How to switch from a local user account/profile , to using an Azure AD connected account/profile?

%3CLINGO-SUB%20id%3D%22lingo-sub-332652%22%20slang%3D%22en-US%22%3EHow%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-332652%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20a%20few%20Surface%20Pro%20devices%20that%20have%20users%20logging%20into%20Windows%2010%20Pro%20using%20a%20local%20user%20account.%26nbsp%3B%26nbsp%3B%20We%20have%20since%20migrated%20to%20Microsoft%20365%20Business%20so%20I%20would%20like%20these%20users%20to%20start%20logging%20in%20using%20their%20M365%20Azure%20AD%20account%2C%20so%20that%20they%20can%20self-service%20their%20login%20password%20and%20MFA%20method%2C%20as%20well%20as%20allowing%20me%20to%20better%20manage%20their%20device%20through%20InTune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20do%20I%20switch%20the%20user%20over%20to%20an%20Azure%20AD%20login%20account%20and%20Windows%20profile%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-332652%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%20Join%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20365%20Business%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ewindows%2010%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-334268%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-334268%22%20slang%3D%22en-US%22%3E%3CP%3EYes%20it%20will%20-%20Be%20sure%20you%20login%20with%20the%20account%20you%20specified%20when%20you%20joined%20to%20the%20device%20to%20Azure%20AD%20-%20or%20added%20any%20other%20accounts%20to%20the%20machine%20that%20you%20want%20logging%20in.%26nbsp%3B%20I%20use%20this%20on%20a%20good%20number%20of%20my%20devices.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-333023%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-333023%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%2C%20Murray.%26nbsp%3B%26nbsp%3B%20And%20once%20I%20do%20this%2C%20will%20that%20then%20give%20me%20the%20prompt%20after%20the%20next%20reboot%20to%20enter%20my%20Office%20365%20email%20address%2C%20and%20not%20just%20a%20username%2C%20to%20log%20onto%20the%20Surface%20Pro%20and%20that%20will%20take%20me%20into%20my%20%22Azure%20AD%22%20specific%20profile%20on%20the%20device%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-332717%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-332717%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-right%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F72292i05298AE2BA3D2DFF%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22AccessWorkorSchool.jpg%22%20title%3D%22AccessWorkorSchool.jpg%22%20%2F%3E%3C%2FSPAN%3EIn%20the%20Settings%20menu%20--%26gt%3B%20Accounts%20choose%20the%20Access%20Work%20or%20School%20and%20choose%20the%20connect%2C%20make%20sure%20you%20choose%20the%20option%20to%20join%20Azure%20AD%2C%20then%20from%20the%20Accounts%20--%26gt%3B%20Other%20Users%20Add%20other%20users%20and%20add%20the%20Azure%20AD%20account%20you%20want%20to%20login%20as%20a%20Standard%20or%20Administrator.%26nbsp%3B%20This%20will%20allow%20the%20user%20to%20then%20login.%26nbsp%3B%20At%20the%20login%20prompt%20use%20the%20Azure%20AD%20email%20address%20(UPN)%20to%20login.%26nbsp%3B%20It%20will%20create%20a%20new%20profile%20for%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2418543%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2418543%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F178244%22%20target%3D%22_blank%22%3E%40Murray%20Wall%3C%2FA%3EI%20also%20followed%20the%20same%20steps%20and%20entered%20office%20email%20address%20which%20is%20my%20UPN%20as%20an%20user%20and%20it%20didnt%20accept%20it%20saying%20its%20not%20a%20microsoft%20account%2C%20I%20tried%20all%20other%20available%20option%20none%20of%20them%20worked.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2480105%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2480105%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1070207%22%20target%3D%22_blank%22%3E%40navn1620%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20the%20same%20issue%2C%20you%20should%20add%20the%20account%20again%20in%20the%20work%20or%20school%20account%20panel%2C%20and%20be%20sure%20to%20select%20the%20Azure%20AD%20option.%20It%20should%20all%20work%20fine%20then.%20Hope%20this%20helps!%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEDIT%3A%3C%2FP%3E%3CP%3EAfter%20doing%20the%20step%20above%20you%20can%20log%20out%20of%20your%20current%20account%20en%20then%20select%20the%20option%20to%20sign%20in%20with%20a%20different%20account%2C%20just%20sign%20in%20with%20the%20credentials%20of%20the%20user%20and%20it%20should%20work.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2697617%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2697617%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%20and%20how%20it%20works%20in%20offline%20mode.%20I%20couldn't%20login%20to%20the%20computer%20without%20internet%20connection...%20So%20in%20that%20case%20we%20will%20use%20Office%20365%20Azure%20AD%20account%20we%20will%20not%20be%20able%20to%20work%20in%20that%20profile%20without%20internet%2C%20in%20offline%20mode%3F%20Or%20how%20to%20set%20up%20to%20be%20able%3F%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2700071%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20switch%20from%20a%20local%20user%20account%2Fprofile%20%2C%20to%20using%20an%20Azure%20AD%20connected%20account%2Fprofile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2700071%22%20slang%3D%22en-US%22%3EYou%20should%20be%20able%20to%20login%20to%20a%20computer%20you%20have%20previously%20been%20authenticated%20on%2C%20on%20a%20new%20machine%2C%20you%20must%20be%20connected%20to%20M365%20to%20authenticate.%20You%20canalso%20have%20a%20hybrid%20joined%20machine%20or%20use%20a%20hardware%20token%20or%20passwordless%20auth%20that%20has%20something%20stored%20in%20the%20local%20TPM%20that%20is%20trusted%20as%20a%20long%20term%20solution.%20Also%20know%20that%20you%20need%20to%20be%20online%20at%20some%20point%20in%20time%20to%20be%20able%20to%20renew%20and%20actually%20use%20the%20SaaS....%3C%2FLINGO-BODY%3E
Frequent Contributor

We have a few Surface Pro devices that have users logging into Windows 10 Pro using a local user account.   We have since migrated to Microsoft 365 Business so I would like these users to start logging in using their M365 Azure AD account, so that they can self-service their login password and MFA method, as well as allowing me to better manage their device through InTune.

 

How do I switch the user over to an Azure AD login account and Windows profile?

7 Replies

 

AccessWorkorSchool.jpgIn the Settings menu --> Accounts choose the Access Work or School and choose the connect, make sure you choose the option to join Azure AD, then from the Accounts --> Other Users Add other users and add the Azure AD account you want to login as a Standard or Administrator.  This will allow the user to then login.  At the login prompt use the Azure AD email address (UPN) to login.  It will create a new profile for you.

Thanks, Murray.   And once I do this, will that then give me the prompt after the next reboot to enter my Office 365 email address, and not just a username, to log onto the Surface Pro and that will take me into my "Azure AD" specific profile on the device?

Yes it will - Be sure you login with the account you specified when you joined to the device to Azure AD - or added any other accounts to the machine that you want logging in.  I use this on a good number of my devices.

@Murray WallI also followed the same steps and entered office email address which is my UPN as an user and it didnt accept it saying its not a microsoft account, I tried all other available option none of them worked.

Hi @navn1620

 

I had the same issue, you should add the account again in the work or school account panel, and be sure to select the Azure AD option. It should all work fine then. Hope this helps! 

 

EDIT:

After doing the step above you can log out of your current account en then select the option to sign in with a different account, just sign in with the credentials of the user and it should work.

Hello, and how it works in offline mode. I couldn't login to the computer without internet connection... So in that case we will use Office 365 Azure AD account we will not be able to work in that profile without internet, in offline mode? Or how to set up to be able?

Thanks

You should be able to login to a computer you have previously been authenticated on, on a new machine, you must be connected to M365 to authenticate. You canalso have a hybrid joined machine or use a hardware token or passwordless auth that has something stored in the local TPM that is trusted as a long term solution. Also know that you need to be online at some point in time to be able to renew and actually use the SaaS....