Windows 10 Deployment on Azure Active Directory & Supporting Users

%3CLINGO-SUB%20id%3D%22lingo-sub-90027%22%20slang%3D%22en-US%22%3EWindows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90027%22%20slang%3D%22en-US%22%3E%3CP%3EHalf%20of%20my%20users%20are%20joined%20to%20my%20local%20domain%2C%20and%20the%20other%20half%20(who%20don't%20come%20in%20the%20office)%20I've%20joined%20to%20Azure%20Active%20directory%20instead.%26nbsp%3B%20I%20would%20like%20to%20eliminate%20the%20local%20AD%20completely%20if%20possible%20for%20PCs%20(not%20servers).%26nbsp%3B%20I%20have%20a%20series%20of%20questions%20related%20to%20this%20senario.%26nbsp%3B%20Also%2C%20if%20there%20is%20a%20document%20that%20provides%20a%20summary%20overview%20of%20how%20to%20accomplish%20the%20items%20below%2C%20please%20send%20me%20a%20link.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EIs%20okay%20to%20join%20a%20new%20Windows%2010%20machine%20to%20Azure%20AD%20with%20an%20Azure%20admin%20account%20and%20have%20that%20account%20be%20the%20local%20machine's%20admin%3F%26nbsp%3B%20I%20want%20to%20eliminate%20a%20PC's%20local%20admin%20altogether%20if%20possible%2C%20and%20then%20only%20use%20and%20Azure%20admin%20for%20the%20local%20account.%20%26nbsp%3B%20Also%2C%20anyone%20who%20might%20be%20an%20Azure%20AD%20admin%20could%20login%20to%20the%20machine%20could%20act%20as%20admin%20on%20the%20machine%2C%20even%20if%20the%20first%20Azure%20admin%20on%20that%20machine%20was%20no%20longer%20active.%26nbsp%3B%20Is%20all%20of%20the%20above%20correct%3F%20%26nbsp%3B%3C%2FLI%3E%3CLI%3EWhat%20is%20the%20difference%20between%20InTune%20and%20Premium%20AD%3F%26nbsp%3B%20Which%20is%20best%20for%20supporting%20my%20users%20if%20I%20am%20no%20longer%20using%20a%20local%20AD%3F%26nbsp%3B%20I%20unclear%20on%20which%20of%20these%20products%20would%20be%20best.%3C%2FLI%3E%3CLI%3EDoes%20Microsoft%20offer%20a%20product%20like%20Logmein%20that%20allows%20me%20to%20support%20end-users%20and%20remote%20control%20their%20machines%3F%26nbsp%3B%3C%2FLI%3E%3C%2FOL%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-95234%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-95234%22%20slang%3D%22en-US%22%3E%3CP%3EMore%20info%20on%20Windows%20Autopilot..%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-%3C%2FA%3E%20us%2Fwindows%2Fdeployment%2Fwindows-10-auto-pilot%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-90159%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90159%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20have%20a%20link%20for%20more%20info%20on%20Autopilot%2C%20I'll%20take%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20answers%2C%20and%20have%20a%20great%20day!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-90139%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90139%22%20slang%3D%22en-US%22%3E%3CP%3EYes%2C%20you%20are%20right%20on%20all%20counts.%3C%2FP%3E%0A%3CP%3E1.%20First%20user%20will%20be%20an%20admin%20without%20Autopilot%3C%2FP%3E%0A%3CP%3E2.%20any%20Azure%20AD%20admin%20can%20logon%20and%20be%20an%20admin%26nbsp%3B%3C%2FP%3E%0A%3CP%3E3.%20Any%20AAD%20user%20can%20login%20to%20the%20machien%20but%20will%20not%20be%20an%20admin%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-90105%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90105%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Janani%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOkay%2C%20great.%26nbsp%3B%20I%20just%20want%20to%20confirm%20a%20specific%20point%20pertaining%20to%20item%20%231%20in%20my%20previous%20message.%26nbsp%3B%20If%20I%20take%20a%20new%20Windows%2010%20device%20and%20select%20the%20option%20%22the%20PC%20belongs%20to%20my%20organization%2C%22%20and%20log%20into%20that%20machine%20for%20the%20first%20time%20with%20my%20Azure%20AD%20admin%20account%2C%20am%20I%20now%20the%20local%20admin%20on%20that%20machine%3F%26nbsp%3B%20Also%2C%20can%20any%20other%20Azure%20AD%20admin%20log%20into%20that%20machine%20and%20be%20the%20admin%3F%26nbsp%3B%20And%2C%20finally%2C%20any%20other%20user%20who%20is%20on%20the%20domain%20will%20now%20be%20able%20to%20login%20to%20the%20machine%2C%20but%20they%20won't%20be%20an%20admin%2C%20correct%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EThomas%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-90089%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90089%22%20slang%3D%22en-US%22%3E%3CP%3EHere%20are%20Microsoft%20Intune's%20remote%20assistance%20solutions%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune-classic%2Fdeploy-use%2Frequest-and-provide-remote-assistance-for-windows-pcs-in-microsoft-intune%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune-classic%2Fdeploy-use%2Frequest-and-provide-remote-assistance-for-windows-pcs-in-microsoft-intune%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-90048%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Deployment%20on%20Azure%20Active%20Directory%20%26amp%3B%20Supporting%20Users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90048%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Thomas%2C%20Great%20to%20hear%20that%20you%20are%20joining%20some%20of%20your%20devices%20to%20Azure%20AD.%20Answers%20to%20your%20questions%20below%3A%3C%2FP%3E%3CP%3E1.%20Yes%2C%20what%20you%20say%20is%20possible.%20However%2C%20you%20can%20use%20Windows%2010%20Autopilot%20to%20AAD%20join%20your%20devices%20and%20also%20designate%20that%20the%20first%20user%20should%20be%20a%20standard%20user.%20So%20you%20can%20now%20make%20sure%20the%20user%20is%20a%20std%20user.%20You%20are%20right%20that%20all%20AAD%20tenant%20admins%20are%20added%20as%20local%20admins%20to%20the%20PC.%20But%20this%20is%20a%20configurable%20setting%20in%20Azure%20AD.%20you%20could%20change%20the%20users%20that%20are%20added%20as%20admins.%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Intune%20is%20the%20management%20tool%20from%20Microsoft%20that%20uses%20MDM%20to%20manage%20devices%20from%20the%20cloud.%20Azure%20AD%20premium%20is%20the%20premium%20version%20of%20the%20Microsoft%20identity%20offering.%20Intune%20depends%20on%20Azure%20AD%20for%20identity.%20So%20think%20of%20Azure%20AD%20as%20the%20identity%20plane%20on%20which%20Intune%20is%20built%20on.%20You%20will%20need%20Azure%20AD%20premium%20if%20you%20would%20like%20to%20auto%20enroll%20into%20Intune%20as%20part%20of%20AAD%20join%20and%20use%20Autopilot%3C%2FP%3E%3CP%3E3.%20Microsoft%20doesnt%20yet%20have%20a%20product%20exactly%20for%20this%20E2E%20but%20Remote%20desktop%20and%20Skype%20are%20tools%20that%20many%20of%20our%20customers%20use.%20Also%20SCCM%20has%20remote%20control%20support%20and%20we%20are%20working%20with%20many%20ISVs%20by%20providing%20the%20right%20APIs%20to%20help%20them%20build%20a%20remote%20assistance%20tool.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFeel%20free%20to%20post%20back%20a%20clarification%20or%20question%20if%20there%20are%20further%20qeuestions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EJanani%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Half of my users are joined to my local domain, and the other half (who don't come in the office) I've joined to Azure Active directory instead.  I would like to eliminate the local AD completely if possible for PCs (not servers).  I have a series of questions related to this senario.  Also, if there is a document that provides a summary overview of how to accomplish the items below, please send me a link.  

 

  1. Is okay to join a new Windows 10 machine to Azure AD with an Azure admin account and have that account be the local machine's admin?  I want to eliminate a PC's local admin altogether if possible, and then only use and Azure admin for the local account.   Also, anyone who might be an Azure AD admin could login to the machine could act as admin on the machine, even if the first Azure admin on that machine was no longer active.  Is all of the above correct?  
  2. What is the difference between InTune and Premium AD?  Which is best for supporting my users if I am no longer using a local AD?  I unclear on which of these products would be best.
  3. Does Microsoft offer a product like Logmein that allows me to support end-users and remote control their machines? 
6 Replies

Hi Thomas, Great to hear that you are joining some of your devices to Azure AD. Answers to your questions below:

1. Yes, what you say is possible. However, you can use Windows 10 Autopilot to AAD join your devices and also designate that the first user should be a standard user. So you can now make sure the user is a std user. You are right that all AAD tenant admins are added as local admins to the PC. But this is a configurable setting in Azure AD. you could change the users that are added as admins. 

2. Intune is the management tool from Microsoft that uses MDM to manage devices from the cloud. Azure AD premium is the premium version of the Microsoft identity offering. Intune depends on Azure AD for identity. So think of Azure AD as the identity plane on which Intune is built on. You will need Azure AD premium if you would like to auto enroll into Intune as part of AAD join and use Autopilot

3. Microsoft doesnt yet have a product exactly for this E2E but Remote desktop and Skype are tools that many of our customers use. Also SCCM has remote control support and we are working with many ISVs by providing the right APIs to help them build a remote assistance tool.

 

Feel free to post back a clarification or question if there are further qeuestions.

 

Thanks,

Janani

Hi Janani,

 

Okay, great.  I just want to confirm a specific point pertaining to item #1 in my previous message.  If I take a new Windows 10 device and select the option "the PC belongs to my organization," and log into that machine for the first time with my Azure AD admin account, am I now the local admin on that machine?  Also, can any other Azure AD admin log into that machine and be the admin?  And, finally, any other user who is on the domain will now be able to login to the machine, but they won't be an admin, correct?

 

Thanks,

Thomas

Yes, you are right on all counts.

1. First user will be an admin without Autopilot

2. any Azure AD admin can logon and be an admin 

3. Any AAD user can login to the machien but will not be an admin

 

Thanks!

If you have a link for more info on Autopilot, I'll take it.

 

Thanks for the answers, and have a great day!

More info on Windows Autopilot..

https://docs.microsoft.com/en- us/windows/deployment/windows-10-auto-pilot