Public/TenantConfiguration/Baseline/DeviceRegistrationPolicies/DeviceRegistrationPolicy.json

{
    "@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/deviceRegistrationPolicy/$entity",
    "multiFactorAuthConfiguration": "notRequired",
    "id": "deviceRegistrationPolicy",
    "displayName": "Device Registration Policy",
    "description": "Tenant-wide policy that manages initial provisioning controls using quota restrictions, additional authentication and authorization checks",
    "userDeviceQuota": 50,
    "azureADRegistration": {
      "isAdminConfigurable": false,
      "allowedToRegister": {
        "@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
      }
    },
    "azureADJoin": {
      "isAdminConfigurable": true,
      "allowedToJoin": {
        "@odata.type": "#microsoft.graph.allDeviceRegistrationMembership"
      }
    },
    "localAdminPassword": {
      "isEnabled": true
    }
  }