Windows Insider Program for Business using Azure Active Directory
- Windows 10
Looking for information about Windows 10 for personal or home use? See Windows Update: FAQ
We recently added features and benefits to better support the IT Professionals and business users in our Windows Insider community. This includes the option to download Windows 10 Insider Preview builds using your corporate credentials in Azure Active Directory (AAD). By enrolling devices in AAD, you increase the visibility of feedback submitted by users in your organization – especially on features that support your specific business needs.
At this point, the Windows Insider Program for Business only supports Azure Active Directory (and not Active Directory on premises) as a corporate authentication method.
New to Azure Active Directory? Go here for an introduction to AAD, including guidance for adding users, device registration and integrating your on-premises directories with Azure AD.
If your company is currently not using AAD – but has a paid subscription to Office 365, Microsoft Dynamics CRM Online, Enterprise Mobility Suite, or other Microsoft services – you have a free subscription to Microsoft Azure Active Directory. This subscription can be used to create users for enrollment in the Windows Insider Program for Business.
In order to get the most benefit out of the Windows Insider Program for Business, organizations should not use a test tenant of AAD. There will be no modifications to the AAD tenant to support the Windows Insider Program as it will only be used as an authentication method.
Register your organization's Azure AD domain to the Windows Insider Program for Business
Rather than have each user in your organization register for Windows 10 Insider Preview builds, you can now simply register your domain – and cover all users with just one registration.
- On the Windows Insider website, go to For Business > Getting Started to register your organizational Azure AD account.
- Register your domain. Rather than have each user register individually for Windows Insider Preview builds, administrators can simply register their domain and control settings centrally.
The signed-in user needs to be a Global Administrator of the Azure AD domain in order to be able to register the domain.
Check if a device is connected to your company’s Azure Active Directory subscription
Simply go to Settings > Accounts > Access work or school. If a corporate account is on Azure Active Directory and it is connected to the device, you will see the account listed as highlighted in the image below.
Enroll a device with an Azure Active Directory account
- Navigate to the Getting Started page on Windows Insider.
- Go to Register your organization account and follow the instructions.
- On your Windows 10 device, go to Settings > Updates & Security > Windows Insider Program.
- Enter the AAD account that you used to register and follow the on-screen directions.
Make sure that you have administrator rights to the machine and that it has latest Windows updates.
Switch device enrollment from your Microsoft account to your AAD account
- Visit insider.windows.com to register your AAD account. If you are signed in with your Microsoft account, sign out, then sign back in with your corporate AAD account.
- Click Get started, read and accept the privacy statement and program terms and click Submit.
- On your Windows 10 PC, go to Settings > Updates & Security > Windows Insider Program.
- Under Windows Insider account, click your Microsoft account, then Change to open a Sign In box.
- Select your corporate account and click Continue to change your account.
Your device must be connected to your corporate account in AAD for the account to appear in the account list.
User consent requirement
With the current version of the Feedback Hub app, we need the user's consent to access their AAD account profile data (We read their name, organizational tenant ID and user ID). When they sign in for the first time with the AAD account, they will see a popup asking for their permission, like this:
Once agreed, everything will work fine, and that user won't be prompted for permission again.
Something went wrong
The option for users to give consent for apps to access their profile data is controlled through Azure Active Directory. This means the AAD administrators have the ability to allow or block users from giving consent.
In case the administrators blocked this option, when the user signs in with the AAD account, they will see the following error message:
This blocks the user from signing in, which means they won't be able to use the Feedback Hub app with their AAD credentials.
To fix this issue, an administrator of the AAD directory will need to enable user consent for apps to access their data.
To do this through the classic Azure portal:
- Go to https://manage.windowsazure.com/ .
- Switch to the Active Directory dashboard.
- Select the appropriate directory and go to the Configure tab.
- Under the integrated applications section, enable Users may give applications permissions to access their data.
To do this through the new Azure portal:
- Go to https://portal.azure.com/ .
- Switch to the Active Directory dashboard.
- Switch to the appropriate directory.
- Under the Manage section, select User settings.
- In the Enterprise applications section, enable Users can allow apps to access their data.
Frequently Asked Questions
Will my test machines be affected by automatic registration?
All devices enrolled in the Windows Insider Program (physical or virtual) will receive Windows 10 Insider Preview builds (regardless of registration with MSA or AAD).
Once I register with my corporate account in AAD, do I need to keep my Microsoft account for the Windows Insider Program?
No, once you set up your device using AAD credentials – all feedback and flighting on that machine will be under your AAD account. You may need MSA for other machines that aren’t being used on your corporate network or to get Microsoft Store App updates.
How do I stop receiving updates?
You can simply “unlink” your account by going to Settings > Updates & Security > Windows Insider Program, select Windows Insider Account and click Unlink.