legacy controls too early can weaken or disrupt protection.
Device configuration
Map Group Policy and Configuration Manager settings to supported Intune configuration. Group Policy analytics can help with assessment, but not every GPO has a one-to-one Intune equivalent. Settings catalog, administrative templates, security baselines, custom OMA-URI settings, and continuing GPO application can overlap.
Windows Update policies
Set update rings, feature-update policy, deadlines, restart behavior, and servicing expectations before moving authority. Check for overlapping Configuration Manager software update deployments and allow the pilot enough time to encounter update and restart behavior.
Office Click-to-Run apps
Confirm the intended update channel, deployment source, servicing behavior, and exclusions so the Intune and Configuration Manager approaches do not compete.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Client apps
Decide which apps remain in Configuration Manager and which will be assigned through Intune. Validate detection rules, dependencies, supersedence, uninstall behavior, bandwidth and storage demands, and Company Portal presentation. Co-management does not convert Configuration Manager applications into Intune apps automatically. After switching the app workload, both Configuration Manager and Intune apps can still be deployed, and the Company Portal experience can surface both, as described in the Microsoft FAQ.
Set workload authority
For a workload, ConfigMgr leaves authority with Configuration Manager; Pilot Intune applies Intune authority to the selected pilot collection; and Intune applies it to all applicable co-managed devices. Make one change at a time, verify the target collection and Intune assignments, and observe results before expanding. Microsoft documents switching and reversal in Switch workloads.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Internet-based devices and CMG
Separate the question “Does this device need Intune enrollment?” from “How will its Configuration Manager client install and reach site infrastructure?” A device that can reach Configuration Manager over a corporate network or VPN may not need CMG for that communication. An internet-only device that cannot reach on-premises management infrastructure may need CMG for client installation or ongoing communication. The wizard’s client-install command appears only when the relevant scenario prerequisites are met; if it is missing, check the configuration rather than copying a command from an old guide. Do not assume a legacy Cloud Distribution Point is required.
Automate enrollment policy creation with PowerShell
Microsoft documents New-CMCoManagementPolicy for creating a policy. This example enables automatic enrollment while keeping each listed workload disabled; it deploys the policy to the example collection ID, which you must replace with an ID from your site.
$CoMgmtPolicyName = "CoMgmtSettingsProd"
New-CMCoManagementPolicy `
-CoManagementPolicyName $CoMgmtPolicyName `
-AutoEnroll $true `
-CAWorkloadEnabled $false `
-RAWorkloadEnabled $false `
-WufbWorkloadEnabled $false `
-EPWorkloadEnabled $false `
-DCWorkloadEnabled $false `
-O365WorkloadEnabled $false `
-ClientAppsWorkloadEnabled $false
New-CMConfigurationPolicyDeployment `
-CoManagementPolicyName $CoMgmtPolicyName `
-CollectionId "XYZ00042"
Run Configuration Manager cmdlets from the Configuration Manager site drive, such as PS XYZ:>, and replace the policy name and collection ID as appropriate. Use the official cmdlet documentation. Do not reuse tenant IDs, client IDs, site codes, management-point URLs, or keys from someone else’s sample.
Troubleshoot by symptom
Automatic enrollment does not start
- Check MDM user scope, Intune license, enrollment restrictions, Intune tenant authority, and the device’s eligibility.
- Verify the device is in the selected automatic-enrollment collection and has a valid Microsoft Entra identity and token state.
- Check for duplicate device objects, Conditional Access blocks, clock or connectivity issues, and client health.
A user does not necessarily need to be interactively signed in for current co-management auto-enrollment; Microsoft documents device-token-based behavior in its enablement guidance.
The device is not hybrid joined
For an existing domain-joined client, check Microsoft Entra Connect synchronization, hybrid-join configuration and SCP, device registration logs and scheduled tasks, and UPN, proxy, or network issues. Resolve identity registration before treating the problem as an Intune policy issue.
Duplicate device records appear
Determine which record is the active device, then remove or clean stale duplicates under your organization’s process. Do not delete the active object until its identity and ownership are confirmed; recheck enrollment and policy reporting afterward.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
The wizard has no CMG installation command
Confirm that you selected an internet-based client-installation scenario and that its prerequisites, including CMG where applicable, are configured. The command is scenario-dependent, not a reusable universal installer.
A workload has not moved
Confirm that the device is co-managed, belongs to the intended pilot collection, and has the workload set to Pilot Intune or Intune. Then verify Intune policy assignment and support for the device’s Windows edition and version, check for conflicting Configuration Manager or Group Policy settings, and confirm a recent device check-in.
VPN or Wi-Fi fails after resource-access changes
- Return the affected collection’s resource-access workload to Configuration Manager if needed.
- Restore a known-good profile and verify certificate issuance and connector health.
- Test with a smaller, explicitly assigned collection and expand only after access is stable.
Conditional Access blocks users
Keep emergency-access accounts, an independently managed policy-change path, and staged enforcement in the rollout plan. Test the enrollment and compliance reporting path before making compliance a production access gate.
Expand and operate the rollout
Move from pilot to broader scope only after enrollment, policy delivery, application behavior, updates, remote access, and reporting meet documented exit criteria. Use change control for each workload, record its owner and rollback collection, monitor check-ins and failures, and keep a route to return the affected workload to Configuration Manager. Workload switching can be reversed; the specific change and recovery steps are in Microsoft’s workload-switching guidance.
Free tools Windows power users keep installed
One-click scans. No signup required.
For a historical comparison, HTMD’s co-management overview explains earlier terminology, while current deployment decisions should follow Microsoft’s version-appropriate documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




