> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Windows Enrollment

> Set up Windows device enrollment in Iru Endpoint as part of initial setup. Configure enrollment URLs and enroll your first Windows device.

<Callout icon="microsoft" color="#4f46e5" iconType="regular">This guide applies to Windows devices</Callout>

Set up enrollment so you can add Windows 11 devices to Iru Endpoint and assign the right Blueprint so apps, settings, and security controls apply automatically. Most organizations start with the enrollment portal: pick a Blueprint, then share the **Enrollment Portal link** and **Enrollment code** with users. If you use Microsoft Entra ID and Windows Autopilot for new hardware, complete [Configure Windows Autopilot](/en/endpoint/settings/windows-integrations/configure-windows-autopilot) instead of (or alongside) manual portal enrollment for those devices.

<Note>
  As of **April 8, 2026**, apps were updated from **Kandji** <img className="inline dark:hidden" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-light-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=3ac73eb9098c090ac2838a4902a70e35" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-light-icon.png" /><img className="hidden dark:inline" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-dark-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=1d4b643c8e1903aabdb072fdf211f2de" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-dark-icon.png" /> to **Iru** <img src="https://mintcdn.com/iru/8j4H0SpqtcKJ5JUM/assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg?fit=max&auto=format&n=8j4H0SpqtcKJ5JUM&q=85&s=befa6ce99e1df18d397deb65aec8edaf" alt="" style={{ display: 'inline', height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 -0.08em 0 0', padding: 0 }} width="14" height="15" data-path="assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg" /> branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names.
</Note>

### How It Works

In Iru Endpoint you get an Enrollment Portal link and an Enrollment code; share both with users. When users open the link, they enter the Enrollment code, then sign in (if you require authentication) and complete the on-screen steps. The device enrolls and is assigned to the chosen Blueprint automatically.

## Windows Enrollment Requirements

Before enrolling Windows devices, ensure you have:

* **Windows 11** (24H2 or 25H2 only): Pro, Pro Education, Enterprise, or Education
* **Microsoft Edge browser** (required for enrollment; see [Microsoft's Mobile Device Management (MDM) enrollment documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link))
* **Network connectivity** to Iru Endpoint services (for details, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks))
* **Iru Endpoint role** with permission to view **Enrollment** and **Blueprints** (see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions))
* **Blueprint** configured for Windows devices
* **For virtual machines**: the VM must expose a stable device serial number (required for enrollment). For details, see the [Windows enrollment configuration](/en/endpoint/enrollment/windows/configuring-windows-enrollment) guide.

## Manual Enrollment Setup

<Steps>
  <Step title="Configure Enrollment Portal">
    a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint.

    b. Ensure the **Enrollment Portal** is active.

    c. Determine which **Blueprint** you want Windows devices to be added to after enrollment.
  </Step>

  <Step title="Configure authentication">
    a. Under **Select Blueprint to enroll the device into**, copy the code of the Blueprint you want devices to enroll into. Click the **Blueprint** and select **Require authentication** (strongly recommended for security).

    b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. If you see a banner that **No single sign-on connections are configured**, go to **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**) and configure Single sign-on, then return and select **Require authentication**. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps.
  </Step>

  <Step title="Share enrollment information">
    a. Copy the **Enrollment Portal link** from **Enrollment** → **Manual Enrollment**.

    b. Share the link and the **Enrollment code** for the correct Blueprint with your end users.

    c. Provide a short note that they'll enter the Enrollment code, then sign in (if required), and follow on-screen prompts to complete enrollment. Include the requirement to use Microsoft Edge browser.
  </Step>
</Steps>

### Enrollment Portal link and Enrollment code

You can also provide the Enrollment Portal link with the Enrollment code embedded in the URL for easier deployment. The format for the shareable link is listed below. The **EnrollmentCodeHere** portion should be the Enrollment code without the dash between the two sets of numbers.

```text Shareable enrollment URL (Windows) icon="link" theme={null}
https://subdomain.iru.com/enroll/windows/access-code/EnrollmentCodeHere
```

<Tip>
  Consider creating a template email or help article with these instructions to ensure consistency across your organization.
</Tip>

## Windows Enrollment Process

### User Enrollment Steps

When users access the Enrollment Portal on their Windows device, they'll enter the Enrollment code you provided and authenticate using SSO if you've enabled that option. Once authenticated, the device enrolls to Iru Endpoint for MDM management and gets configured according to your Blueprint settings.

### MDM Enrollment Process

The device enrolls to Iru Endpoint for MDM management. Once enrolled, MDM automatically pushes the Iru Agent and Self Service apps to the device. The Iru Agent handles app inventory and app lifecycle management, while policies and configurations are delivered through the MDM channel.

## Windows Management Features

Once enrolled, you can deploy applications, enforce security policies, and monitor compliance across your Windows devices. Iru Endpoint provides centralized management for user and device inventory, along with remote troubleshooting capabilities.

## Best Practices

Test your Blueprints on designated devices before enrolling production hardware. Enable SSO authentication for secure enrollment and provide clear instructions to users about the Windows enrollment process. You can monitor enrollment success and troubleshoot issues using the [Activity Page](/en/endpoint/devices/activity-page).

## Troubleshooting

### Trial Tenant Device Limit

Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again.

### Common Issues

If enrollment fails, check your Blueprint configuration and network connectivity. For authentication issues, ensure SSO is properly configured and users have the necessary access. Verify that the Iru Agent installs correctly and that Blueprint policies are applied after enrollment.

### Support Resources

Check the [Activity Page](/en/endpoint/devices/activity-page) for enrollment logs and errors, and review Device records for enrollment status. [Contact Support](/en/iru/iru-support/access-to-iru-support) if you need additional assistance.

## Related Articles

<CardGroup cols={2}>
  <Card title="Configure Windows Autopilot" icon="microsoft" href="/en/endpoint/settings/windows-integrations/configure-windows-autopilot">
    Microsoft Entra ID and Autopilot setup for zero-touch Windows enrollment
  </Card>

  <Card title="Blueprint Routing" icon="route" href="/en/endpoint/enrollment/blueprint-routing">
    Configure dynamic Blueprint assignment during device enrollment using Assignment Rules
  </Card>

  <Card title="Configuring Windows Enrollment" icon="microsoft" href="/en/endpoint/enrollment/windows/configuring-windows-enrollment">
    Complete guide to Windows device enrollment and management setup
  </Card>

  <Card title="User Experience with Windows Enrollment" icon="user" href="/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment">
    What to expect when enrolling your Windows device through the enrollment portal
  </Card>

  <Card title="Configure Require Authentication for Enrollment" icon="shield" href="/en/endpoint/enrollment/configure-require-authentication-for-enrollment">
    Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms
  </Card>
</CardGroup>

## Next Steps

After setting up Windows enrollment:

<Steps>
  <Step title="Test enrollment">
    Test the process with a few Windows devices and monitor compliance and policy enforcement on the [Activity Page](/en/endpoint/devices/activity-page).
  </Step>

  <Step title="Set up enrollment for other platforms (optional)">
    To enroll Apple or Android devices as well, see [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment) or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment).
  </Step>
</Steps>

If you missed a step or want to review the path, see [Getting Started](/en/endpoint/getting-started/getting-started) for the full guide.
