Hello, everyone. In today’s article, we’ll talk about device management in Azure AD. We’ll cover the concepts and requirements for the ways a device can be associated with Azure AD.
There are three ways to associate a device with Azure AD, namely:
Azure AD register – Typically used in BYOD (bring your own device) scenarios, where the user uses their personal account to sign in to the device and their corporate account to access the resources available from the corporation. It’s possible to apply policies and control access using tools, location, user, and device. It’s also possible to use single sign-on with web or corporate applications.
Azure AD Join – This format is used when the company has cloud-only infrastructure or a strategy to migrate its devices to the cloud. Once the device has joined the Azure AD domain, the user will only be able to access the device using the corporate credential registered in Azure AD.
Azure Hybrid AD Join – This model allows devices managed by the on-premises domain to access resources in Azure AD, getting the best of both worlds. To use this model, the on-premises AD objects need to be replicated to Azure. For this replication to work, we use Azure AD Connect. To understand how to configure this replication, take a look at the article Introduction to Azure AD Connect.
Below, we show a comparison between the scenarios explained above:
Azure AD registred |
Azure AD joined |
Hybrid Azure AD joined |
|
|---|---|---|---|
| Público | BYOD e dispositivos móveis | Todos os usuários da organização | Todos os usuários da organização |
| Dono do dispositivo | Usuário ou a organização | Organização | Organização |
| Sistemas operacionais suportados | Windows 10, IOS, Android e MacOS | Windows 10 | Windows 10, 8.1 e 7 Windows Server 2008/R2, 2012/R2, 2016 and 2019 |
| Provisionamento disponível | Windows 10 (settings) IOS/Android - Company portal ou Microsoft authenticator MacOS - Company portal | Windows 10 | Windows 10, Windows Server 2016/2019 |
| Gerenciamento do dispositivo | Mobile Device Management ou Mobile Application Management | Mobile Device Management ou System Center Configuration Manager (co-management) | GPO, System Center Configuration Manager, co-manatement com MS Intune |
| Opções de autenticação | Senha, windows hello, PIN, biometria | Senha, windows hello for business, chaves de segurança FIDO 2.0 (preview) | Senha, windows hello for business para dispositivos windows 10 |
Single sign-on
It allows the user to authenticate to one application and use the same session to access other applications. This feature simplifies access to cloud-hosted applications and, depending on the deployment, can also be used to access on-premises applications.
For more information about single sign-on, visit this link.
Summary
In today’s article, we provided a brief introduction to the ways devices can join Azure AD, and how each technology offers security and a better user experience when using corporate applications.
In the next article, we’ll demonstrate step by step how to manually register a device in Azure AD.
I hope this content has contributed to expanding your knowledge of Azure.
Did you like the post? Like and share it. 🙂
If you have any suggestions or comments, let us know.
[ ]’s
Ulysses Neves
