Skip to content

Commit de119b3

Browse files
authored
Merge pull request #48497 from MarkusVi/quickfix32
quickfix32
2 parents 7938746 + 8f08089 commit de119b3

5 files changed

+20
-85
lines changed

articles/active-directory/active-directory-device-registration-on-premises-setup.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ There are many different ways to communicate this URL to your users. For example
160160
### Join a Windows 7 device by using Azure Active Directory device registration
161161
To register Windows 7 domain-joined devices, you need to deploy the [device registration software package](https://www.microsoft.com/download/details.aspx?id=53554).
162162

163-
For instructions about how to use the package, see [Windows Installer packages for non-Windows 10 computers](devices/hybrid-azuread-join-manual-steps.md#windows-installer-packages-for-non-windows-10-computers).
163+
For instructions about how to use the package, see [Windows Installer packages for non-Windows 10 computers](devices/hybrid-azuread-join-control.md#control-windows-down-level-devices).
164164

165165
## Verify that registered devices are written back to Active Directory
166166
You can view and verify that your device objects have been written back to your Active Directory by using LDP.exe or ADSI Edit. Both are available with the Active Directory administrator tools.

articles/active-directory/devices/hybrid-azuread-join-federated-domains.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,7 @@ This tutorial assumes that you are familiar with:
4646

4747
- [How to plan your hybrid Azure Active Directory join implementation](hybrid-azuread-join-plan.md)
4848

49+
- [How to control the hybrid Azure AD join of your devices](hybrid-azuread-join-control.md)
4950

5051

5152
To configure the scenario in this tutorial, you need:

articles/active-directory/devices/hybrid-azuread-join-managed-domains.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,9 @@ This tutorial assumes that you are familiar with:
4646

4747
- [How to plan your hybrid Azure Active Directory join implementation](hybrid-azuread-join-plan.md)
4848

49+
- [How to control the hybrid Azure AD join of your devices](hybrid-azuread-join-control.md)
50+
51+
4952
To configure the scenario in this article, you need the [latest version of Azure AD Connect](https://www.microsoft.com/download/details.aspx?id=47594) (1.1.819.0 or higher) to be installed.
5053

5154

articles/active-directory/devices/hybrid-azuread-join-manual-steps.md

Lines changed: 8 additions & 84 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.workload: identity
1414
ms.tgt_pltfrm: na
1515
ms.devlang: na
1616
ms.topic: article
17-
ms.date: 08/02/2018
17+
ms.date: 08/08/2018
1818
ms.author: markvi
1919
ms.reviewer: sandeo
2020

@@ -31,40 +31,18 @@ If you have an on-premises Active Directory environment and you want to join you
3131
> If using Azure AD Connect is an option for you, see [Select your scenario](hybrid-azuread-join-plan.md#select-your-scenario). By using Azure AD Connect, you can simplify the configuration of hybrid Azure AD join significantly.
3232
3333

34-
## Before you begin
3534

36-
Before you start configuring hybrid Azure AD joined devices in your environment, you should familiarize yourself with the supported scenarios and the constraints.
3735

38-
If you are relying on the [System Preparation Tool (Sysprep)](https://docs.microsoft.com/previous-versions/windows/it-pro/windows-vista/cc721940(v=ws.10)), please make sure you create images from an installation of Windows that has not been yet registered with Azure AD.
39-
40-
All domain-joined devices running Windows 10 Anniversary Update and Windows Server 2016 automatically register with Azure AD at device restart or user sign-in once the configuration steps mentioned below are complete. **If this automatic register behavior is not preferred or if a controlled rollout is desired**, please follow instructions in the "Step 4: Control Deployment and Rollout" section below first to selectively enable or disable automatic rollout before following the other configuration steps.
41-
42-
To improve the readability of the descriptions, this article uses the following term:
43-
44-
- **Windows current devices** - This term refers to domain-joined devices running Windows 10 or Windows Server 2016.
45-
- **Windows down-level devices** - This term refers to all **supported** domain-joined Windows devices that are neither running Windows 10 nor Windows Server 2016.
46-
47-
### Windows current devices
48-
49-
- For devices running the Windows desktop operating system, the supported version is the Windows 10 Anniversary Update (version 1607) or later.
50-
- The registration of Windows current devices **is** supported in non-federated environments such as password hash sync configurations.
51-
52-
53-
### Windows down-level devices
54-
55-
- The following Windows down-level devices are supported:
56-
- Windows 8.1
57-
- Windows 7
58-
- Windows Server 2012 R2
59-
- Windows Server 2012
60-
- Windows Server 2008 R2
61-
- The registration of Windows down-level devices **is** supported in non-federated environments through Seamless Single Sign On [Azure Active Directory Seamless Single Sign-On](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start).
62-
- The registration of Windows down-level devices **is not** supported when using Azure AD Pass-through Authentication without Seamless Single Sign On.
63-
- The registration of Windows down-level devices **is not** supported for devices using roaming profiles. If you are relying on roaming of profiles or settings, use Windows 10.
36+
## Prerequisites
6437

38+
This tutorial assumes that you are familiar with:
39+
40+
- [Introduction to device management in Azure Active Directory](../device-management-introduction.md)
41+
42+
- [How to plan your hybrid Azure Active Directory join implementation](hybrid-azuread-join-plan.md)
6543

44+
- [How to control the hybrid Azure AD join of your devices](hybrid-azuread-join-control.md)
6645

67-
## Prerequisites
6846

6947
Before you start enabling hybrid Azure AD joined devices in your organization, you need to make sure that:
7048

@@ -114,7 +92,6 @@ Use the following table to get an overview of the steps that are required for yo
11492
| Configure service connection point | ![Check][1] | ![Check][1] | ![Check][1] |
11593
| Setup issuance of claims | | ![Check][1] | ![Check][1] |
11694
| Enable non-Windows 10 devices | | | ![Check][1] |
117-
| Control deployment and rollout | ![Check][1] | ![Check][1] | ![Check][1] |
11895
| Verify joined devices | ![Check][1] | ![Check][1] | ![Check][1] |
11996

12097

@@ -559,59 +536,6 @@ To avoid certificate prompts when users in register devices authenticate to Azur
559536

560537
`https://device.login.microsoftonline.com`
561538

562-
## Control deployment and rollout
563-
564-
When you have completed the required steps, domain-joined devices are ready to automatically join Azure AD:
565-
566-
- All domain-joined devices running Windows 10 Anniversary Update and Windows Server 2016 automatically register with Azure AD at device restart or user sign-in.
567-
568-
- New devices register with Azure AD when the device restarts after the domain join operation is completed.
569-
570-
- Devices that were previously Azure AD registered (for example, for Intune) transition to “*Domain Joined, AAD Registered*”; however it takes some time for this process to complete across all devices due to the normal flow of domain and user activity.
571-
572-
### Remarks
573-
574-
- You can use a Group Policy object or System Center Configuration Manager client setting to control the rollout of automatic registration of Windows 10 and Windows Server 2016 domain-joined computers. **If you do not want these devices to automatically register with Azure AD or you want to control the registration**, then you must roll out group policy disabling the automatic registration to all these devices first or if you are using Configuration Manager you must configure the client setting under Cloud Services > Automatically register new Windows 10 domain joined devices with Azure Active Directory to "No", before starting with any of the configuration steps.
575-
576-
> [!Important]
577-
> Since there is a potential delay in the application of the group policy object on newly domain joined computers during which automatic registration attempt of Windows 10 devices can occur, you must create a new sysprep image from a Windows 10 device that was never previously automatically registered, and that already has GPO to disable the automatic registration of Windows 10 devices and use that sysprep image to provision the new computers that will join your organization's domain.
578-
579-
After you are done configuring, and when you are ready to test, you must roll out group policy enabling the automatic registration only to the test devices and then to all other devices as you choose.
580-
581-
- To rollout of Windows down-level computers, you can deploy a [Windows Installer package](#windows-installer-packages-for-non-windows-10-computers) to computers that you select.
582-
583-
- If you push the Group Policy object to Windows 8.1 domain-joined devices, a join is attempted; however it is recommended that you use the [Windows Installer package](#windows-installer-packages-for-non-windows-10-computers) to join all your Windows down-level devices.
584-
585-
### Create a Group Policy object
586-
587-
To control the rollout of Windows current computers, you should deploy the **Register domain-joined computers as devices** Group Policy object to the devices you want to register. For example, you can deploy the policy to an organizational unit or to a security group.
588-
589-
**To set the policy:**
590-
591-
1. Open **Server Manager**, and then go to `Tools > Group Policy Management`.
592-
2. Go to the domain node that corresponds to the domain where you want to activate auto-registration of Windows current computers.
593-
3. Right-click **Group Policy Objects**, and then select **New**.
594-
4. Type a name for your Group Policy object. For example, *Hybrid Azure AD join.
595-
5. Click **OK**.
596-
6. Right-click your new Group Policy object, and then select **Edit**.
597-
7. Go to **Computer Configuration** > **Policies** > **Administrative Templates** > **Windows Components** > **Device Registration**.
598-
8. Right-click **Register domain-joined computers as devices**, and then select **Edit**.
599-
600-
> [!NOTE]
601-
> This Group Policy template has been renamed from earlier versions of the Group Policy Management console. If you are using an earlier version of the console, go to `Computer Configuration > Policies > Administrative Templates > Windows Components > Workplace Join > Automatically workplace join client computers`.
602-
603-
7. Select **Enabled**, and then click **Apply**. You must select **Disabled** if you want the policy to block the devices controlled by this group policy from automatically registering with Azure AD.
604-
605-
8. Click **OK**.
606-
9. Link the Group Policy object to a location of your choice. For example, you can link it to a specific organizational unit. You also could link it to a specific security group of computers that automatically join with Azure AD. To set this policy for all domain-joined Windows 10 and Windows Server 2016 computers in your organization, link the Group Policy object to the domain.
607-
608-
### Windows Installer packages for non-Windows 10 computers
609-
610-
To join domain-joined Windows down-level computers in a federated environment, you can download and install these Windows Installer package (.msi) from Download Center at the [Microsoft Workplace Join for non-Windows 10 computers](https://www.microsoft.com/en-us/download/details.aspx?id=53554) page.
611-
612-
You can deploy the package by using a software distribution system like System Center Configuration Manager. The package supports the standard silent install options with the *quiet* parameter. System Center Configuration Manager Current Branch offers additional benefits from earlier versions, like the ability to track completed registrations. For more information, see [System Center Configuration Manager](https://www.microsoft.com/cloud-platform/system-center-configuration-manager).
613-
614-
The installer creates a scheduled task on the system that runs in the user’s context. The task is triggered when the user signs in to Windows. The task silently joins the device with Azure AD with the user credentials after authenticating using Integrated Windows Authentication. To see the scheduled task, in the device, go to **Microsoft** > **Workplace Join**, and then go to the Task Scheduler library.
615539

616540
## Verify joined devices
617541

articles/active-directory/devices/hybrid-azuread-join-plan.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,13 @@ If you are relying on a Virtual Machine (VM) snapshot to create additional VMs,
9393

9494
The registration of Windows down-level devices is not supported for devices configured for user profile roaming or credential roaming. If you are relying on roaming of profiles or settings, use Windows 10.
9595

96+
- The registration of Windows down-level devices **is** supported in non-federated environments through Seamless Single Sign On [Azure Active Directory Seamless Single Sign-On](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start).
97+
98+
- The registration of Windows down-level devices **is not** supported when using Azure AD Pass-through Authentication without Seamless Single Sign On.
99+
100+
- The registration of Windows down-level devices **is not** supported for devices using roaming profiles. If you are relying on roaming of profiles or settings, use Windows 10.
101+
102+
96103
The registration of Windows Server running the Domain Controller (DC) role is not supported.
97104

98105
If your organization requires access to the Internet via an authenticated outbound proxy, you must make sure that your Windows 10 computers can successfully authenticate to the outbound proxy. Because Windows 10 computers run device registration using machine context, it is necessary to configure outbound proxy authentication using machine context.

0 commit comments

Comments
 (0)