Question: Script to see if device is Azure AD joined

%3CLINGO-SUB%20id%3D%22lingo-sub-3486418%22%20slang%3D%22en-US%22%3EQuestion%3A%20Script%20to%20see%20if%20device%20is%20Azure%20AD%20joined%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3486418%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20often%20receive%20notebooks%20that%20are%20still%20joined%20to%20a%20Azure%20AD%20tenant.%20Is%20there%20a%20(simple)%20Powershell%20script%20that%20shows%20if%20a%20device%20is%20still%20joined%20to%20a%20tenant%3F%20Knowing%20which%20exact%20tenant%20the%20device%20is%20registered%20to%20is%20a%20nice-to-have%20but%20not%20required.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFYI%2C%20we%20already%20tried%20the%20cmd%20command%20'dsregcmd'%20but%20unfortunately%20the%20output%20was%20not%20reliable.%20We%20found%20multiple%20occasions%20where%20dsregcmd%20claimed%20the%20device%20was%20not%20Azure%20AD%20joined%20while%20it%20definitely%20was.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3486418%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Active%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Intune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3492490%22%20slang%3D%22en-US%22%3ERe%3A%20Question%3A%20Script%20to%20see%20if%20device%20is%20Azure%20AD%20joined%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3492490%22%20slang%3D%22en-US%22%3E%24subKey%20%3D%20Get-Item%20%22HKLM%3A%2FSYSTEM%2FCurrentControlSet%2FControl%2FCloudDomainJoin%2FJoinInfo%22%3CBR%20%2F%3E%3CBR%20%2F%3E%24guids%20%3D%20%24subKey.GetSubKeyNames()%3CBR%20%2F%3Eforeach(%24guid%20in%20%24guids)%20%7B%3CBR%20%2F%3E%24guidSubKey%20%3D%20%24subKey.OpenSubKey(%24guid)%3B%3CBR%20%2F%3E%24tenantId%20%3D%20%24guidSubKey.GetValue(%22TenantId%22)%3B%3CBR%20%2F%3E%24userEmail%20%3D%20%24guidSubKey.GetValue(%22UserEmail%22)%3B%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%3CBR%20%2F%3Ewrite-host%20%24tenantId%20%24userEmail%3CBR%20%2F%3E%3CBR%20%2F%3E(Got%20this%20from%20%3CA%20href%3D%22https%3A%2F%2Fnerdymishka.com%2Farticles%2Fazure-ad-domain-join-registry-keys%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fnerdymishka.com%2Farticles%2Fazure-ad-domain-join-registry-keys%2F%3C%2FA%3E%20%2C%20it%20works%20for%20me%20and%20shows%20me%20the%20tenantid%20and%20the%20account%20which%20was%20used%20for%20joining)%3C%2FLINGO-BODY%3E
Occasional Contributor

We often receive notebooks that are still joined to a Azure AD tenant. Is there a (simple) Powershell script that shows if a device is still joined to a tenant? Knowing which exact tenant the device is registered to is a nice-to-have but not required. 

 

FYI, we already tried the cmd command 'dsregcmd' but unfortunately the output was not reliable. We found multiple occasions where dsregcmd claimed the device was not Azure AD joined while it definitely was.

2 Replies
$subKey = Get-Item "HKLM:/SYSTEM/CurrentControlSet/Control/CloudDomainJoin/JoinInfo"

$guids = $subKey.GetSubKeyNames()
foreach($guid in $guids) {
$guidSubKey = $subKey.OpenSubKey($guid);
$tenantId = $guidSubKey.GetValue("TenantId");
$userEmail = $guidSubKey.GetValue("UserEmail");
}

write-host $tenantId $userEmail

(Got this from https://nerdymishka.com/articles/azure-ad-domain-join-registry-keys/ , it works for me and shows me the tenantid and the account which was used for joining)
Did this answer your question?