Benefits to Azure AD registration for Windows 10 clients O365 sign-in - Would you recommend it?

%3CLINGO-SUB%20id%3D%22lingo-sub-116482%22%20slang%3D%22en-US%22%3ERe%3A%20Benefits%20to%20Azure%20AD%20registration%20for%20Windows%2010%20clients%20O365%20sign-in%20-%20Would%20you%20recommend%20it%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-116482%22%20slang%3D%22en-US%22%3EI'd%20like%20to%20know%20this%20as%20well%2C%20even%20though%20I%20have%2C%20additionally%20to%20your%20settings%2C%20enabled%20ADFS%20for%20true%20SSO.%3CBR%20%2F%3EAs%20far%20as%20I%20know%2C%20you'll%20profit%20from%20the%20possibility%20to%20enable%20user%20settings%20roaming%20and%20I%20believe%20some%20OMS%20integration.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-116267%22%20slang%3D%22en-US%22%3EBenefits%20to%20Azure%20AD%20registration%20for%20Windows%2010%20clients%20O365%20sign-in%20-%20Would%20you%20recommend%20it%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-116267%22%20slang%3D%22en-US%22%3E%3CP%3EOur%20environment%20is%20Office%20365%20with%20Azure%20AD%20Connect%20sync%20of%20accounts%20to%20our%20native%20Windows%20Active%20Directory.%26nbsp%3B%20We%20use%20multiple%20Office%20365%20services%20including%20Office%20365%20ProPlus.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECurrently%20our%20Windows%2010%20clients%20are%20domain-joined%20to%20the%20Windows%20AD%2C%20but%20%3CSTRONG%3Enot%3C%2FSTRONG%3E%20Azure%20AD%20registered.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMicrosoft%20seem%20to%20be%20encouraging%20users%20to%20Azure%20AD%20register%2C%20and%20we%20note%20that%20the%20Office%20ProPlus%201710%20encourages%20this%20via%20the%20%22Add%20this%20account%20to%20Windows%3F%22%20dialog%20(below)%2C%26nbsp%3B%20It%20suggests%202%20improvments%2C%20but%20I%20can't%20find%20the%20details.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EWindow%20can%20remember%20%7BWork%2FSchool%20Account%7D%26nbsp%3Bmaking%20it%20easier%20to%20sign%20in%20to%20other%20apps%20and%20web%20sites%3F%3C%2FSTRONG%3E%3C%2FP%3E%3COL%3E%3CLI%3EHow%20specifically%20is%20sign%20in%20remembered%3F%3C%2FLI%3E%3CLI%3ETo%20which%20services%2Fapps%2Fweb%20sites%20is%20the%20remembered%20sign-in%E2%80%99s%20applied%3F%3C%2FLI%3E%3CLI%3EHow%20specifically%20is%20sign-in%20easer%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CSTRONG%3EClicking%20Yes%20below%20means%20that%20you%20won%E2%80%99t%20have%20to%20enter%20your%20password%20each%20time%3F%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EThis%20implies%20that%20before%20Azure%20AD%20join%20do%20did%20have%20to%20enter%20your%20password%20%E2%80%98each%20time%E2%80%99.%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EWhich%20service%2Fapp%2Fweb%20sig-in%2Fpassword%20scenario%20does%20this%20refer%20to%3F%3C%2FLI%3E%3CLI%3EWhat%20does%20%E2%80%98each%20time%E2%80%99%20mean%20%E2%80%93%20each%20time%20of%E2%80%A6..%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EHas%20anyone%20experience%20of%20how%20Azure%20AD%20registration%20and%20the%20improvements%20highlighed.%26nbsp%3B%20I%20can't%20find%20any%20KB%20articles%20on%20this.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Account_Settings%20-%20Copy%20-%20Copy.png%22%20style%3D%22width%3A%20651px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22133i2D6CDF9D29B54B93%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Account_Settings%20-%20Copy%20-%20Copy.png%22%20alt%3D%22Account_Settings%20-%20Copy%20-%20Copy.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%20for%20any%20response.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERichard%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-116267%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1893100%22%20slang%3D%22en-US%22%3ERe%3A%20Benefits%20to%20Azure%20AD%20registration%20for%20Windows%2010%20clients%20O365%20sign-in%20-%20Would%20you%20recommend%20it%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1893100%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3751%22%20target%3D%22_blank%22%3E%40Richard%20Tinker%3C%2FA%3EWay%20late%20response%2C%20but%20no%2C%20I%20would%20highly%20highly%20recommend%20staying%20away%20from%20Azure%20AD%20registration%20as%20much%20as%20possible.%26nbsp%3B%20It's%20basically%20opening%20up%20an%20enormous%20security%20hole%20and%20its%20offensive%20that%20this%20cannot%20be%20disabled%20when%20you%20use%20MDM%20with%20Office365.%26nbsp%3B%20Even%20worse%20they%20offer%20no%20way%20to%20clean%20up%20stale%20devices%20that%20have%20been%20registered%20except%20through%20obscure%20powershell%20backend%20commands.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere's%20my%20issue%20with%20this%20%22feature%22%3A%3C%2FP%3E%3CP%3E1.%20It%20lets%20any%20unmanaged%20computer%20that%20registered%20in%20Azure%20AD%20unregulated%20access%20to%20Office365%20for%20up%20to%2090%20days%20without%20requiring%20any%20form%20of%20authentication.%26nbsp%3B%20All%20they%20need%20is%20a%20working%20user%20account.%3C%2FP%3E%3CP%3E2.%20Because%20you%20are%20registering%20with%20a%20company%20user%20account%2C%20the%20login%20to%20that%20unmanaged%20computer%20bypasses%20any%20password%20policies%20your%20AD%20domain%20might%20have.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20we%20experienced%20is%20that%20Azure%20AD%20registered%20devices%20can%20fully%20access%20all%20our%20Office365%20resources%2C%20even%20if%20the%20account%20they%20are%20using%20has%20an%20expired%20password%20due%20to%20the%2090%20day%20free-for-all%20access.%26nbsp%3B%20To%20make%20matters%20worse%2C%20you%20are%20leaving%20the%20control%20up%20to%20the%20user%20--%20admins%20cannot%20disable%20this%20ridiculous%20feature%20if%20they%20are%20using%20any%20form%20of%20Office365%20MDM%20(Intune%20or%20the%20standard%20one).%26nbsp%3B%20I%20even%20opened%20a%20support%20ticket%20to%20disable%20this%20garbage%20but%20got%20nowhere%20after%20being%20ping-ponged%20between%20the%20Azure%20and%20Intune%20team.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20I%20would%20block%20registration%20if%20you%20have%20that%20option%20still%20available%20to%20you.%26nbsp%3B%20Whoever%20thought%20this%20was%20a%20good%20idea%20should%20be%20required%20to%20sit%20through%20a%20weeks%20worth%20of%20security%20best%20practices.%26nbsp%3B%20Even%20if%20a%20device%20is%20registered%20in%20Azure%20AD%2C%20we%20still%20have%20no%20control%20over%20it.%26nbsp%3B%20Admins%20can%20disable%20or%20delete%20the%20device%2C%20but%20all%20this%20does%20is%20require%20them%20to%20reregister%20and%20they%20are%20good%20to%20go%20again.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Our environment is Office 365 with Azure AD Connect sync of accounts to our native Windows Active Directory.  We use multiple Office 365 services including Office 365 ProPlus.

 

Currently our Windows 10 clients are domain-joined to the Windows AD, but not Azure AD registered.

 

Microsoft seem to be encouraging users to Azure AD register, and we note that the Office ProPlus 1710 encourages this via the "Add this account to Windows?" dialog (below),  It suggests 2 improvments, but I can't find the details.

 

Window can remember {Work/School Account} making it easier to sign in to other apps and web sites?

  1. How specifically is sign in remembered?
  2. To which services/apps/web sites is the remembered sign-in’s applied?
  3. How specifically is sign-in easer?

Clicking Yes below means that you won’t have to enter your password each time?

This implies that before Azure AD join do did have to enter your password ‘each time’. 

  1. Which service/app/web sig-in/password scenario does this refer to?
  2. What does ‘each time’ mean – each time of…..?

 

Has anyone experience of how Azure AD registration and the improvements highlighed.  I can't find any KB articles on this.  

 

Account_Settings - Copy - Copy.png

 

Thanks in advance for any response.

 

Richard

2 Replies
I'd like to know this as well, even though I have, additionally to your settings, enabled ADFS for true SSO.
As far as I know, you'll profit from the possibility to enable user settings roaming and I believe some OMS integration.
Highlighted

@Richard TinkerWay late response, but no, I would highly highly recommend staying away from Azure AD registration as much as possible.  It's basically opening up an enormous security hole and its offensive that this cannot be disabled when you use MDM with Office365.  Even worse they offer no way to clean up stale devices that have been registered except through obscure powershell backend commands.

 

Here's my issue with this "feature":

1. It lets any unmanaged computer that registered in Azure AD unregulated access to Office365 for up to 90 days without requiring any form of authentication.  All they need is a working user account.

2. Because you are registering with a company user account, the login to that unmanaged computer bypasses any password policies your AD domain might have.

 

What we experienced is that Azure AD registered devices can fully access all our Office365 resources, even if the account they are using has an expired password due to the 90 day free-for-all access.  To make matters worse, you are leaving the control up to the user -- admins cannot disable this ridiculous feature if they are using any form of Office365 MDM (Intune or the standard one).  I even opened a support ticket to disable this garbage but got nowhere after being ping-ponged between the Azure and Intune team.

 

So I would block registration if you have that option still available to you.  Whoever thought this was a good idea should be required to sit through a weeks worth of security best practices.  Even if a device is registered in Azure AD, we still have no control over it.  Admins can disable or delete the device, but all this does is require them to reregister and they are good to go again.