
StephenH.69375 (Customer) asked a question.
We have been able to create rules to allow us to register our devices as Hybrid-Joined devices in Azure. The rule stops MFA from being requested. We have request.userAgent.contains("Windows-AzureAD-Authentication-Provider") in the custom expression as well as check that the client is Exchange ActiveSync/Legacy Auth
We now need a new rule to allow machines to automatically enroll in Intune, i.e. also stopping MFA and allowing just password.
Does anyone know what we need in the custom expression for the rule to see that it is an Intune erollment being made?

Hello @StephenH.69375 (Customer) Thank you for posting on our Community page!
The Okta Community Questions forum isn't really meant for in-depth troubleshooting.
I would recommend to have a Support ticket open, then continuing the discussion with the assigned Technical Support Engineers. They'll be able to access additional tools and resources to help you get to the bottom of it.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.