Azure AD Join on Windows 10 devices

%3CLINGO-SUB%20id%3D%22lingo-sub-272324%22%20slang%3D%22en-US%22%3EAzure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-272324%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20running%20a%20100%25%20cloud%20instance%20of%20Microsoft%20365%20for%20about%2010%20users.%26nbsp%3B%26nbsp%3B%20All%20those%20users%20have%20Surface%20Pro%204's%20running%20Windows%2010%20Pro.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20order%20to%20get%20the%20full%20benefit%20of%20the%20Microsoft%20365%20service%2C%20should%20I%20be%20%22joining%22%20these%20Surfaces%20to%20my%20Azure%20AD%20the%20same%20way%20that%20I%20would%20join%20an%20on%20premise%20Windows%202016%20domain%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20so%2C%20where%20can%20I%20find%20instructions%20for%20how%20to%20%22join%22%20my%20computers%20to%20my%20Azure%20AD%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-272324%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESurface%20Pro%204%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-286178%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-286178%22%20slang%3D%22en-US%22%3EHi%20Robert%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20am%20in%20agreement%20with%20the%20others.%20If%20you%20have%20Microsoft%20365%20then%3A%3CBR%20%2F%3E%3CBR%20%2F%3E1.)%20You%20can%20upgrade%20these%20Win%2010%20pros%20to%20Win%2010%20Business%20or%20Enterprise%20depending%20on%20your%20Win%2010%20SKU%3CBR%20%2F%3E%3CBR%20%2F%3E2.)%20Enrolling%20them%20into%20Azure%20AD%20means%20you%20can%20then%20manage%20them%20with%20Microsoft%20Intune%20and%20apply%20compliance%2C%20configuration%20and%20app%20protection%20policies%20to%20the%20local%20machines.%20This%20includes%20functionality%20like%20enforcing%20bitlocker%2C%20passwords%2C%20closing%20down%20the%20windows%20store%2C%20turning%20off%20the%20cameras%20and%20numerous%20other%20things.%3CBR%20%2F%3E%3CBR%20%2F%3E3.)%20By%20Azure%20AD%20joining%20you%20can%20push%20the%20bitlockers%20keys%20up%20to%20the%20Azure%20AD%20user%3CBR%20%2F%3E%3CBR%20%2F%3E4.)%20If%20you%20have%20the%20right%20Microsoft%20365%20SKU%20you%20can%20start%20implementing%20application%20SSO%20with%20Azure%20AD%3CBR%20%2F%3E%3CBR%20%2F%3E5.)%20You%20can%20set%20up%20Autopilot%20so%20that%20as%20soon%20a%20new%20machine%20joins%20AAD%20it%20is%20setup%20out%20of%20the%20box%3CBR%20%2F%3E%3CBR%20%2F%3EPete%20I%20do%20a%20good%20article%20how%20to%20join%20a%20machine%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petri.com%2Fjoin-windows-10-to-azure-active-directory%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petri.com%2Fjoin-windows-10-to-azure-active-directory%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-279096%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-279096%22%20slang%3D%22en-US%22%3E%3CP%3EYes.%20If%20it%20is%20Out%20of%20Box%20device%20use%20Windows%20Autopilot%20feature%20to%20configure%20and%20add%20them%20to%20AAD%20using%20Microsoft%20Intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20the%20devices%20are%20already%20Domain%20Joined%2C%20then%20use%20Work%20account%20from%20settings%20to%20get%20the%20device%20registered%20to%20AAD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-272342%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20on%20Windows%2010%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-272342%22%20slang%3D%22en-US%22%3E%3CP%3Eyes!%20i%20think%20you%20should%2C%20to%20benefit%20from%20all%20the%20features%20you%20get%20regarding%20managebility%20and%20security.%20Also%20automatic%20upgrade%20to%20win%2010%20enterprise%3C%2FP%3E%3CP%3EPlease%20read%20more%20here%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fazure%2Factive-directory%2Fdevices%2Fazuread-joined-devices-frx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fazure%2Factive-directory%2Fdevices%2Fazuread-joined-devices-frx%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

We are running a 100% cloud instance of Microsoft 365 for about 10 users.   All those users have Surface Pro 4's running Windows 10 Pro.

 

In order to get the full benefit of the Microsoft 365 service, should I be "joining" these Surfaces to my Azure AD the same way that I would join an on premise Windows 2016 domain?

 

If so, where can I find instructions for how to "join" my computers to my Azure AD?

3 Replies
Highlighted

yes! i think you should, to benefit from all the features you get regarding managebility and security. Also automatic upgrade to win 10 enterprise

Please read more here:

 

https://docs.microsoft.com/sv-se/azure/active-directory/devices/azuread-joined-devices-frx

 

Adam

Highlighted

Yes. If it is Out of Box device use Windows Autopilot feature to configure and add them to AAD using Microsoft Intune.

 

If the devices are already Domain Joined, then use Work account from settings to get the device registered to AAD.

Highlighted
Hi Robert,

I am in agreement with the others. If you have Microsoft 365 then:

1.) You can upgrade these Win 10 pros to Win 10 Business or Enterprise depending on your Win 10 SKU

2.) Enrolling them into Azure AD means you can then manage them with Microsoft Intune and apply compliance, configuration and app protection policies to the local machines. This includes functionality like enforcing bitlocker, passwords, closing down the windows store, turning off the cameras and numerous other things.

3.) By Azure AD joining you can push the bitlockers keys up to the Azure AD user

4.) If you have the right Microsoft 365 SKU you can start implementing application SSO with Azure AD

5.) You can set up Autopilot so that as soon a new machine joins AAD it is setup out of the box

Pete I do a good article how to join a machine:

https://www.petri.com/join-windows-10-to-azure-active-directory

Best, Chris