SOLVED

Domain joined & MDM managed

%3CLINGO-SUB%20id%3D%22lingo-sub-1936804%22%20slang%3D%22en-US%22%3EDomain%20joined%20%26amp%3B%20MDM%20managed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1936804%22%20slang%3D%22en-US%22%3E%3CP%3EI%20find%20a%20lot%20of%20conflicting%20info%20on%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20manage%20(using%20MDM)%20a%20domain%20joined%20device%20without%20registering%2Fjoining%20it%20with%20Azure%20AD%3F%20Based%20on%20our%20tests%2C%20it%20seems%20possible.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20is%20the%20impact%20on%20the%20MDM%20management%20when%20the%20device%20is%20or%20isn't%20registered%2Fjoined%20to%20Azure%20AD%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1936804%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1962232%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20joined%20%26amp%3B%20MDM%20managed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1962232%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F7187%22%20target%3D%22_blank%22%3E%40bart%20vermeersch%3C%2FA%3E%26nbsp%3BJust%20wondering%20what%20your%20use%20case%20is%20here%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1964163%22%20slang%3D%22en-US%22%3ERe%3A%20Domain%20joined%20%26amp%3B%20MDM%20managed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1964163%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F470541%22%20target%3D%22_blank%22%3E%40JanBakker330%3C%2FA%3E%26nbsp%3B%20that's%20a%20good%20question%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20like%20to%20understand%20the%20dependencies%20between%20%22joined%2Fregistered%2F..%22%20and%20%22MDM%2FMAM%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20a%20user%20with%20a%20byod%20device%20is%20going%20through%20the%20AAD%20device%20registering%20flow%20(when%20configuring%20Outlook%20or%20Teams)%2C%20what%20makes%20that%20the%20device%20will%20be%20enrolled%20in%20MDM%3F%20I%20understand%20the%20user%20can%20opt-in%2C%20during%20the%20registration%20flow%2C%20but%20how%20is%20this%20configured%20in%20Azure%20and%20when%20is%20it%20enrolled%20in%20MDM%20vs%20MAM%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20domain%20joined%20device%20(AD)%20can%20be%20enrolled%20in%20MDM%20without%20(hybrid)joining%20the%20device.%20What%20are%20the%20benefits%20of%20hybrid%20joining%20if%20the%20device%20can%20be%20managed%20in%20MDM%20and%20SSO%20is%20covered%20in%20ADFS%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20our%20tenant%2C%20on-prem%20domain%20joined%20devices%20are%20also%20listed%20as%20AAD%20registered%2C%20I%20always%20thought%20this%20was%20not%20possible%20and%20you%20had%20to%20use%20(hybrid)join.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Super Contributor

I find a lot of conflicting info on:

 

Is it possible to manage (using MDM) a domain joined device without registering/joining it with Azure AD? Based on our tests, it seems possible.

 

What is the impact on the MDM management when the device is or isn't registered/joined to Azure AD?

 

Thanks!

3 Replies

@bart vermeersch Just wondering what your use case is here? 

 

 

@JanBakkerOrphaned  that's a good question :)

 

I would like to understand the dependencies between "joined/registered/.." and "MDM/MAM".

 

If a user with a byod device is going through the AAD device registering flow (when configuring Outlook or Teams), what makes that the device will be enrolled in MDM? I understand the user can opt-in, during the registration flow, but how is this configured in Azure and when is it enrolled in MDM vs MAM?  

 

A domain joined device (AD) can be enrolled in MDM without (hybrid)joining the device. What are the benefits of hybrid joining if the device can be managed in MDM and SSO is covered in ADFS? 

 

In our tenant, on-prem domain joined devices are also listed as AAD registered, I always thought this was not possible and you had to use (hybrid)join.

 

Thanks!

Best Response confirmed by bart vermeersch (Super Contributor)
Solution
You will have automatic enrollment enabled which states that a device that is joined to AAD (or registered) will automatically enroll into Intune (https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enroll#enable-windows-10-automatic-en...).

You can block registration for domain joined PC's: HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin: "BlockAADWorkplaceJoin"=dword:00000001.

Have you checked out this site for more information about registration? https://docs.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-register

Azure AD Registration is something that is mostly done on personal devices.

For your corporate devices, hybrid join is the way to go. Because you can't force a device registration.

Hybrid Join also provides capabilities within conditional access, which registration does not.