You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/azure-ad-joined-hybrid-azure-ad-joined.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -60,7 +60,7 @@ The endpoint is joined to Azure AD. It's not joined to an on-premises AD domain.
60
60
61
61
To join Windows endpoints to Azure AD, you have some options:
62
62
63
-
-**Use [Windows Autopilot](/mem/autopilot/)**. Windows Autopilot guides users through the Windows Out of Box Experience (OOBE). When users enter their work or school account, the endpoint joins Azure AD.
63
+
-**Use [Windows Autopilot](./autopilot/index.yml)**. Windows Autopilot guides users through the Windows Out of Box Experience (OOBE). When users enter their work or school account, the endpoint joins Azure AD.
64
64
65
65
All devices registered with Windows Autopilot are automatically considered organization owned devices. Windows Autopilot is one of the most adopted approaches to get organization devices joined to Azure AD and managed by IT.
66
66
@@ -132,7 +132,7 @@ Consider the following scenarios:
132
132
| You want to manage endpoints using MDM policies | ✔️ Azure AD join <br/><br/> Microsoft Intune, which is a 100% cloud solution, can manage Windows client devices. Intune has many built-in features and settings that can manage settings, control device features, help secure your endpoints, and more. <br/><br/>The [High level planning guide to move to cloud-native endpoints: Intune features you should know](cloud-native-endpoints-planning-guide.md#intune-features-you-should-know) lists some of these features. [What is Intune](./intune/fundamentals/what-is-intune.md) is also a good resource. <br/><br/>❌ Hybrid Azure AD join<br/><br/> On HAADJ endpoints, you must use group policies objects (GPO) to control policy settings. If you enable [co-management](./configmgr/comanage/overview.md) (Intune (cloud) + Configuration Manager (on-premises)), then you can use some Azure AD features, such as conditional access. <br/><br/>For some guidance, go to [Deployment guide: Setup or move to Microsoft Intune](./intune/fundamentals/deployment-guide-intune-setup.md). |
133
133
| You want to eliminate on-premises AD for authentication and sign-on | ✔️ Azure AD join <br/><br/> User identities are created and stored in Azure AD. Users can sign in to their endpoints from anywhere and at any time. If you use [passwordless authentication](/azure/active-directory/authentication/concept-authentication-passwordless), then users might not need internet access to sign in. <br/><br/> AADJ endpoints can also use modern authentication, including multifactor authentication (MFA), smart card authentication, and certificate-based authentication.<br/><br/> ❌ Hybrid Azure AD join<br/><br/> HAADJ endpoints require a line-of-sight to the on-premises AD domain controller for initial sign-in and to change passwords. If the domain is down, or there isn't any internet access, then users could be blocked from signing in to their endpoints. <br/><br/> If you use [passwordless authentication](/azure/active-directory/authentication/howto-authentication-passwordless-faqs), then users need internet access and line of sight to the DCs. HAADJ endpoints can use kerberos and NTLM to authenticate. |
134
134
| You need to access on-premises resources | ✔️ Azure AD join <br/><br/> AADJ endpoints can access on-premises resources, and can use single sign-on (SSO). For more specific information, go to [Cloud-native endpoints and on-premises resources](cloud-native-endpoints-on-premises.md).<br/><br/>✔️ Hybrid Azure AD join<br/><br/> HAADJ endpoints can use single sign-on (SSO) across your cloud and on-premises resources. For more specific information, go to [Configure hybrid Azure AD join](/azure/active-directory/devices/howto-hybrid-azure-ad-join). |
135
-
| You want device compliance and/or conditional access | ✔️ Azure AD join <br/><br/> With Microsoft Intune or [co-management](/configmgr/comanage/overview) (Intune (cloud) + Configuration Manager (on-premises)), you can create [compliance policies](/mem/intune/protect/device-compliance-get-started). When combined with [conditional access](/mem/intune/protect/conditional-access), you can enforce your compliance policies on AADJ endpoints. <br/><br/>✔️ Hybrid Azure AD join<br/><br/> With Microsoft Intune or [co-management](/configmgr/comanage/overview) (Intune (cloud) + Configuration Manager (on-premises)), you can create [compliance policies](/mem/intune/protect/device-compliance-get-started). When combined with [conditional access](/mem/intune/protect/conditional-access), you can enforce your compliance policies on HAADJ endpoints. |
135
+
| You want device compliance and/or conditional access | ✔️ Azure AD join <br/><br/> With Microsoft Intune or [co-management](/configmgr/comanage/overview) (Intune (cloud) + Configuration Manager (on-premises)), you can create [compliance policies](./intune/protect/device-compliance-get-started.md). When combined with [conditional access](./intune/protect/conditional-access.md), you can enforce your compliance policies on AADJ endpoints. <br/><br/>✔️ Hybrid Azure AD join<br/><br/> With Microsoft Intune or [co-management](/configmgr/comanage/overview) (Intune (cloud) + Configuration Manager (on-premises)), you can create [compliance policies](./intune/protect/device-compliance-get-started.md). When combined with [conditional access](./intune/protect/conditional-access.md), you can enforce your compliance policies on HAADJ endpoints. |
136
136
137
137
## Follow the cloud-native endpoints guidance
138
138
@@ -141,4 +141,4 @@ Consider the following scenarios:
141
141
3. 🡺 **Concept: Azure AD joined vs. Hybrid Azure AD joined** (*You are here*)
142
142
4.[Concept: Cloud-native endpoints and on-premises resources](cloud-native-endpoints-on-premises.md)
Copy file name to clipboardExpand all lines: memdocs/cloud-native-endpoints-known-issues.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -119,7 +119,7 @@ The following list includes common features and services that might use machine
119
119
120
120
For more information, go to:
121
121
122
-
-[Add PowerShell scripts to Windows 10/11 devices in Microsoft Intune](/mem/intune/apps/intune-management-extension)
122
+
-[Add PowerShell scripts to Windows 10/11 devices in Microsoft Intune](./intune/apps/intune-management-extension.md)
123
123
-[Introduction to OneDrive in Microsoft 365](/learn/modules/m365-onedrive-collaboration-use/)
124
124
125
125
## Group policy objects might not apply
@@ -128,14 +128,14 @@ It's possible some of your older policies aren't available, or don't apply to cl
128
128
129
129
**Resolution**:
130
130
131
-
- Using [Group Policy Analytics](/mem/intune/configuration/group-policy-analytics) in Endpoint Manager, you can evaluate your existing group policy objects (GPO). The analysis shows the policies that are available, and policies that aren't available.
131
+
- Using [Group Policy Analytics](./intune/configuration/group-policy-analytics.md) in Endpoint Manager, you can evaluate your existing group policy objects (GPO). The analysis shows the policies that are available, and policies that aren't available.
132
132
- In endpoint management, policies are deployed to users and groups. They aren't applied in LSDOU order. This behavior is a mind shift, so make sure your users and groups are in order.
133
133
134
-
For more specific information and guidance on policy assignment in Microsoft Intune, go to [Assign user and device profiles in Microsoft Intune](/mem/intune/configuration/device-profile-assign).
134
+
For more specific information and guidance on policy assignment in Microsoft Intune, go to [Assign user and device profiles in Microsoft Intune](./intune/configuration/device-profile-assign.md).
135
135
136
136
- Inventory your policies, and determine what they do. You may find categories or groupings, such as policies that focus on security, policies that focus on the OS, and so on.
137
137
138
-
You can create an Intune policy that includes the settings from your categories or groupings. The [Settings Catalog](/mem/intune/configuration/settings-catalog) is a good resource.
138
+
You can create an Intune policy that includes the settings from your categories or groupings. The [Settings Catalog](./intune/configuration/settings-catalog.md) is a good resource.
139
139
140
140
- Be prepared to create new policies. The built-in features of modern endpoint management, like Microsoft Intune, may have better options to create and deploy policies.
141
141
@@ -176,4 +176,4 @@ For more specific information, go to [Implement password hash synchronization wi
176
176
3.[Concept: Azure AD joined vs. Hybrid Azure AD joined](azure-ad-joined-hybrid-azure-ad-joined.md)
177
177
4.[Concept: Cloud-native endpoints and on-premises resources](cloud-native-endpoints-on-premises.md)
Copy file name to clipboardExpand all lines: memdocs/cloud-native-endpoints-overview.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -69,7 +69,7 @@ A cloud-native endpoint doesn't necessarily live exclusively in the cloud. Inste
69
69
70
70
These endpoints can be located anywhere that has internet access. They can also be physical devices or virtual machines.
71
71
72
-
From a technical perspective, cloud-native endpoints are Windows devices that are deployed using [Windows Autopilot](/mem/autopilot/windows-autopilot), joined to Azure Active Directory ([Azure AD joined](/azure/active-directory/devices/concept-azure-ad-join)), and are automatically enrolled in a Mobile Device Management (MDM) solution, like [Microsoft Endpoint Manager](/mem/endpoint-manager-overview).
72
+
From a technical perspective, cloud-native endpoints are Windows devices that are deployed using [Windows Autopilot](./autopilot/windows-autopilot.md), joined to Azure Active Directory ([Azure AD joined](/azure/active-directory/devices/concept-azure-ad-join)), and are automatically enrolled in a Mobile Device Management (MDM) solution, like [Microsoft Endpoint Manager](./endpoint-manager-overview.md).
73
73
74
74
A cloud-native endpoint has the following characteristics:
75
75
@@ -150,4 +150,4 @@ The [High level planning guide to move to cloud-native endpoints](cloud-native-e
150
150
3.[Concept: Azure AD joined vs. Hybrid Azure AD joined](azure-ad-joined-hybrid-azure-ad-joined.md)
151
151
4.[Concept: Cloud-native endpoints and on-premises resources](cloud-native-endpoints-on-premises.md)
0 commit comments