You can use Intune together with Azure Active Directory (Azure AD) conditional access policies to require multifactor authentication (MFA) during device enrollment. If you require MFA, employees and students wanting to enroll devices must first authenticate with a second device and two forms of credentials. We do not want unauthorized users joining devices to our network.
Policy
• MFA Shall be required to enroll devices into Intune
Licensing Considerations
This setting requires at least an Azure AD P1 license which comes standalone or as part of the following bundles: