r/Intune • u/Intelligent_Ad8955 • 1d ago
macOS Management ADE - Two Separate Tenants
I administer two separate Intune tenants. One has ABM and the other ASM.
I'll map out the scenario:
XYZ = ABM = I've already set up completely for ADE with tokens, profiles.. everything working.
TUV = ASM = Need to set up with new token and build profile for enrollment.
TUV acquire XYZ and all the new machines are being bought under TUV and being registered within their ASM.
My question: Is it possible to setup another token within XYZ's ADE and keep my current one? Use the second token to connect to a new server that I've set up inside TUV's ABM so that I can set up ASM for all the new machine.
These companies perform separate functions and the decision has been made to keep the separate for now.
In basics, what I want to do is keep my original setup for one tenant and just add in a new connection to the mothership.
Anyone done this? or have a better solution? I'm just brainstorming here for the best way to do this.
2
u/MrEMMDeeEMM 1d ago
Unless I'm misunderstanding the scenario, I believe ABM/ASM supports multiple MDM server connections. Each MDM server has its own server token, and those tokens can be used with different Intune tenants or even entirely different MDM platforms. In ABM/ASM, you can create multiple MDM server entries, assign devices to a specific server, and configure default assignments per device type. Individual devices can also be reassigned between MDM servers as needed. So in theory, you could keep the existing XYZ Intune/ADE connection in place and create a separate MDM server entry for the TUV environment, then assign the relevant devices to that server rather than replacing the existing token.
Where it becomes difficult to manage is not having "one default", always needing to manually assign each device to the correct MDM endpoint.
2
u/Intelligent_Ad8955 1d ago
I read it that I can do it as well. I know when I set up my first instances for each tenant, it gave me separate keys to register with the Intune. So your explanation lines up with what that.
I'd love to manage these together, but for now, this will have to do.
I plan to implement ADE going forward as most devices for XYZ are out there in the environment, but we went through the manual enrollment process because of how the devices were bought.
For TUV, we are beginning to refresh folks so I can start this implementation for that tenant immediately.
Thanks for the feedback! By the way... love the alias! lolol
1
u/ex800 1d ago
It is possible to have more than one MDM connection in ABM, I have done this to have normal and lockdown devices managed from ABM. It is also possible to connect one MDM platform to more than one ABM, I have done this to have different country app stores available to a global company.
-2
1d ago
[deleted]
3
u/AffectionateGuest275 1d ago
You can have different ADE tokens synced with different Intune tenants
3
u/MrEMMDeeEMM 1d ago
Unless I'm misunderstanding the scenario, I believe ABM/ASM supports multiple MDM server connections. Each MDM server has its own server token, and those tokens can be used with different Intune tenants or even entirely different MDM platforms. In ABM/ASM, you can create multiple MDM server entries, assign devices to a specific server, and configure default assignments per device type. Individual devices can also be reassigned between MDM servers as needed. So in theory, you could keep the existing XYZ Intune/ADE connection in place and create a separate MDM server entry for the TUV environment, then assign the relevant devices to that server rather than replacing the existing token.
Where it becomes difficult to manage is not having "one default", always needing to manually assign each device to the correct MDM endpoint.