Skip to main content

Automatic Enrollment for into Microsoft Intune for Windows Devices

These instructions are for the School of Medicine community.

The university offers an automated Intune enrollment process for eligible Stanford-owned Windows devices. 

TIP: Most Stanford-owned Windows devices in the School of Medicine are eligible to auto-enroll. If yours isn't, you'll be prompted to launch the guided-enrollment an app.

What you need to know 

Once you’ve set up your new Microsoft login using the Microsoft Authenticator app (for iOS or Android) or another approved authentication method, wait 24 hours for the system to update. Then connect your device to one of the following Stanford networks for at least one hour and your device will enroll in Intune automatically:

Step-by-step instructions

After setting up your new Microsoft login, wait 24 hours for the systems to update. Then proceed through these steps:

  1. Logout or restart your computer.
  2. On the login screen, select Other users from the bottom left corner.
    select other user
  3. On the new screen, login using your SUNet credentials making sure to use the @stanford.edu suffix.
    enter sunet id credentials
     
  4. After log in, connect your device to the Stanford network by choosing one of the following options:
    1. On campus: Connect directly to the Stanford network.
    2. Off campus: Connect using Cisco Secure Client VPN for Windows to su-vpn.stanford.edu
  5. Remain connected to the Stanford network or VPN for at least one hour. You must stay connected so your device can receive the necessary enrollment configuration.
  6. Once you have stayed connected for at least one hour, restart your computer to complete the enrollment process.
  7. On your next login, you may be prompted to set up Windows Hello. This step is optional and appears only on some devices. If you are prompted, follow the on-screen prompts to create your PIN (and set to fingerprint or facial recognition, if your device supports it.) Follow the on-screen prompts to complete this setup. 

Windows Hello

If you set up Windows Hello

If you set up Windows Hello, complete these additional steps.

TIP: The first time you sign in with your new Windows Hello PIN or biometric, your device must be able to reach the Stanford network to verify your credentials. If you’re off campus, you’ll need to connect to VPN at the login screen before you sign in. Skipping this step can cause a sign-in error. (See the note below). 
  1. Log off from your current session, or restart your computer. 
  2. At the login screen, connect to the Stanford network before signing in: 
    1. On campus: Confirm you are connected to the Stanford network. 
    2. Off campus: Connect to the Cisco Secure Client VPN for Windows (su-vpn.stanford.edu) using the VPN option available on the login screen. 
      select VPN option
  3. Once connected, sign in with your new Windows Hello PIN or biometric. 

Important: If you set up Windows Hello and then sign in while not connected to the Stanford network (on campus or via VPN), you may see a "Your credentials could not be verified" error. If this happens, follow the How to Resolve "Your Credentials Could Not Be Verified" Error guide to get signed in.
 

What's next

Wait at least one hour after completing enrollment, then verify your device's registration on the company portal web site

See also

Need more help?

  • For answers to common questions, review the FAQs.
  • For additional assistance, contact SoM Entra ID / Intune support using any of the options listed below: 
    • SoM TDS Service Desk: Call (650) 725-8000 (option 7), available 6:00 a.m. - 10:00 p.m., 7 days a week. Hours have been expanded to handle increased demand.
    • SoM Tech Bar: Schedule an appointment at the location nearest you.
    • SoM Field Service Technician: Request an appointment at a time that works for you.
Last modified