Home

Azure AD Join on Windows 10 devices

%3CLINGO-SUB%20id%3D%22lingo-sub-272324%22%20slang%3D%22en-US%22%3EAzure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-272324%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20running%20a%20100%25%20cloud%20instance%20of%20Microsoft%20365%20for%20about%2010%20users.%26nbsp%3B%26nbsp%3B%20All%20those%20users%20have%20Surface%20Pro%204's%20running%20Windows%2010%20Pro.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20order%20to%20get%20the%20full%20benefit%20of%20the%20Microsoft%20365%20service%2C%20should%20I%20be%20%22joining%22%20these%20Surfaces%20to%20my%20Azure%20AD%20the%20same%20way%20that%20I%20would%20join%20an%20on%20premise%20Windows%202016%20domain%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20so%2C%20where%20can%20I%20find%20instructions%20for%20how%20to%20%22join%22%20my%20computers%20to%20my%20Azure%20AD%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-272324%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESurface%20Pro%204%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286178%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286178%22%20slang%3D%22en-US%22%3EHi%20Robert%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20am%20in%20agreement%20with%20the%20others.%20If%20you%20have%20Microsoft%20365%20then%3A%3CBR%20%2F%3E%3CBR%20%2F%3E1.)%20You%20can%20upgrade%20these%20Win%2010%20pros%20to%20Win%2010%20Business%20or%20Enterprise%20depending%20on%20your%20Win%2010%20SKU%3CBR%20%2F%3E%3CBR%20%2F%3E2.)%20Enrolling%20them%20into%20Azure%20AD%20means%20you%20can%20then%20manage%20them%20with%20Microsoft%20Intune%20and%20apply%20compliance%2C%20configuration%20and%20app%20protection%20policies%20to%20the%20local%20machines.%20This%20includes%20functionality%20like%20enforcing%20bitlocker%2C%20passwords%2C%20closing%20down%20the%20windows%20store%2C%20turning%20off%20the%20cameras%20and%20numerous%20other%20things.%3CBR%20%2F%3E%3CBR%20%2F%3E3.)%20By%20Azure%20AD%20joining%20you%20can%20push%20the%20bitlockers%20keys%20up%20to%20the%20Azure%20AD%20user%3CBR%20%2F%3E%3CBR%20%2F%3E4.)%20If%20you%20have%20the%20right%20Microsoft%20365%20SKU%20you%20can%20start%20implementing%20application%20SSO%20with%20Azure%20AD%3CBR%20%2F%3E%3CBR%20%2F%3E5.)%20You%20can%20set%20up%20Autopilot%20so%20that%20as%20soon%20a%20new%20machine%20joins%20AAD%20it%20is%20setup%20out%20of%20the%20box%3CBR%20%2F%3E%3CBR%20%2F%3EPete%20I%20do%20a%20good%20article%20how%20to%20join%20a%20machine%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petri.com%2Fjoin-windows-10-to-azure-active-directory%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petri.com%2Fjoin-windows-10-to-azure-active-directory%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-279096%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-279096%22%20slang%3D%22en-US%22%3E%3CP%3EYes.%20If%20it%20is%20Out%20of%20Box%20device%20use%20Windows%20Autopilot%20feature%20to%20configure%20and%20add%20them%20to%20AAD%20using%20Microsoft%20Intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20the%20devices%20are%20already%20Domain%20Joined%2C%20then%20use%20Work%20account%20from%20settings%20to%20get%20the%20device%20registered%20to%20AAD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-272342%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-272342%22%20slang%3D%22en-US%22%3E%3CP%3Eyes!%20i%20think%20you%20should%2C%20to%20benefit%20from%20all%20the%20features%20you%20get%20regarding%20managebility%20and%20security.%20Also%20automatic%20upgrade%20to%20win%2010%20enterprise%3C%2FP%3E%3CP%3EPlease%20read%20more%20here%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fazure%2Factive-directory%2Fdevices%2Fazuread-joined-devices-frx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fazure%2Factive-directory%2Fdevices%2Fazuread-joined-devices-frx%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3C%2FLINGO-BODY%3E
Robert Gordon
Contributor

We are running a 100% cloud instance of Microsoft 365 for about 10 users.   All those users have Surface Pro 4's running Windows 10 Pro.

 

In order to get the full benefit of the Microsoft 365 service, should I be "joining" these Surfaces to my Azure AD the same way that I would join an on premise Windows 2016 domain?

 

If so, where can I find instructions for how to "join" my computers to my Azure AD?

3 Replies

yes! i think you should, to benefit from all the features you get regarding managebility and security. Also automatic upgrade to win 10 enterprise

Please read more here:

 

https://docs.microsoft.com/sv-se/azure/active-directory/devices/azuread-joined-devices-frx

 

Adam

Yes. If it is Out of Box device use Windows Autopilot feature to configure and add them to AAD using Microsoft Intune.

 

If the devices are already Domain Joined, then use Work account from settings to get the device registered to AAD.

Hi Robert,

I am in agreement with the others. If you have Microsoft 365 then:

1.) You can upgrade these Win 10 pros to Win 10 Business or Enterprise depending on your Win 10 SKU

2.) Enrolling them into Azure AD means you can then manage them with Microsoft Intune and apply compliance, configuration and app protection policies to the local machines. This includes functionality like enforcing bitlocker, passwords, closing down the windows store, turning off the cameras and numerous other things.

3.) By Azure AD joining you can push the bitlockers keys up to the Azure AD user

4.) If you have the right Microsoft 365 SKU you can start implementing application SSO with Azure AD

5.) You can set up Autopilot so that as soon a new machine joins AAD it is setup out of the box

Pete I do a good article how to join a machine:

https://www.petri.com/join-windows-10-to-azure-active-directory

Best, Chris
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies