You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/active-directory-device-registration-on-premises-setup.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -160,7 +160,7 @@ There are many different ways to communicate this URL to your users. For example
160
160
### Join a Windows 7 device by using Azure Active Directory device registration
161
161
To register Windows 7 domain-joined devices, you need to deploy the [device registration software package](https://www.microsoft.com/download/details.aspx?id=53554).
162
162
163
-
For instructions about how to use the package, see [Windows Installer packages for non-Windows 10 computers](devices/hybrid-azuread-join-manual-steps.md#windows-installer-packages-for-non-windows-10-computers).
163
+
For instructions about how to use the package, see [Windows Installer packages for non-Windows 10 computers](devices/hybrid-azuread-join-control.md#control-windows-down-level-devices).
164
164
165
165
## Verify that registered devices are written back to Active Directory
166
166
You can view and verify that your device objects have been written back to your Active Directory by using LDP.exe or ADSI Edit. Both are available with the Active Directory administrator tools.
Copy file name to clipboardExpand all lines: articles/active-directory/devices/hybrid-azuread-join-managed-domains.md
+3Lines changed: 3 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -46,6 +46,9 @@ This tutorial assumes that you are familiar with:
46
46
47
47
-[How to plan your hybrid Azure Active Directory join implementation](hybrid-azuread-join-plan.md)
48
48
49
+
-[How to control the hybrid Azure AD join of your devices](hybrid-azuread-join-control.md)
50
+
51
+
49
52
To configure the scenario in this article, you need the [latest version of Azure AD Connect](https://www.microsoft.com/download/details.aspx?id=47594) (1.1.819.0 or higher) to be installed.
Copy file name to clipboardExpand all lines: articles/active-directory/devices/hybrid-azuread-join-manual-steps.md
+8-84Lines changed: 8 additions & 84 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
15
ms.devlang: na
16
16
ms.topic: article
17
-
ms.date: 08/02/2018
17
+
ms.date: 08/08/2018
18
18
ms.author: markvi
19
19
ms.reviewer: sandeo
20
20
@@ -31,40 +31,18 @@ If you have an on-premises Active Directory environment and you want to join you
31
31
> If using Azure AD Connect is an option for you, see [Select your scenario](hybrid-azuread-join-plan.md#select-your-scenario). By using Azure AD Connect, you can simplify the configuration of hybrid Azure AD join significantly.
32
32
33
33
34
-
## Before you begin
35
34
36
-
Before you start configuring hybrid Azure AD joined devices in your environment, you should familiarize yourself with the supported scenarios and the constraints.
37
35
38
-
If you are relying on the [System Preparation Tool (Sysprep)](https://docs.microsoft.com/previous-versions/windows/it-pro/windows-vista/cc721940(v=ws.10)), please make sure you create images from an installation of Windows that has not been yet registered with Azure AD.
39
-
40
-
All domain-joined devices running Windows 10 Anniversary Update and Windows Server 2016 automatically register with Azure AD at device restart or user sign-in once the configuration steps mentioned below are complete. **If this automatic register behavior is not preferred or if a controlled rollout is desired**, please follow instructions in the "Step 4: Control Deployment and Rollout" section below first to selectively enable or disable automatic rollout before following the other configuration steps.
41
-
42
-
To improve the readability of the descriptions, this article uses the following term:
43
-
44
-
-**Windows current devices** - This term refers to domain-joined devices running Windows 10 or Windows Server 2016.
45
-
-**Windows down-level devices** - This term refers to all **supported** domain-joined Windows devices that are neither running Windows 10 nor Windows Server 2016.
46
-
47
-
### Windows current devices
48
-
49
-
- For devices running the Windows desktop operating system, the supported version is the Windows 10 Anniversary Update (version 1607) or later.
50
-
- The registration of Windows current devices **is** supported in non-federated environments such as password hash sync configurations.
51
-
52
-
53
-
### Windows down-level devices
54
-
55
-
- The following Windows down-level devices are supported:
56
-
- Windows 8.1
57
-
- Windows 7
58
-
- Windows Server 2012 R2
59
-
- Windows Server 2012
60
-
- Windows Server 2008 R2
61
-
- The registration of Windows down-level devices **is** supported in non-federated environments through Seamless Single Sign On [Azure Active Directory Seamless Single Sign-On](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start).
62
-
- The registration of Windows down-level devices **is not** supported when using Azure AD Pass-through Authentication without Seamless Single Sign On.
63
-
- The registration of Windows down-level devices **is not** supported for devices using roaming profiles. If you are relying on roaming of profiles or settings, use Windows 10.
36
+
## Prerequisites
64
37
38
+
This tutorial assumes that you are familiar with:
39
+
40
+
-[Introduction to device management in Azure Active Directory](../device-management-introduction.md)
41
+
42
+
-[How to plan your hybrid Azure Active Directory join implementation](hybrid-azuread-join-plan.md)
65
43
44
+
-[How to control the hybrid Azure AD join of your devices](hybrid-azuread-join-control.md)
66
45
67
-
## Prerequisites
68
46
69
47
Before you start enabling hybrid Azure AD joined devices in your organization, you need to make sure that:
70
48
@@ -114,7 +92,6 @@ Use the following table to get an overview of the steps that are required for yo
114
92
| Configure service connection point |![Check][1]|![Check][1]|![Check][1]|
115
93
| Setup issuance of claims ||![Check][1]|![Check][1]|
116
94
| Enable non-Windows 10 devices |||![Check][1]|
117
-
| Control deployment and rollout |![Check][1]|![Check][1]|![Check][1]|
118
95
| Verify joined devices |![Check][1]|![Check][1]|![Check][1]|
119
96
120
97
@@ -559,59 +536,6 @@ To avoid certificate prompts when users in register devices authenticate to Azur
559
536
560
537
`https://device.login.microsoftonline.com`
561
538
562
-
## Control deployment and rollout
563
-
564
-
When you have completed the required steps, domain-joined devices are ready to automatically join Azure AD:
565
-
566
-
- All domain-joined devices running Windows 10 Anniversary Update and Windows Server 2016 automatically register with Azure AD at device restart or user sign-in.
567
-
568
-
- New devices register with Azure AD when the device restarts after the domain join operation is completed.
569
-
570
-
- Devices that were previously Azure AD registered (for example, for Intune) transition to “*Domain Joined, AAD Registered*”; however it takes some time for this process to complete across all devices due to the normal flow of domain and user activity.
571
-
572
-
### Remarks
573
-
574
-
- You can use a Group Policy object or System Center Configuration Manager client setting to control the rollout of automatic registration of Windows 10 and Windows Server 2016 domain-joined computers. **If you do not want these devices to automatically register with Azure AD or you want to control the registration**, then you must roll out group policy disabling the automatic registration to all these devices first or if you are using Configuration Manager you must configure the client setting under Cloud Services > Automatically register new Windows 10 domain joined devices with Azure Active Directory to "No", before starting with any of the configuration steps.
575
-
576
-
> [!Important]
577
-
> Since there is a potential delay in the application of the group policy object on newly domain joined computers during which automatic registration attempt of Windows 10 devices can occur, you must create a new sysprep image from a Windows 10 device that was never previously automatically registered, and that already has GPO to disable the automatic registration of Windows 10 devices and use that sysprep image to provision the new computers that will join your organization's domain.
578
-
579
-
After you are done configuring, and when you are ready to test, you must roll out group policy enabling the automatic registration only to the test devices and then to all other devices as you choose.
580
-
581
-
- To rollout of Windows down-level computers, you can deploy a [Windows Installer package](#windows-installer-packages-for-non-windows-10-computers) to computers that you select.
582
-
583
-
- If you push the Group Policy object to Windows 8.1 domain-joined devices, a join is attempted; however it is recommended that you use the [Windows Installer package](#windows-installer-packages-for-non-windows-10-computers) to join all your Windows down-level devices.
584
-
585
-
### Create a Group Policy object
586
-
587
-
To control the rollout of Windows current computers, you should deploy the **Register domain-joined computers as devices** Group Policy object to the devices you want to register. For example, you can deploy the policy to an organizational unit or to a security group.
588
-
589
-
**To set the policy:**
590
-
591
-
1. Open **Server Manager**, and then go to `Tools > Group Policy Management`.
592
-
2. Go to the domain node that corresponds to the domain where you want to activate auto-registration of Windows current computers.
593
-
3. Right-click **Group Policy Objects**, and then select **New**.
594
-
4. Type a name for your Group Policy object. For example, *Hybrid Azure AD join.
595
-
5. Click **OK**.
596
-
6. Right-click your new Group Policy object, and then select **Edit**.
597
-
7. Go to **Computer Configuration** > **Policies** > **Administrative Templates** > **Windows Components** > **Device Registration**.
598
-
8. Right-click **Register domain-joined computers as devices**, and then select **Edit**.
599
-
600
-
> [!NOTE]
601
-
> This Group Policy template has been renamed from earlier versions of the Group Policy Management console. If you are using an earlier version of the console, go to `Computer Configuration > Policies > Administrative Templates > Windows Components > Workplace Join > Automatically workplace join client computers`.
602
-
603
-
7. Select **Enabled**, and then click **Apply**. You must select **Disabled** if you want the policy to block the devices controlled by this group policy from automatically registering with Azure AD.
604
-
605
-
8. Click **OK**.
606
-
9. Link the Group Policy object to a location of your choice. For example, you can link it to a specific organizational unit. You also could link it to a specific security group of computers that automatically join with Azure AD. To set this policy for all domain-joined Windows 10 and Windows Server 2016 computers in your organization, link the Group Policy object to the domain.
607
-
608
-
### Windows Installer packages for non-Windows 10 computers
609
-
610
-
To join domain-joined Windows down-level computers in a federated environment, you can download and install these Windows Installer package (.msi) from Download Center at the [Microsoft Workplace Join for non-Windows 10 computers](https://www.microsoft.com/en-us/download/details.aspx?id=53554) page.
611
-
612
-
You can deploy the package by using a software distribution system like System Center Configuration Manager. The package supports the standard silent install options with the *quiet* parameter. System Center Configuration Manager Current Branch offers additional benefits from earlier versions, like the ability to track completed registrations. For more information, see [System Center Configuration Manager](https://www.microsoft.com/cloud-platform/system-center-configuration-manager).
613
-
614
-
The installer creates a scheduled task on the system that runs in the user’s context. The task is triggered when the user signs in to Windows. The task silently joins the device with Azure AD with the user credentials after authenticating using Integrated Windows Authentication. To see the scheduled task, in the device, go to **Microsoft** > **Workplace Join**, and then go to the Task Scheduler library.
Copy file name to clipboardExpand all lines: articles/active-directory/devices/hybrid-azuread-join-plan.md
+7Lines changed: 7 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -93,6 +93,13 @@ If you are relying on a Virtual Machine (VM) snapshot to create additional VMs,
93
93
94
94
The registration of Windows down-level devices is not supported for devices configured for user profile roaming or credential roaming. If you are relying on roaming of profiles or settings, use Windows 10.
95
95
96
+
- The registration of Windows down-level devices **is** supported in non-federated environments through Seamless Single Sign On [Azure Active Directory Seamless Single Sign-On](https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start).
97
+
98
+
- The registration of Windows down-level devices **is not** supported when using Azure AD Pass-through Authentication without Seamless Single Sign On.
99
+
100
+
- The registration of Windows down-level devices **is not** supported for devices using roaming profiles. If you are relying on roaming of profiles or settings, use Windows 10.
101
+
102
+
96
103
The registration of Windows Server running the Domain Controller (DC) role is not supported.
97
104
98
105
If your organization requires access to the Internet via an authenticated outbound proxy, you must make sure that your Windows 10 computers can successfully authenticate to the outbound proxy. Because Windows 10 computers run device registration using machine context, it is necessary to configure outbound proxy authentication using machine context.
0 commit comments