What is the correct DNS CNAME record to configure for Enterprise Enrollment of mobile devices with Intune?
First, I should explain that this CNAME is only required if you are enrolling Windows devices. It is not required for iOS and Android.
There are three options:
- Redirect enterpriseenrollment.yourdomain.com to manage.microsoft.com
- Redirect enterpriseenrollment-s.yourdomain.com to manage.microsoft.com
- Don't configure a CNAME at all
So this is the scoop on the three options:
- This is a throwback to the early stages of this technology. It still works but is now deemed to be less secure and not recommended by Microsoft. You will still find this referenced on many online blog posts simply because they have not been updated.
- This is now the recommended configuration. It uses a secure channel (hence the -s).
- This will also work but means that the user has to enter "manage.microsoft.com" as the server name during the enrollment process. This would be #2 in terms of preference.
I hope this clears up any confusion. Until next time.......