Event banner
Windows Office Hours: January 16, 2025
Event Ended
Thursday, Jan 16, 2025, 08:00 AM PSTEvent details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keep...
Pearl-Angeles
Updated Jan 08, 2025
Amarjeet5
Jan 16, 2025Iron Contributor
For strong cert mapping changes does it impact devices that are Microsoft Entra joined only? The blog post discusses hybrid joined for Windows devices being impacted.
- For device certificates, only Microsoft Entra hybrid joined devices will have SID information, so strong mapping changes are applicable only to Windows devices that are Microsoft Entra hybrid joined. For other device types, like iOS or Android, strong mapping is not supported for device certificates, and user certificates should be used instead.
From blog post: Support tip: Implementing strong mapping in Microsoft Intune certificates
HeyHey16K
Jan 16, 2025Iron Contributor
This MS article also suggests it only affects HAADJ computers:
https://learn.microsoft.com/en-us/mem/intune/fundamentals/in-development#plan-for-change-implement-strong-mapping-for-scep-and-pkcs-certificates
- Jason_SandysJan 16, 2025
Microsoft
This is correct since the strong mapping changes are for on-prem AD only and Entra joined devices and any certificates that are issued to them are not related to on-prem AD.