Home

Restrict Certain Group Sign-Ins to AAD-Joined Device

%3CLINGO-SUB%20id%3D%22lingo-sub-400951%22%20slang%3D%22en-US%22%3ERestrict%20Certain%20Group%20Sign-Ins%20to%20AAD-Joined%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-400951%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20joined%20a%20few%20machines%20to%20Azure%20AD.%20I%20would%20like%20to%20be%20able%20to%20prevent%20some%20users%20from%20accessing%20an%20AAD-joined%20device%20but%20it%20seems%20that%20once%20a%20device%20is%20joined%20every%20user%20in%20the%20organization%20is%20capable%20of%20logging%20in%2C%20though%20they%20at%20least%20are%20limited%20to%20user%20privileges.%20Is%20it%20possible%20to%20prevent%20this%20behavior%3F%20It%20would%20be%20preferable%20to%20be%20able%20to%20allow%20only%20users%20in%20specific%20groups%20to%20log%20into%20specific%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEnterprise%20State%20Roaming%20is%20enabled%2C%20if%20it%20makes%20a%20difference.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-400951%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-400989%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20Certain%20Group%20Sign-Ins%20to%20AAD-Joined%20Device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-400989%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20not%20aware%20of%20any%20method%2C%20but%20interested%20to%20see%20if%20I%20might%20have%20missed%20something.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

I have joined a few machines to Azure AD. I would like to be able to prevent some users from accessing an AAD-joined device but it seems that once a device is joined every user in the organization is capable of logging in, though they at least are limited to user privileges. Is it possible to prevent this behavior? It would be preferable to be able to allow only users in specific groups to log into specific devices.

 

Enterprise State Roaming is enabled, if it makes a difference.

1 Reply

I'm not aware of any method, but interested to see if I might have missed something.