You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Azure AD provides you with a central place to manage device identities.
20
+
Azure AD provides you with a central place to manage device identities and monitor related event information.
21
21
22
-
The **All devices** page enables you to:
22
+
[](./media/device-management-azure-portal/devices-azure-portal.png#lightbox)
23
+
24
+
You can access the devices overview using the following steps:
25
+
26
+
1. Sign in to the [Azure portal](https://portal.azure.com).
27
+
1. Browse to **Azure Active Directory** > **Devices**.
28
+
29
+
From the devices overview you can find the total device number, stale devices, noncompliant devices, and unmanaged devices. You can also quickly access links to Intune, Conditional Access, BitLocker keys, and basic monitoring.
30
+
31
+
Device counts on the overview page don't update in real-time, changes should be reflected every few hours.
32
+
33
+
From there you can go to **All devices** to:
23
34
24
35
- Identify devices, including:
25
36
- Devices that have been joined or registered in Azure AD.
26
37
- Devices deployed using [Windows Autopilot](/windows/deployment/windows-autopilot/windows-autopilot).
27
38
- Printers using [Universal Print](/universal-print/fundamentals/universal-print-getting-started)
28
-
-Perform device identity management tasks like enable, disable, delete, or manage.
39
+
-Complete device identity management tasks like enable, disable, delete, or manage.
29
40
-[Printers](/universal-print/fundamentals/) and [Windows Autopilot](/windows/deployment/windows-autopilot/windows-autopilot) devices have limited management options in Azure AD. They must be managed from their respective admin interfaces.
30
41
- Configure your device identity settings.
31
42
- Enable or disable Enterprise State Roaming.
@@ -34,42 +45,16 @@ The **All devices** page enables you to:
34
45
35
46
[](./media/device-management-azure-portal/all-devices-azure-portal.png#lightbox)
36
47
37
-
You can access the devices portal using the following steps:
38
-
39
-
1. Sign in to the [Azure portal](https://portal.azure.com).
40
-
1. Browse to **Azure Active Directory** > **Devices**.
41
-
42
-
## Manage devices
43
-
44
-
There are two locations to manage devices in Azure AD:
45
-
46
-
-**Azure portal** > **Azure Active Directory** > **Devices**
47
-
-**Azure portal** > **Azure Active Directory** > **Users** > Select a user > **Devices**
-[Printers](/universal-print/fundamentals/) and [Windows Autopilot](/windows/deployment/windows-autopilot/windows-autopilot) devices have limited management options in Azure AD. They must be managed from their respective admin interfaces.
62
-
63
48
> [!TIP]
64
49
> - Hybrid Azure AD Joined Windows 10 devices do not have an owner. If you are looking for a device by owner and didn't find it, search by the device ID.
65
50
>
66
-
> - If you see a device that is "Hybrid Azure AD joined" with a state "Pending" under the REGISTERED column, it indicates that the device has been synchronized from Azure AD connect and is waiting to complete registration from the client. Read more on how to [plan your Hybrid Azure AD join implementation](hybrid-azuread-join-plan.md). Additional information can be found in the article, [Devices frequently asked questions](faq.yml).
51
+
> - If you see a device that is "Hybrid Azure AD joined" with a state "Pending" under the **Registered** column, it indicates that the device has been synchronized from Azure AD connect and is waiting to complete registration from the client. Read more on how to [plan your Hybrid Azure AD join implementation](hybrid-azuread-join-plan.md). Additional information can be found in the article, [Devices frequently asked questions](faq.yml).
67
52
>
68
53
> - For some iOS devices, the device names containing apostrophes can potentially use different characters that look like apostrophes. So searching for such devices is a little tricky - if you are not seeing search results correctly, ensure that the search string contains matching apostrophe character.
69
54
70
55
### Manage an Intune device
71
56
72
-
If you are an Intune administrator, you can manage devices where MDM is marked **Microsoft Intune**. If the device is not enrolled with Microsoft Intune, the "Manage" option will be greyed out.
57
+
If you have rights to manage devices in Intune, you can manage devices where Mobile Device Management is marked **Microsoft Intune**. If the device isn't enrolled with Microsoft Intune, the "Manage" option will be greyed out.
73
58
74
59
### Enable or disable an Azure AD device
75
60
@@ -99,11 +84,11 @@ To delete a device, you have two options:
99
84
> - Removes all details that are attached to the device, for example, BitLocker keys for Windows devices.
100
85
> - Represents a non-recoverable activity and is not recommended unless it is required.
101
86
102
-
If a device is managed by another management authority (for example, Microsoft Intune), make sure that the device has been wiped / retired before deleting the device in Azure AD. Review how to [manage stale devices](manage-stale-devices.md) before deleting any devices.
87
+
If a device is managed by another management authority, like Microsoft Intune, make sure that the device has been wiped or retired before you delete the device. Review how to [manage stale devices](manage-stale-devices.md) before deleting any devices.
103
88
104
89
### View or copy device ID
105
90
106
-
You can use a device ID to verify the device ID details on the device or using PowerShell during troubleshooting. To access the copy option, click the device.
91
+
You can use a device ID to verify the device ID details on the device or using PowerShell during troubleshooting. To access the copy option, select the device.
107
92
108
93

109
94
@@ -113,7 +98,7 @@ You can view and copy the BitLocker keys to allow users to recover encrypted dri
To view or copy the BitLocker keys, you need to be either the owner of the device, or a user that has at least one of the following roles assigned:
101
+
To view or copy the BitLocker keys, you need to be the owner of the device, or have one of the following roles:
117
102
118
103
- Cloud Device Administrator
119
104
- Global Administrator
@@ -141,11 +126,11 @@ To enable the preview filtering functionality in the **All devices** view:
141
126
1. Browse to **Azure Active Directory** > **Devices**.
142
127
1. Select the banner that says, **Try out the new devices filtering improvements. Click to enable the preview.**
143
128
144
-
You will now have the ability to**Add filters** to your **All devices** view.
129
+
You can now **Add filters** to your **All devices** view.
145
130
146
131
### Download devices (preview)
147
132
148
-
Cloud device administrators, Intune administrators, and Global administrators can use the **Download devices (preview)** option to export a CSV file of devices based on any applied filters. If no filters are applied to the list then all devices will be exported. An export may run for a period of up to one hour depending on the
133
+
Cloud device administrators, Intune administrators, and Global administrators can use the **Download devices (preview)** option to export a CSV file of devices based on any applied filters. If no filters are applied to the list, all devices will be exported. An export task may run for up to one hour depending on the selections.
149
134
150
135
The exported list includes the following device identity attributes:
151
136
@@ -181,7 +166,7 @@ This option is a premium edition capability available through products such as A
181
166
> - We recommend using ["Register or join devices" user action](../conditional-access/concept-conditional-access-cloud-apps.md#user-actions) in Conditional Access for enforcing multi-factor authentication for joining or registering a device.
182
167
> - You must set this setting to **No** if you are using Conditional Access policy to require multi-factor authencation.
183
168
184
-
-**Maximum number of devices** - This setting enables you to select the maximum number of Azure AD joined or Azure AD registered devices that a user can have in Azure AD. If a user reaches this quota, they are not be able to add additional devices until one or more of the existing devices are removed. The default value is **50**. You can increase the value up to 100 and if you enter a value above 100, Azure AD will set it to 100. You can also use Unlimited value to enforce no limit other than existing quota limits.
169
+
-**Maximum number of devices** - This setting enables you to select the maximum number of Azure AD joined or Azure AD registered devices that a user can have in Azure AD. If a user reaches this quota, they can't add more devices until one or more of the existing devices are removed. The default value is **50**. You can increase the value up to 100 and if you enter a value above 100, Azure AD will set it to 100. You can also use Unlimited value to enforce no limit other than existing quota limits.
185
170
186
171
> [!NOTE]
187
172
> **Maximum number of devices** setting applies to devices that are either Azure AD joined or Azure AD registered. This setting does not apply to hybrid Azure AD joined devices.
@@ -220,12 +205,11 @@ To narrow down the reported data to a level that works for you, you can filter t
220
205
- Target
221
206
- Initiated By (Actor)
222
207
223
-
In addition to the filters, you can search for specific entries.
208
+
You can also search for specific entries.
224
209
225
210
:::image type="content" source="./media/device-management-azure-portal/65.png" alt-text="Screenshot of audit data filter controls, with category, activity resource type, activity, date range, target, and actor fields and a search field." border="false":::
226
211
227
212
## Next steps
228
213
229
-
[How to manage stale devices in Azure AD](manage-stale-devices.md)
230
-
231
-
[Enterprise State Roaming](enterprise-state-roaming-overview.md)
214
+
-[How to manage stale devices in Azure AD](manage-stale-devices.md)
Copy file name to clipboardExpand all lines: articles/active-directory/devices/hybrid-azuread-join-manual.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -566,7 +566,7 @@ Here are 3 ways to locate and verify the device state:
566
566
### Using the Azure portal
567
567
568
568
1. Go to the devices page using a [direct link](https://portal.azure.com/#blade/Microsoft_AAD_IAM/DevicesMenuBlade/Devices).
569
-
2. Information on how to locate a device can be found in [How to manage device identities using the Azure portal](./device-management-azure-portal.md#manage-devices).
569
+
2. Information on how to locate a device can be found in [Manage device identities using the Azure portal](./device-management-azure-portal.md).
570
570
3. If the **Registered** column says **Pending**, then Hybrid Azure AD Join has not completed. In federated environments, this can happen only if it failed to register and AAD connect is configured to sync the devices.
571
571
4. If the **Registered** column contains a **date/time**, then Hybrid Azure AD Join has completed.
0 commit comments