Azure Domain Join Group Policy
If you prefer a controlled rollout rather than this auto registration you can use group policy to selectively enable or disable automatic rollout.
Azure domain join group policy. Once you install serviceconnectionpoint for azure ad hybrid join every single windows 10 machine in forest will perform aad hybrid join. For windows 7 and windows 8 1 devices the documentation states that it is necessary to deploy the workplace join client msi package from here this is not required for windows 10 systems which can register to azure ad via group policy although in my lab that does not appear to be working as that does not produce any records when i run get msoldevice. If you have cloud only service with azure this service will allow you to manage your azure identities more affectively. What s in and not in the box.
This group policy should be set before starting the other configuration steps. Azure ad intune and group policy. Disabled setting doesn t block windows10 azure ad hybrid join. At the moment gpo windows components device registration register domain joined computers as devices has absolutely no effect.
This procedure will work for any future version as well. To join your organizations azure ad click on join azure ad button. Azure ad domain services is a managed domain service which provides group policy ldap ntlm kerberos authentication without need of domain controller in your azure cloud setup. Group policy has been the way admins shore up security because windows is not secure out of the box.
Create a group policy object gpo and enable the group policy computer configuration policies administrative templates windows components mdm enable automatic mdm enrollment using default azure ad credentials. Since then it has become the go to tool for managing and securing the windows desktop across the domain. Create a group policy object in your active directory. When you click on the link join or leave azure ad as mentioned in the above step it will take you to windows 10 settings system about page.
Restart the domain controller for the policy to be available.