Admin Manuals

Device Conversion & User Onboarding

All configuration profiles and Conditional Access rules are deployed during the onboarding project and targeted to specific user and device security groups, allowing granular onboarding and different security levels per user.

3 min read Updated September 11, 2025

Prerequisites

Device Requirements

  • Windows Professional (minimum) — Home edition is not supported
  • The device must be able to join Entra ID (no conflicting MDM enrollment)
  • An existing local or domain user profile to be converted

Users without a dedicated Windows or Mac device that can be managed should not be onboarded to this baseline. Standard protection with MFA is applied to those users instead.

Device Conversion

Users sign in with their Microsoft 365 account on Windows after onboarding. This requires their existing local or domain profiles to be migrated using ProfWiz.

1

Run ProfWiz

Execute the ProfWiz profile migration tool to convert the existing local or domain user profile to an Entra ID account. The computer will auto-reboot after completion.

2

Sign in with M365 Account

After the reboot, sign in with the user's Microsoft 365 account. Intune enrollment begins automatically in the background.

3

Configure Windows Hello for Business

The user will be prompted to configure WHFB. Guide them through setting up a PIN and optionally fingerprint or camera sign-in. Set up MFA (Microsoft Authenticator) at the same time.

User Onboarding

Add the user to the Baseline – Modern Workplace Users security group to apply the full baseline security posture.

What Adding the User Activates

  • Strict Conditional Access rules applied — compliant device required for all access
  • App Protection Policies applied to mobile devices — inform the user, request phone reboot, and have them manually relaunch all Microsoft apps
  • Native iOS and Android mail clients will no longer work — Microsoft apps only, or Intune enrollment required

Mobile App Protection Policies require an explicit user communication step — inform the user of the extra security requirements and ensure they understand which apps are affected before adding them to the group.