Home

Azure AD Conditional Access - Require Domain Joined Device

%3CLINGO-SUB%20id%3D%22lingo-sub-136963%22%20slang%3D%22en-US%22%3EAzure%20AD%20Conditional%20Access%20-%20Require%20Domain%20Joined%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-136963%22%20slang%3D%22en-US%22%3E%3CP%3ECan%20someone%20help%20me%20with%20this%20scenario%3B%3C%2FP%3E%0A%3CP%3EWe%20are%20planning%20to%20move%20from%20on%20premise%20AD%20to%20Azure%20AD.%3C%2FP%3E%0A%3CP%3EAll%20colleagues%20have%20an%20Office%20365%20E3%20account%20and%20will%20have%20added%20their%20Office%20365%20account%20to%20their%20device%20for%20Single%20Sign%20On%20and%20device%20registration.%3C%2FP%3E%0A%3CP%3EWhat%20are%20the%20next%20steps%20and%20what%20happens%20to%20the%20user%20profile%3F%3C%2FP%3E%0A%3CP%3EDisconnect%20from%20AD%3F%3C%2FP%3E%0A%3CP%3EHow%20can%20I%20get%20the%20logon%20screen%20after%20starting%20the%20device%20to%20log%20on%20as%20an%20Office%20365%20user%3F%3C%2FP%3E%0A%3CP%3EAre%20the%20user%20profiles%20lost%3F%3C%2FP%3E%0A%3CP%3EIs%20everybody%20still%20a%20member%20of%20the%20local%20administrators%20group%20as%20they%20where%20when%20AD%20joined%3F%3C%2FP%3E%0A%3CP%3EIs%20the%20way%20to%20go%20Windows%20ICD%3F%3C%2FP%3E%0A%3CP%3EI%20know%20a%20lot%20of%20questions%2C%20but%20I%20hope%20someone%20can%20help%20me%20or%20guide%20me%20to%20a%20good%20resource.%3C%2FP%3E%0A%3CP%3EThanks%20a%20lot%20in%20advance!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-136963%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-142038%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Conditional%20Access%20-%20Require%20Domain%20Joined%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-142038%22%20slang%3D%22en-US%22%3E%3CP%3ERichard%2C%3C%2FP%3E%0A%3CP%3EFirstly%20Azure%20AD%20is%20not%20the%20same%20as%20your%20on-premise%20AD.%20Microsoft%20offers%20Azure%20AD%20Domain%20Services%20to%20manage%20Azure%20AD%20and%20allows%20you%20to%20be%20able%20to%20join%20Azure%20VMs%20to%20Azure%20AD.%20Please%20note%20it%20does%20not%20allow%20you%20to%20join%20your%20on-premise%20servers%20and%20devices%20to%20join%20Azure%20AD.%20You%20may%20want%20to%20watch%20my%20you%20tube%20video%20for%20better%20understanding%20at%2C%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DjpT1MxEkEzI%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DjpT1MxEkEzI%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESecondly%20you%20may%20join%20your%20Windows%2010%20Devices%20to%20Azure%20AD.%20You%20can%20accomplish%20it%20to%20your%20already%20domain%20joined%20devices.%20Therefore%20your%20devices%20can%20be%20joined%20to%20both%20Azure%20AD%20as%20well%20as%20on-premise%20AD.%20If%20you%20are%20using%20ADFS%2C%20it%20needs%20a%20Power%20Shell%20command%20to%20make%20necessary%20changes%20to%20your%20on-premise%20AD%20Schema.%3C%2FP%3E%0A%3CP%3EAs%20Azure%20AD%20is%20not%20replacing%20on-premise%20AD%20at%20least%20for%20now%2C%20you%20may%20want%20to%20keep%20your%20on-prem%20AD%20and%20but%20take%20advantages%20of%20Azure%20AD.%3C%2FP%3E%0A%3CP%3EIf%20you%20decide%20to%20go%20this%20route%2C%20then%20your%20questions%20around%20users'%20profile%20and%20administrators%20membership%20are%20no%20more%20a%20question%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-141544%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Conditional%20Access%20-%20Require%20Domain%20Joined%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-141544%22%20slang%3D%22en-US%22%3EFrom%20looking%20at%20your%20post%20I%20would%20setup%20an%20Intune%20environment%20with%20the%20settings%20and%20policies%20you%20want%20for%20your%20Windows%2010%20devices.%20Setup%20conditional%20access%20so%20you%20can%20restrict%20access%20if%20the%20machine%20does%20not%20meet%20your%20requirements%20it%20does%20not%20access%20your%20resources.%20Once%20that%20is%20setup%20get%20a%20new%20build%20machine%2C%20i.e.%20off%20the%20shelf%20and%20just%20set%20it%20up%20off%20the%20domain%20with%20a%20local%20username%20and%20password%2C%20kind%20of%20like%20you%20would%20a%20home%20computer.%20Once%20you%20have%20got%20that%20done%20enrol%20the%20device%20into%20Intune%2C%20this%20should%20also%20Azure%20domain%20join%2Fregister%20(not%20sure%20on%20this%20week%E2%80%99s%20terminology)%20the%20device%2C%20your%20policies%20should%20apply%2C%20then%20you%20should%20be%20able%20to%20use%20your%20office%20365%20environment.%20Obviously%20this%20is%20very%20high%20level%20and%20you%20will%20need%20to%20do%20a%20lot%20of%20work%20to%20figure%20out%20the%20exact%20settings%20and%20obviously%20test%20it%20touchhole%20before%20rolling%20out%20to%20end%20users%2C%20also%20make%20sure%20you%20document%20as%20much%20as%20you%20can%20for%20the%20setup%20processes%2C%20so%20that%20your%20support%20team%20has%20minimal%20work%20and%20you%20have%20minimal%20escalations.%3C%2FLINGO-BODY%3E
Richard Dokter
New Contributor

Can someone help me with this scenario;

We are planning to move from on premise AD to Azure AD.

All colleagues have an Office 365 E3 account and will have added their Office 365 account to their device for Single Sign On and device registration.

What are the next steps and what happens to the user profile?

Disconnect from AD?

How can I get the logon screen after starting the device to log on as an Office 365 user?

Are the user profiles lost?

Is everybody still a member of the local administrators group as they where when AD joined?

Is the way to go Windows ICD?

I know a lot of questions, but I hope someone can help me or guide me to a good resource.

Thanks a lot in advance! 

2 Replies
From looking at your post I would setup an Intune environment with the settings and policies you want for your Windows 10 devices. Setup conditional access so you can restrict access if the machine does not meet your requirements it does not access your resources. Once that is setup get a new build machine, i.e. off the shelf and just set it up off the domain with a local username and password, kind of like you would a home computer. Once you have got that done enrol the device into Intune, this should also Azure domain join/register (not sure on this week’s terminology) the device, your policies should apply, then you should be able to use your office 365 environment. Obviously this is very high level and you will need to do a lot of work to figure out the exact settings and obviously test it touchhole before rolling out to end users, also make sure you document as much as you can for the setup processes, so that your support team has minimal work and you have minimal escalations.

Richard,

Firstly Azure AD is not the same as your on-premise AD. Microsoft offers Azure AD Domain Services to manage Azure AD and allows you to be able to join Azure VMs to Azure AD. Please note it does not allow you to join your on-premise servers and devices to join Azure AD. You may want to watch my you tube video for better understanding at,

https://www.youtube.com/watch?v=jpT1MxEkEzI

 

Secondly you may join your Windows 10 Devices to Azure AD. You can accomplish it to your already domain joined devices. Therefore your devices can be joined to both Azure AD as well as on-premise AD. If you are using ADFS, it needs a Power Shell command to make necessary changes to your on-premise AD Schema.

As Azure AD is not replacing on-premise AD at least for now, you may want to keep your on-prem AD and but take advantages of Azure AD.

If you decide to go this route, then your questions around users' profile and administrators membership are no more a question?  

Demystifying Microsoft Security https://www.youtube.com/watch?v=qPJ-1_rPdOg&t=36s Azure Multi Factor Authentication https://www.youtube.com/watch?v=dA8N0gh-GCk&t=979s Azure B2B for On-Prem SharePoint External Users Access https://www.youtube.com/watch?v=WRnCBYaPQhs&t=5s Phishing Email Attacks and
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies