Jun 19 2018
12:11 AM
- last edited on
Jan 14 2022
05:24 PM
by
TechCommunityAP
Jun 19 2018
12:11 AM
- last edited on
Jan 14 2022
05:24 PM
by
TechCommunityAP
Hi,
I want to join the Windows 10 devices to AAD using AAD Join, by this, I get SSO for resources in the cloud. But do I get SSO for on-premise resources for e.g Fileshares and Print etc?
I have gone through the below articles, I really did not understand how I get TGT & TGS from on-premise Dcs without the computer account in the on-premise active directory.
I do not want to use Domain Join + Device registration as I would like to manage client devices in Azure AD using intune(so only AADJoin so that i can manage devices using intune)
Articles i refered
https://blogs.technet.microsoft.com/trejo/2016/04/09/azure-ad-join-vs-azure-ad-device-registration/
https://blogs.technet.microsoft.com/janketil/2016/01/25/single-sign-on-to-on-premises-resources-from...
https://jankesblog.com/2016/01/single-sign-on-to-on-premises-resources-from-azure-ad-joined-when-onp...
Jun 19 2018 11:49 AM
Jun 27 2018 10:42 AM
SolutionHi,
At last i found that it is possible to get both PRT from AAD & TGT from onprem AD for a user logged on to AAD Join machine(no hybrid, just AAD Join).
We should have a windows 2016 AD DCs to achieve this.
I could get PRT & TGT once I installed 2016 DC.
Jun 27 2018 10:42 AM
SolutionHi,
At last i found that it is possible to get both PRT from AAD & TGT from onprem AD for a user logged on to AAD Join machine(no hybrid, just AAD Join).
We should have a windows 2016 AD DCs to achieve this.
I could get PRT & TGT once I installed 2016 DC.