Skip to content

Commit bd84de4

Browse files
committed
saving changes
1 parent 9d876c6 commit bd84de4

1 file changed

Lines changed: 12 additions & 2 deletions

File tree

memdocs/azure-ad-joined-hybrid-azure-ad-joined.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ author: MandiOhlinger
99

1010
ms.author: mandia
1111
manager: dougeby
12-
ms.date: 05/03/2022
12+
ms.date: 05/17/2022
1313
ms.topic: conceptual
1414
ms.service: mem
1515
ms.subservice: fundamentals
@@ -123,7 +123,17 @@ For new, refurbished, or refreshed Windows devices, Microsoft recommends [Azure
123123

124124
Keep in mind that HAADJ and AADJ are not mutually exclusive, both can coexist in the same environment. However, HAADJ should not be your organization's end goal for its Windows endpoints and having both may increase the environment's complexity which may translate into additional support costs.
125125

126-
Enabling HAADJ on existing endpoints where they cannot be reset or reposivioned is generally the path of least resistance for most organizations. This allows these devices to have a cloud identity and to use cloud services that require a cloud identity without initial impact to the end-user.
126+
It depends, and there might not be a right or wrong answer. It depends on your environment, your hardware, and your organization goals. Consider the following scenarios:
127+
128+
- **Endpoints can't be reset or reprovisioned**
129+
130+
In this scenario, Hybrid Azure AD joined is the easiest option. Devices have a cloud identity and can use cloud services that require a cloud identity. It might have minimal impact to end users.
131+
132+
- **You have new endpoints or can reset existing endpoints**
133+
134+
In this scenario, Azure AD joined is recommended.
135+
136+
127137

128138
For newly provisioned Windows endpoints, you should strongly consider only using AADJ whenever possible. Choosing HAADJ for newly provisioned devices leads to additional envrionmental complexity and costs because of this complexity. There are some known blockers and challeneges outside of Microsoft's control that may prevent your organization from fully adopting AADJ for newly provisioned Windows endpoints. There may also be unknown blockers that are specific to your organization and its configuration or expectations. Note that these blockers may be technical in nature or they mat arise due to other, non-technical factors.
129139

0 commit comments

Comments
 (0)