From 42ffd1a4b9a9abddec06b31d5319d498599b907f Mon Sep 17 00:00:00 2001 From: j0eyv <41282854+j0eyv@users.noreply.github.com> Date: Tue, 20 Jan 2026 11:35:32 +0100 Subject: [PATCH] Update README with Autopilot enrollment warning Added important note about Autopilot Device Preparation enrollment issues. --- README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/README.md b/README.md index 795498d..1aacb42 100644 --- a/README.md +++ b/README.md @@ -266,6 +266,9 @@ This policy requires MFA for internals when enrolling their devices in Intune. > [!IMPORTANT] > Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example. +> [!IMPORTANT] +> Autopilot Device Preparation (v2) enrollment can fail under this policy, resulting in devices getting stuck during OOBE. This happens because the automated enrollment process is unable to fulfill the MFA requirement. To avoid this issue, add Autopilot Device Preparation users to the exclusion group for this policy. + ![CA203](./Images/CA203.png) ### CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms