Skip to main content

βš™οΈπŸͺŸπŸ§‘β€πŸ’ΌCP - Security - MDM Unenrollment Block

What this page is about πŸ”’β€‹

This policy stops users from manually removing their device from MDM β€” because yes, even standard users can do that by default. And no, it’s not a joke.

This sets AllowManualMDMUnenrollment = False, blocking the β€œDisconnect” button under Access work or school in Settings.

No more rogue offboarding. No more accidental BYOD situations. No more drama.

If you're not sure why this exists β€” read this blog post for the full meltdown story.


❗ Why this matters​

By default, Windows thinks users should be trusted to manage their own MDM enrollment. That’s adorable.

Without this policy:

  • Any standard user can click β€œDisconnect”
  • Compliance? Gone.
  • Security baselines? Gone.
  • Your grip on reality? Also gone.

It’s like letting Deadpool run your Intune environment β€” chaotic, loud, and something’s probably on fire.


πŸ“„ Policy details​

FieldValue
PlatformWindows 10/11
Profile typeSettings catalog
CategoryExperience > Allow manual MDM unenrollment
Setting nameAllowManualMDMUnenrollment
StateDisabled
CSPExperience/AllowManualMDMUnenrollment

πŸ‘₯ Group Assignments​

βœ… Included:​

  • All Users

❌ Excluded:​

Because some users (like staging admins or troubleshooting engineers) need a way out. But we do it cleanly, with the Allow policy, and not by letting Jan from Finance click buttons he doesn't understand.



🧠 Final words​

This setting is like the ejector seat in a spaceship. Handy if you're an astronaut. Dangerous if you're the intern.

Block it. Document exceptions. And sleep better knowing your endpoints won’t self-destruct mid-flight.