Forum Discussion

bart_vermeersch's avatar
bart_vermeersch
Steel Contributor
Nov 27, 2020

Domain joined & MDM managed

I find a lot of conflicting info on:

 

Is it possible to manage (using MDM) a domain joined device without registering/joining it with Azure AD? Based on our tests, it seems possible.

 

What is the impact on the MDM management when the device is or isn't registered/joined to Azure AD?

 

Thanks!

    • bart_vermeersch's avatar
      bart_vermeersch
      Steel Contributor

      JanBakkerOrphaned  that's a good question 🙂

       

      I would like to understand the dependencies between "joined/registered/.." and "MDM/MAM".

       

      If a user with a byod device is going through the AAD device registering flow (when configuring Outlook or Teams), what makes that the device will be enrolled in MDM? I understand the user can opt-in, during the registration flow, but how is this configured in Azure and when is it enrolled in MDM vs MAM?  

       

      A domain joined device (AD) can be enrolled in MDM without (hybrid)joining the device. What are the benefits of hybrid joining if the device can be managed in MDM and SSO is covered in ADFS? 

       

      In our tenant, on-prem domain joined devices are also listed as AAD registered, I always thought this was not possible and you had to use (hybrid)join.

       

      Thanks!

Resources