October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk10 min

How to Set Up Configuration Manager and Intune Co-Management

Enable Intune enrollment without prematurely moving workloads. This guide covers prerequisites, Cloud Attach, pilot validation, workload switching, and rollback.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a current deployment, use Configuration Manager’s Cloud Attach Configuration Wizard and Microsoft’s current co-management guidance—not setup instructions written for SCCM Current Branch 1709/1710. You can enroll a pilot of eligible devices in Intune while leaving every management workload with Configuration Manager; switch a workload only after its Intune policies are ready and tested.

What Configuration Manager and Intune co-management does

Co-management lets a supported Windows device be managed by both the Configuration Manager client and Microsoft Intune. It does not automatically transfer policies or applications, and enabling it does not require you to move any workload on day one. Configuration Manager remains authoritative for workloads you have not switched; Intune manages a workload only after you assign that authority to Intune. See Microsoft’s co-management overview.

Co-management is different from tenant attach, which connects a Configuration Manager environment to cloud experiences without, by itself, enrolling a device in Intune or changing its workload authority. It is also different from Microsoft Entra hybrid join: hybrid join gives a domain-joined device a cloud identity, but is not co-management. The original HTMD guide documents an early implementation and uses historical terminology; its 1709/1710-era setup should not be treated as a current runbook (HTMD’s original guide).

Current terms for older guides

Older term Current meaning
SCCM or SCCM CB Configuration Manager, or Configuration Manager current branch
Azure AD Microsoft Entra ID
Microsoft Endpoint Manager admin center Microsoft Intune admin center and its current experiences
Co-management wizard Cloud Attach Configuration Wizard or the current co-management enablement workflow
Cloud DP or CDP Legacy Cloud Distribution Point terminology; do not assume one is required
Intune workload A supported management area whose authority has been moved to Intune

Since Configuration Manager version 2111, the Cloud Attach Configuration Wizard provides the newer onboarding experience. Use a supported current-branch release and check the guidance for your installed version; do not plan around Windows 10 version 1709 as a current requirement. Microsoft’s enablement procedure describes the current workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose an onboarding path

Existing Configuration Manager clients

This is the usual route for domain-joined or hybrid-joined corporate devices already receiving Configuration Manager policy. Ensure existing Active Directory domain-joined clients are Microsoft Entra hybrid joined, configure Intune automatic MDM enrollment, and use Configuration Manager to enroll a selected collection. The clients can remain under Configuration Manager workload authority while you validate enrollment and prepare Intune policies. Microsoft describes the existing-client scenario in its co-manage clients tutorial.

New or Intune-managed internet devices

For cloud-native devices, the device can join Microsoft Entra ID and enroll in Intune first; Intune can then deploy the Configuration Manager client. A Cloud Management Gateway (CMG) is relevant when an internet-based device must install or communicate with the Configuration Manager client without reaching on-premises infrastructure. It is not a universal co-management prerequisite, and a Cloud Distribution Point is not a blanket requirement. The current wizard’s generated installation command depends on the scenario and prerequisites. See Microsoft’s new-device tutorial and the CMG overview.

Windows Autopilot

Autopilot into co-management is a distinct provisioning scenario, not simply another name for existing-client onboarding. Review its requirements—including supported Windows, Microsoft Entra join, Intune profiles, Configuration Manager 2111 or later, and CMG—in Microsoft’s Autopilot co-management guidance.

Check prerequisites before enabling enrollment

Area What to confirm
Licensing Appropriate Intune, Microsoft Entra ID P1 or P2, and Windows licensing. The administrator account accessing Intune needs an Intune license. Confirm entitlements against your organization’s agreement; bundles and eligibility vary.
Configuration Manager A supported current-branch release, healthy site systems and management points, functioning clients on pilot devices, required administrative permissions, and tenant connection/service-principal configuration.
Microsoft Entra ID Correct tenant and cloud, device identity and join state, synchronization for hybrid-joined devices, join restrictions, user sign-in configuration, and no stale or duplicate device objects.
Intune enrollment Intune is the tenant’s MDM authority; Windows automatic MDM enrollment is configured; the correct MDM user scope includes the pilot; licenses are assigned; enrollment and platform restrictions permit the devices.
Windows and client health Devices run supported Windows 10 or Windows 11 releases and have a healthy Configuration Manager client. Do not use the old Windows 10 1709 baseline as a current target.
Network Determine whether devices can reach Configuration Manager over LAN or VPN, or need CMG for internet-based client installation and communication.
Permissions Have Configuration Manager Full Administrator rights for enablement and the Microsoft Entra permissions required by the workflow. Use least privilege where the current procedure permits it; do not leave a highly privileged account in routine use.

Microsoft lists current requirements in its overview and prerequisites. For automatic MDM enrollment, follow Microsoft’s Windows enrollment setup. Clean up duplicate Microsoft Entra device objects before auto-enrollment; duplicates can make enrollment and policy reporting ambiguous.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare a pilot and a rollback plan

Inventory Configuration Manager version, Windows releases, identity state, client health, existing Intune enrollment, remote-access patterns, and current policy owners. Record which systems deploy software, updates, security settings, certificates, Wi-Fi, and VPN. Identify overlaps among Group Policy, Configuration Manager, and Intune before assigning a workload to a new authority.

Create separate, clearly scoped collections—for example, CoMgmt - Enrollment - Pilot, CoMgmt - Workload - Compliance - Pilot, and CoMgmt - Rollback. These are example names, not required Microsoft labels. Include representative device models, Windows releases, remote and on-premises users, VPN patterns, security software, and important applications. Keep the enrollment pilot distinct from workload pilots so Intune enrollment does not accidentally become a policy migration.

Define who can approve expansion, what successful enrollment and policy application look like, how long a workload will be observed, and who can return it to Configuration Manager. Automatic enrollment in a large environment may be staggered rather than immediate. Pilot groups can be used without a mandatory time limit, according to Microsoft’s enablement guidance.

Configure identity and automatic enrollment

  1. Confirm device identity. For the existing domain-joined client path, verify Microsoft Entra hybrid join and synchronization. For cloud-native devices, verify Microsoft Entra join. Resolve duplicate objects and sign-in or synchronization problems before troubleshooting Intune enrollment.
  2. Set up Windows automatic MDM enrollment. In the Microsoft Intune admin center, configure the MDM user scope to include the pilot users or groups, then check licenses and enrollment restrictions. The precise labels may vary as the admin center changes; use the current automatic enrollment instructions.
  3. Review Conditional Access carefully. Do not block the identity, enrollment, or bootstrap steps needed to bring a device under management. Compliance-based Conditional Access is often introduced after enrollment and compliance reporting work in a pilot, not as the first production change.

Enable Cloud Attach and co-management

  1. Open the Configuration Manager console and go to the cloud-attach or cloud-services area available in your installed current-branch version.
  2. Start the Cloud Attach Configuration Wizard and sign in with an account that has the permissions required for the workflow. Select the appropriate Microsoft cloud and configure the tenant connection.
  3. Choose the automatic enrollment scope: None to avoid enrolling clients, Pilot to enroll eligible devices in the selected Intune Auto Enrollment collection, or All to enroll all eligible clients.
  4. Complete the wizard with workloads left assigned to Configuration Manager for the initial rollout. Verify the selected collection and monitor which devices actually enroll before expanding scope.

Enabling enrollment and changing workload authority are separate decisions. Keep them separate unless a specific workload is already configured, assigned, and approved for an immediate switch. The Cloud Attach instructions and co-management procedure provide version-specific detail.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate enrollment before moving any workload

  • On the Windows device: Check its Microsoft Entra identity and Intune enrollment, the work or school account connection in Windows Settings, Configuration Manager client health and properties, and whether assigned policy arrives. Company Portal visibility may also help where applicable.
  • In Configuration Manager: Check collection membership, client activity and communication, co-management status in the console or reports, and management point or CMG communication as appropriate.
  • In Intune: Check that the device record is present, its last check-in is current, its enrollment and compliance state are understood, and assigned policies report their status.

Do not infer workload authority from enrollment alone. Confirm the device is co-managed and inspect the applicable workload setting and reports. Microsoft’s FAQ also describes co-managed device visibility and cloud management experiences.

Move workloads one at a time

Supported co-management workloads include compliance policies, Windows Update policies, resource access policies, Endpoint Protection, device configuration, Office Click-to-Run apps, and client apps. Microsoft advises configuring and deploying the corresponding Intune workload before switching authority; each workload should have a clear management owner. The sequence below is a planning pattern, not a mandated order.

Compliance policies

Compliance is often a contained first move and can support compliance reporting and Conditional Access. Define the requirements and verify reporting freshness before using compliance to control access: stale or conflicting results can block users. Where supported, configure how Configuration Manager compliance information contributes to Intune compliance.

Resource access

Wi-Fi, VPN, and certificate profiles can reduce dependence on older resource-access policies, but a profile or certificate failure can cut off connectivity. Validate certificate issuance and connector health, use distinct profile assignments, and test remote access before broadening the collection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
  • Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
  • ABIS BOOK
  • Packt Publishing

Endpoint Protection

Map existing antimalware, firewall, Defender, attack-surface-reduction, and security-baseline settings before switching. Avoid duplicate or contradictory configurations and verify expected policy precedence; removing legacy controls too early can weaken or disrupt protection.

Device configuration

Map Group Policy and Configuration Manager settings to supported Intune configuration. Group Policy analytics can help with assessment, but not every GPO has a one-to-one Intune equivalent. Settings catalog, administrative templates, security baselines, custom OMA-URI settings, and continuing GPO application can overlap.

Windows Update policies

Set update rings, feature-update policy, deadlines, restart behavior, and servicing expectations before moving authority. Check for overlapping Configuration Manager software update deployments and allow the pilot enough time to encounter update and restart behavior.

Office Click-to-Run apps

Confirm the intended update channel, deployment source, servicing behavior, and exclusions so the Intune and Configuration Manager approaches do not compete.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Client apps

Decide which apps remain in Configuration Manager and which will be assigned through Intune. Validate detection rules, dependencies, supersedence, uninstall behavior, bandwidth and storage demands, and Company Portal presentation. Co-management does not convert Configuration Manager applications into Intune apps automatically. After switching the app workload, both Configuration Manager and Intune apps can still be deployed, and the Company Portal experience can surface both, as described in the Microsoft FAQ.

Set workload authority

For a workload, ConfigMgr leaves authority with Configuration Manager; Pilot Intune applies Intune authority to the selected pilot collection; and Intune applies it to all applicable co-managed devices. Make one change at a time, verify the target collection and Intune assignments, and observe results before expanding. Microsoft documents switching and reversal in Switch workloads.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Internet-based devices and CMG

Separate the question “Does this device need Intune enrollment?” from “How will its Configuration Manager client install and reach site infrastructure?” A device that can reach Configuration Manager over a corporate network or VPN may not need CMG for that communication. An internet-only device that cannot reach on-premises management infrastructure may need CMG for client installation or ongoing communication. The wizard’s client-install command appears only when the relevant scenario prerequisites are met; if it is missing, check the configuration rather than copying a command from an old guide. Do not assume a legacy Cloud Distribution Point is required.

Automate enrollment policy creation with PowerShell

Microsoft documents New-CMCoManagementPolicy for creating a policy. This example enables automatic enrollment while keeping each listed workload disabled; it deploys the policy to the example collection ID, which you must replace with an ID from your site.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
$CoMgmtPolicyName = "CoMgmtSettingsProd"

New-CMCoManagementPolicy `
  -CoManagementPolicyName $CoMgmtPolicyName `
  -AutoEnroll $true `
  -CAWorkloadEnabled $false `
  -RAWorkloadEnabled $false `
  -WufbWorkloadEnabled $false `
  -EPWorkloadEnabled $false `
  -DCWorkloadEnabled $false `
  -O365WorkloadEnabled $false `
  -ClientAppsWorkloadEnabled $false

New-CMConfigurationPolicyDeployment `
  -CoManagementPolicyName $CoMgmtPolicyName `
  -CollectionId "XYZ00042"

Run Configuration Manager cmdlets from the Configuration Manager site drive, such as PS XYZ:>, and replace the policy name and collection ID as appropriate. Use the official cmdlet documentation. Do not reuse tenant IDs, client IDs, site codes, management-point URLs, or keys from someone else’s sample.

Troubleshoot by symptom

Automatic enrollment does not start

  • Check MDM user scope, Intune license, enrollment restrictions, Intune tenant authority, and the device’s eligibility.
  • Verify the device is in the selected automatic-enrollment collection and has a valid Microsoft Entra identity and token state.
  • Check for duplicate device objects, Conditional Access blocks, clock or connectivity issues, and client health.

A user does not necessarily need to be interactively signed in for current co-management auto-enrollment; Microsoft documents device-token-based behavior in its enablement guidance.

The device is not hybrid joined

For an existing domain-joined client, check Microsoft Entra Connect synchronization, hybrid-join configuration and SCP, device registration logs and scheduled tasks, and UPN, proxy, or network issues. Resolve identity registration before treating the problem as an Intune policy issue.

Duplicate device records appear

Determine which record is the active device, then remove or clean stale duplicates under your organization’s process. Do not delete the active object until its identity and ownership are confirmed; recheck enrollment and policy reporting afterward.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The wizard has no CMG installation command

Confirm that you selected an internet-based client-installation scenario and that its prerequisites, including CMG where applicable, are configured. The command is scenario-dependent, not a reusable universal installer.

A workload has not moved

Confirm that the device is co-managed, belongs to the intended pilot collection, and has the workload set to Pilot Intune or Intune. Then verify Intune policy assignment and support for the device’s Windows edition and version, check for conflicting Configuration Manager or Group Policy settings, and confirm a recent device check-in.

VPN or Wi-Fi fails after resource-access changes

  1. Return the affected collection’s resource-access workload to Configuration Manager if needed.
  2. Restore a known-good profile and verify certificate issuance and connector health.
  3. Test with a smaller, explicitly assigned collection and expand only after access is stable.

Conditional Access blocks users

Keep emergency-access accounts, an independently managed policy-change path, and staged enforcement in the rollout plan. Test the enrollment and compliance reporting path before making compliance a production access gate.

Expand and operate the rollout

Move from pilot to broader scope only after enrollment, policy delivery, application behavior, updates, remote access, and reporting meet documented exit criteria. Use change control for each workload, record its owner and rollback collection, monitor check-ins and failures, and keep a route to return the affected workload to Configuration Manager. Workload switching can be reversed; the specific change and recovery steps are in Microsoft’s workload-switching guidance.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a historical comparison, HTMD’s co-management overview explains earlier terminology, while current deployment decisions should follow Microsoft’s version-appropriate documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.