SOLVED

Approval flow for Azure AD Registration

%3CLINGO-SUB%20id%3D%22lingo-sub-2270415%22%20slang%3D%22en-US%22%3EApproval%20flow%20for%20Azure%20AD%20Registration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2270415%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20-%20is%20there%20a%20way%20to%20have%20an%20approval%20flow%20for%20getting%20a%20device%20Azure%20AD%20registered%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20an%20educational%20institution.%20Say%20we%20have%20a%20set%20of%20requirements%20for%20a%20registered%20device%2C%20in%20order%20for%20it%20to%20access%20our%20services%2C%20but%20we%20don't%20want%20just%20anybody%20to%20be%20able%20to%20register%20a%20device.%20MFA%20is%20not%20enough%2C%20as%20that%20doesn't%20require%20people%20to%20really%20consider%20whether%20or%20not%20to%20register%20a%20certain%20device%2C%20so%20we'd%20need%20an%20approval%20flow%20for%20employees%20to%20be%20able%20to%20AAD%20register%20a%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20the%20same%20time%2C%20we%20want%20students%20to%20be%20able%20to%20keep%20working%20from%20their%20privately%20owned%20devices%2C%20without%20the%20same%20requirements%2C%20yet%20they%20should%20be%20able%20to%20AAD%20register%20a%20device%20too.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe'd%20use%20Conditional%20Access%20to%20distinguish%20between%20students%20and%20employees%20logging%20on%20from%20AAD%20registered%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2270415%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Hello - is there a way to have an approval flow for getting a device Azure AD registered?

 

We are an educational institution. Say we have a set of requirements for a registered device, in order for it to access our services, but we don't want just anybody to be able to register a device. MFA is not enough, as that doesn't require people to really consider whether or not to register a certain device, so we'd need an approval flow for employees to be able to AAD register a device.

 

At the same time, we want students to be able to keep working from their privately owned devices, without the same requirements, yet they should be able to AAD register a device too.

 

We'd use Conditional Access to distinguish between students and employees logging on from AAD registered devices.

 

Thanks!

4 Replies
Are you talking about AAD Join or AAD registration, as those are different, with the latter being a requirement for O365 MDM/Intune. If AAD Join, you can limit it to specific users via the Azure AD blade > Devices > Device settings > Users may join devices to Azure AD selection.
Hello Vasil, thank you for replying. I'm talking about registration, not join, as we know that we can limit that.

It could be BYOD devices that are owned by employees themselves, including their own PC's at home, but also devices they may not directly own themselves. We're concerned that if all it takes to AAD register a device, is MFA, then they could in theory go borrow someone else's computer or maybe go to a netcafé or something like that, where they would have local admin, and then Azure AD register the device, without understanding what happens and then start syncing files from OneDrive or whatever else they might want to do. But we also don't want to eliminate the BYOD scenario entirely, thus thinking that if we could have an approval flow for such devices, then maybe that could be a workable middle ground.

Hope that makes sense?
best response confirmed by Allan With Sørensen (Contributor)
Solution
I think Microsoft's reasoning here is that you should be using the controls available within M365 MDM/Intune to address this, thus no granular control on Azure AD side.
Thank for that response - I'll post here, if we figure something out.