> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Windows Enrollment

> Configure Windows device enrollment in Iru Endpoint. Set up MDM enrollment URLs, authentication, and group policy for automated Windows management.

<Callout icon="microsoft" color="#B84A7A" iconType="regular">This guide applies to Windows devices</Callout>

Windows devices in Iru Endpoint enroll through the **Enrollment Portal** (manual flow) or through **[Windows Autopilot](/en/endpoint/settings/windows-integrations/configure-windows-autopilot)** when you connect Microsoft Entra ID and register devices with the Autopilot service. Management uses Microsoft's MDM framework and the Iru Agent for app installation, upgrades, and application inventory. For enabling the Windows platform and a quick enrollment overview, see [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup) and [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment).

<Note>
  As of **April 8, 2026**, apps were updated from **Kandji** <img className="inline dark:hidden" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-light-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=3ac73eb9098c090ac2838a4902a70e35" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-light-icon.png" /><img className="hidden dark:inline" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-dark-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=1d4b643c8e1903aabdb072fdf211f2de" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-dark-icon.png" /> to **Iru** <img src="https://mintcdn.com/iru/8j4H0SpqtcKJ5JUM/assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg?fit=max&auto=format&n=8j4H0SpqtcKJ5JUM&q=85&s=befa6ce99e1df18d397deb65aec8edaf" alt="" style={{ display: 'inline', height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 -0.08em 0 0', padding: 0 }} width="14" height="15" data-path="assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg" /> branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names.
</Note>

## How Windows Enrollment Works

Windows enrollment in Iru Endpoint uses a browser-based portal that connects devices to your organization's management system. When users access the **Enrollment Portal link**, they'll enter the **Enrollment code**, then sign in with your organization's credentials if authentication is required. The code determines which Blueprint is assigned to the device; the Blueprint determines which policies and applications get applied. Blueprints can use Assignment Maps to apply conditional logic based on device attributes, user information, or other organizational criteria.

The enrollment process establishes a secure connection between the Windows device and Iru Endpoint through Microsoft's MDM framework, while the Iru Agent handles application management and inventory collection. This gives you centralized management while keeping user flexibility.

## Prerequisites

<Steps>
  <Step title="Admin permissions">
    An Iru Endpoint role with permission to view **Enrollment** and **Blueprints**
  </Step>

  <Step title="Device requirements">
    Windows 11 24H2 or 25H2 (Pro, Pro Education, Enterprise, Education)
  </Step>

  <Step title="Network access">
    Windows devices with internet access and Microsoft Edge browser (required for enrollment)
  </Step>

  <Step title="SSO configuration">
    (Recommended) **Single sign-on (SSO)** configured for secure authentication
  </Step>

  <Step title="Network configuration">
    Firewall ports opened for enrollment traffic
  </Step>
</Steps>

## Configure Windows Enrollment

<Steps>
  <Step title="Get the Enrollment Portal link">
    Sign in to your Iru Endpoint tenant and navigate to **Enrollment** → **Manual Enrollment**. Copy the **Enrollment Portal link**. You'll share this with users.
  </Step>

  <Step title="Choose the Blueprint and Copy Its Code">
    Under the **Select Blueprint to enroll the device into** section, copy the code of the Blueprint you want devices to enroll into. (Recommended) Click the Blueprint and select **Require authentication**.
  </Step>

  <Step title="Send Enrollment Instructions to Users">
    Share the following with each user (email, chat, or help portal):

    * The **Enrollment Portal link** from **Enrollment** → **Manual Enrollment**
    * The **Enrollment code** for the correct **Blueprint**
    * A short note that they'll enter the Enrollment code, then sign in (if required), and follow on-screen prompts to complete enrollment

    <Tip>
      Consider creating a template email or help article with these instructions to ensure consistency across your organization.
    </Tip>
  </Step>
</Steps>

### Enrollment Portal link and Enrollment code

You can also provide the Enrollment Portal link with the Enrollment code embedded in the URL for easier deployment. The format for the shareable link is listed below. The **EnrollmentCodeHere** portion should be the Enrollment code without the dash between the two sets of numbers.

```text Shareable enrollment URL (Windows) icon="link" theme={null}
https://subdomain.iru.com/enroll/windows/access-code/EnrollmentCodeHere
```

## Verify Enrollment

<Steps>
  <Step title="Check devices">
    In Iru Endpoint, open **Devices**
  </Step>

  <Step title="Locate device">
    Locate the newly enrolled device (search by user email, device name, or serial number)
  </Step>

  <Step title="Verify configuration">
    Confirm it shows assigned **Blueprint**, **apps**, and **policies**. Installations will proceed automatically
  </Step>
</Steps>

## Windows Management Architecture

Windows device management in Iru Endpoint uses a hybrid approach:

* **Microsoft MDM Framework** - Handles device enrollment, policy enforcement, and basic device management
* **Iru Agent** - Proprietary agent that manages application installation and upgrade, and collects application inventory

This combination provides comprehensive Windows device management while leveraging Microsoft's native MDM capabilities for core device policies and the Iru Agent for advanced application management.

## Windows-Specific Considerations

### Device Requirements

* **Windows 11 24H2 or 25H2** — You'll need Windows 11 Pro, Pro Education, Enterprise, or Education (24H2 or 25H2 only) for enrollment
* **Microsoft Edge browser** - You'll need Microsoft Edge for Windows enrollment (see [Microsoft's MDM enrollment documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link))
* **Local administrator rights** - The enrolling user must have admin access on the device
* **Serial numbers** - Physical devices include these automatically, but virtual machines need them defined
* **Synchronized time** - Make sure the device clock is synced with a reliable time source

<Note>
  Some advanced Windows features may not be available depending on your device configuration and Windows version.
</Note>

### Network Requirements

Devices must have internet connectivity for enrollment. Make sure all required ports are opened in your firewall configuration. Configure proxy settings if your network requires them.

<Note>
  For detailed network requirements including specific domains, ports, and firewall configurations, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks).
</Note>

### Security Considerations

<Warning>
  Always use SSO authentication when possible to ensure only authorized users can enroll devices. This prevents unauthorized access to your organization's device management system.
</Warning>

Require strong authentication for enrollment and make sure the Enrollment Portal links are only accessible from trusted networks. Verify device identity before enrollment to maintain security.

<Note>
  Windows enrollment supports both SSO authentication and basic authentication, but SSO provides better security and user experience.
</Note>

## Best Practices

<CardGroup cols={2}>
  <Card title="Enable Authentication" icon="shield">
    Enable "Require authentication." Combined with SSO, this ensures only authorized users can enroll
  </Card>

  <Card title="Pre-stage Items" icon="box">
    Pre-stage critical items (Wi-Fi, Certificates, SCEP, Password policies) in the Blueprint so devices come online with required trust and connectivity. You can use Assignment Maps within Blueprints for conditional logic if needed.
  </Card>

  <Card title="Test Process" icon="flask">
    Test the enrollment process with a small group before rolling out to all users
  </Card>

  <Card title="Document Process" icon="file-text">
    Document the enrollment process and provide clear instructions to users
  </Card>
</CardGroup>

## Additional Windows Management

### Active Directory Integration

If your organization requires Active Directory domain join, Azure AD Join, or Hybrid Azure AD join, these must be configured separately from Iru Endpoint enrollment. Coordinate with your Active Directory team to ensure proper domain join procedures are followed.

### Device Sync and Management

Windows devices use multiple sync mechanisms:

* **Event-driven MDM commands** - Changes from the Iru Endpoint Web App apply within minutes via Windows Push Notification Service (WNS)
* **Daily MDM check-in** - Full sync every 24 hours to remediate configuration drift
* **Agent check-in** - Iru Agent checks in every 15 minutes for app updates and inventory collection

From the Iru Endpoint Web App, you can open the device record and click **Perform Recurring Check-In** to force MDM policies to evaluate and remediate (this does not trigger an agent sync). The agent syncs independently every 15 minutes for application management.

### Policy Application

Windows devices automatically receive security policies and restrictions, network configuration (Wi-Fi, VPN), application deployments, and compliance monitoring.

**MDM vs. Agent Responsibilities:**

* **MDM Framework** - Handles Wi-Fi, Windows Firewall, BitLocker, and other system policies
* **Iru Agent** - Manages application installation, updates, and inventory collection

## Related Articles

<CardGroup cols={2}>
  <Card title="Configure Windows Autopilot" icon="microsoft" href="/en/endpoint/settings/windows-integrations/configure-windows-autopilot">
    Connect Microsoft Entra ID for zero-touch Windows 11 enrollment during OOBE
  </Card>

  <Card title="User Experience with Windows Enrollment" icon="user" href="/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment">
    What to expect when enrolling your Windows device through the enrollment portal
  </Card>

  <Card title="Configuring Apple Enrollment" icon="apple" href="/en/endpoint/enrollment/apple/configuring-apple-enrollment">
    Configure Apple device enrollment with Automated Device Enrollment (ADE)
  </Card>

  <Card title="Configuring Android Enrollment" icon="android" href="/en/endpoint/enrollment/android/configuring-android-enrollment">
    Complete guide to Android device enrollment and work profile management
  </Card>

  <Card title="Configure the Windows Update Library Item" icon="refresh" href="/en/endpoint/library/library-items-profiles/configure-the-windows-update-library-item">
    Manage Windows Update settings and the end-user update experience on Windows devices
  </Card>
</CardGroup>
