Azure AD Join and workgroup machines

Anjana R 156 Reputation points
2021-09-28T20:07:02.92+00:00

Hi Team,

We are joining Windows 10 machines to Azure AD and machines are not part of any domain. They are in WORKGROUP. We are not using any on-premises Active Directory domain and users are having accounts in Azure AD with domain.onmicrosoft.com account . Plan is to add the workgroup machines to Azure AD.

In this case:

  1. What all policies can be applied to this workgroup machine if they are Azure AD joined?
  2. Whether multiple users can login to the same Windows 10 machine once they are Azure AD joined? Or the machine should be joined to an Active Directory domain to achieve this functionality?
  3. If machines are in workgroup and Azure AD joined, whether they can be enrolled and managed using Intune/Endpoint Manager?

Thanks,
Anjana

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,389 questions
0 comments No comments
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,231 Reputation points Microsoft Employee
    2021-09-29T04:33:16.34+00:00

    @Anjana R Thanks for reaching out.

    1) There is no device management policies which gets applied when you join it to Azure AD. For that you will have to use Intune portal and setup Auto enrollment to Intune if you want this. (Auto Enrollment makes it easier )

    2) Yes, multiple users can login with their Azure AD account on the Azure AD Joined Devices.

    3) Yes they can be directly enrolled in Intune either when they are Azure AD joined or even when they are not Azure AD join.

    Here are few links which will help you further :

    1. Different Methods to Enroll the Windows machine to Intune : https://learn.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-methods
    2. Managing Windows 10 with Intune : https://www.microsoft.com/en-us/insidetrack/managing-windows-10-devices-with-microsoft-intune
    3. Planning Azure AD join Deployments : https://learn.microsoft.com/en-us/azure/active-directory/devices/azureadjoin-plan

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


0 additional answers

Sort by: Most helpful