# Enroll Win 10 or above Laptops, Desktops & Surface Pro Tablets Last updated: August 14, 2026 This page explains how to enroll Windows 10 or above laptops, desktops, and Surface Pro tablets with ManageEngine MDM. It covers downloading and running the enrollment tool, assigning users individually or in bulk via a CSV file, and verifying enrollment on the device. It also details how Endpoint Central users can automate Windows laptop enrollment using a Custom Script configuration and Dynamic Custom Groups, ensuring new systems are enrolled automatically without manual intervention. With the advent of Windows 10 or above MDM now lets you manage any kind of Windows device - be it laptop, desktop or Surface Pro tablets. The major advantage is the unified dashboard to manage all your Windows 10 or above devices and machines, ensuring all the requisite configurations aren't done twice - once for devices and once for machines. ## Procedure Follow the steps given below to enroll a Windows machine with MDM: - On the MDM server, Click **Enrollment** tab from the top menu and select **Laptop and Surface Pro enrollment**, present under **Windows.** - Download the enrollment tool from the MDM server, on the machine to be enrolled and extract the contents. You can also copy the extracted contents and paste it on the machines to be enrolled. - From the extracted contents, run enrollment.bat to enroll the machine with MDM. You can view the list of devices enrolled by clicking on **Laptop and Surface Pro enrollment** tab from the left pane. - Now the enrolled devices will be listed in the MDM server. You need to assign users to these devices to complete enrollment. - You assign users on a device-to-device basis or in bulk using a CSV. In case of the former, Click the Assign user option present under Actions, against the device and provide the requisite data to complete user assignment. In case of the latter, Click Assign Users and upload a CSV ([View Sample CSV](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_enrolling_windows_desktops_laptops_tablets.html#sample_csv)) file with requisite details. You can additionally add devices to multiple groups to automate the distribution of apps, profiles and documents to devices. - You can verify if the machine has been enrolled by navigating to **Settings --> Accounts --> Access work or school** and an MDM account will be displayed here. ## Sample CSV Format 1. The fields Serial Number, User Name, Email Address and Group Name are mandatory. All the other fields are optional. Ensure the specified group name is already created in the MDM server. If values are not provided, default values will be taken. 2. The default values for various non-mandatory fields are: Domain Name -- MDM Owned By -- Corporate 3. If multiple groups are specified, the group names must be separated with a slash (/) 4. The first line of the CSV is the column header and the columns can be in any order. 5. Blank column values should be comma separated. 6. If the column value contains comma, it should be specified within quotes. ## Automated Enrollment for Endpoint Central Users Endpoint Central is ManageEngine's unified endpoint management solution. So if you are a Endpoint Central user you can enjoy the benefits of managing both the modern and legacy systems right from a single console. MDM has further simplified the enrollment process for Windows Laptops, and Surface Pros that are already managed by Endpoint Central. Follow the steps given below to automate your Win laptop and surface pro enrollment- 1. On the MDM server, navigate to the **Mobile Device Mgmt** tab and select **Enrollment** from the left pane. 2. Under the **Windows** Enrollment methods, Click **Laptop and SurfacePro Enrollment**. 3. From the server, download the zip file titled **ManageEngine_MDMLaptopEnrollment.zip** by clicking on **Download**. Extract the file once the download is completed. 4. Navigate to the **Configurations** tab on the Endpoint Central console. 5. Under **Configurations**, select **Windows** from the menu that appears when you hover over it. 6. Select the **Custom Script** and then **Computer**. 7. Provide a name to your Configuration. 8. In the **Specify the exit code** field, enter the exit code that indicates successful script execution. This is a mandatory field. 9. For the **Execute script from** option, choose **Command line** 10. Enter **enrollment.bat -s** in the **Command line** text box. 11. Click **Add** to add the dependency files. To find the files, navigate to the **Scripts** folder in the extracted zip file. The following dependency files need to be uploaded: - enrollment.bat - logger.conf - mdmregistrationhandler.exe - mdmServer.cer (This file will not be available if you are using third-party certificates to secure the server.) - mdmregistrationhandler_64.exe 12. You can also choose the frequency based on your requirement. The next step would be to select the target computers which need to be enrolled. 1. Under **Define target**, you can choose the remote office or the domain for which you want to apply this configuration. 2. Once you have selected your target systems, you can make the other changes as required. 3. Click either **Deploy** or **Deploy Now**. But what happens if your organization purchases new laptops, would you have to run this configuration again for those systems? You don't have to! You can just create a **Dynamic Custom group** to which systems are added if they meet certain criteria. Follow the steps given below to create a dynamic custom group: 1. Navigate to **Admin** and under **Global Settings** select **Custom Groups** 2. Click **Create new group**. 3. Enter a **Group Name** and under **Category** select **Dynamic**. 4. Configure to ensure that any new Win system gets added to this custom group. 5. Click **Create Group**. Once the custom group is created, you can choose this group while defining a target for the created configuration. This will ensure that any new system that in managed by Endpoint Central will automatically get enrolled with MDM. ## Assigning Users Once the system is enrolled with MDM, it will be available in the **Laptop and SurfacePro Enrollment** page along with the rest of the mobile devices. You can complete the user assignment process as explained earlier in this document. ## Frequently Asked Questions ### 1. Which Windows versions are supported for enrollment in ManageEngine MDM? ManageEngine MDM supports enrollment of devices running Windows 10 and later, including laptops, desktops, and Surface Pro tablets. Windows devices must have an active internet connection to communicate with the MDM server. ### 2. Can Windows devices be enrolled in ManageEngine MDM without joining an Azure AD domain? Yes. Windows devices can be enrolled using a local account and the enrollment URL or QR code provided in the enrollment invitation, without requiring Azure AD or domain joining. ### 3. What management capabilities are available for enrolled Windows devices? After enrollment, administrators can push Wi-Fi profiles, VPN configurations, certificates, and restrictions, as well as remotely lock, wipe, and track enrolled Windows desktops, laptops, and tablets through the ManageEngine MDM console.