Add a policy to prevent device unenrollment from Company portal
Companies provide devices to their employees and generally wants to make sure that these devices will always remain managed through Intune. It could be interesting to have a policy that prevent users to unenroll a device identified as a company device from the Intune company portal.

I can confirm that we have this on our plan for early in 2020/ Thanks for your patience!
91 comments
-
Ash Hoque commented
This would certainly work for us.
-
Carlos Conrado commented
Hi Cathy having the disable remove device based on corp or personal device would be a good enough solution.
Thanks
-
Rob de Roos commented
Isn't this available allready? I believe it is. Disable manual unenrollment it is called if I am not mistaken.
-
Rich Moore commented
That would work for us
-
Anonymous commented
This would work for us.
-
Owen Dickenson commented
That would work for us; we would want to have corporate devices managed with no choice to our end users. Those connecting personal devices - that's up to them.
-
Thomas Wiedenhofer commented
For me it would be nice if corporate devices are disabled from removing the device, personal owned devices could be free of choice. Thank you!
-
Noel Fairclough commented
Yes -being able to un-enroll based on ownership status is perfect. Corporately owned = they can't un-enroll the device without approval, or without the admin doing it for them. Personally owned = they can do what they want. We can restrict access to corporate resources based on MAM policies -so if they don't want the managed app, they can't access resources. Simple. If they don't want to use their personal device, they can apply for a corporate device but then live by our rules.
-
Pratik Dave commented
Apple DEP integration has capabilities which stops device unenrollment for iOS Corp devices ! Something out the of box would be useful too, may be altering when user trigger removal of mgmt would be useful for admins
-
Anthony Zmoda commented
That wouldn't work for us. We offer device wide VPN to both BYOD and Corporate owned Intune enrolled devices. We can't containerize device wide VPN so we require all of our end users to wipe their devices when leaving the mobility program. If we could toggle the "remove device" icon from within the Company Portal app, then that would reduce the likelihood of a device leaving Intune enrollment without having the factory reset performed.
-
James Read commented
Disabling removing devices by ownership is exactly what we need.
-
stillajl commented
Yes, that would work based on corporate or personal owned devices.
-
Rama Shankar commented
disabling this option on corporate devices seems more appropriate whoever on personal also it would be best if the app from personal device can be removed after admins approval ( when user tries to remove it, admin will get notified and can approve or deny )
-
Kevin Pearce commented
Yes, this would do exactly what we need.
-
Brad Dunn commented
Hi Cathy, disabling based on ownership is exactly what we need.
-
Justin W commented
Yes, if all managed devices are corporate devices, only a domain admin should be able to remove them from Intune
-
Anonymous commented
This a great idea and would be very useful. The idea of corporate vs personal is spot on!
-
Marcus commented
There's still no such feature for Android device. Looking forward to have such feature, please add this feature.
-
Lucas van de Pieterman commented
Hi,
Can you please add this functionality!! -
Rishikesh Negi commented
Yes we need this option.