Office 365 / Azure AD Join, device registration (byod; devices…)

Introduction to device management in Azure Active Directory:

https://docs.microsoft.com/fr-fr/azure/active-directory/devices/overview

https://docs.microsoft.com/en-us/azure/active-directory/device-management-introduction#getting-devices-under-the-control-of-azure-ad

As a rule of a thumb, you should use:

  • Azure AD registered devices:
    • For personal devices
    • To manually register devices with Azure AD
  • Azure AD joined devices:
    • For devices that are owned by your organization
    • For devices that are not joined to an on-premises AD
    • To manually register devices with Azure AD
    • To change the local state of a device
  • Hybrid Azure AD joined devices for devices that are joined to an on-premises AD
    • For devices that are owned by your organization
    • For devices that are joined to an on-premises AD
    • To automatically register devices with Azure AD
    • To change the local state of a device

How to Setup: https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan

c

Azure AD registered devices:

https://docs.microsoft.com/en-us/azure/active-directory/device-management-introduction#azure-ad-registered-devices

Hybrid Azure AD joined devices:

https://docs.microsoft.com/en-us/azure/active-directory/device-management-introduction#hybrid-azure-ad-joined-devices

To configure Hybrid Azure AD joined devices, kindly visit the link:

https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-manual-steps

Azure AD joined devices:

https://docs.microsoft.com/en-us/azure/active-directory/device-management-introduction#azure-ad-joined-devices

Azure AD Join vs Azure AD Device Registration:

https://blogs.technet.microsoft.com/trejo/2016/04/09/azure-ad-join-vs-azure-ad-device-registration/

Manage devices:

https://docs.microsoft.com/en-us/azure/active-directory/device-management-azure-portal#manage-devices

Device management tasks:

https://docs.microsoft.com/en-us/azure/active-directory/device-management-azure-portal#device-management-tasks

Configure On-Premises Conditional Access using registered devices:

https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-device-based-conditional-access-on-premises

Very interesting article about BYOD and impact with different options and CAPs

Securing BYOD – The different options when signing in to M365 Apps

Published by jdalbera

IT Pro: 28 years experience for large companies - Technical manager and solution architect: Directory services and Identity Managemen expert, Azure AD, Office 365, Azure infrastructures, Microsoft AD Security (ADDS,ADFS,ADCS), PowerShell, Quest solutions architect. Operating systems (Win/Lin). Unix and Microsoft interoperability. Data center Operations. Company integrations. Network architectures. Virtualization and storage infrastructures. HP/Dell servers deployments. Multiple certifications: Azure, MCSE, MCPs, MCITS, ITIL, VCP, CCNA, CyberArk