How to Join Windows 10 to Azure Active Directory
Registering Windows 10 devices with an identity provider, like Azure Active Directory, is an important part of including endpoints in the Zero Trust security model.
In this article, I’m going to show you how to join Windows 10 to Azure Active Directory. You will 1) join an existing Windows 10 device with Azure Active Directory using the Settings app in Windows 10. You can also join an new device to Azure Active Directory as part of the out-of-box setup experience (OOBE).
Join or register Windows with Azure AD?
In a previous article, I showed you how to register Windows 10 with Azure Active Directory (AD). Devices registered with Azure AD are usually Bring Your Own Device (BYOD). Registration is supported not just on Windows 10 but also iOS, Android, and macOS. But when you join a Windows 10 device to AAD, users sign in to Windows using their organizational work or school account from the lock screen, either using a password, Windows Hello for Business, or FIDO2.0 security keys. It’s important to understand the difference between register and join when talking about Azure AD.
The security landscape is changing quickly as more users are working remotely and using their own devices. Without a robust security model in place, endpoints can easily become the weakest link in your organization’s security.
Microsoft’s identity-centric Zero Trust solution requires that every user accessing an application must be verified. Zero Trust requires that all requests for access, regardless of where they originate, must be verified as if they come from an untrusted network.
Join Windows to Azure AD
Joining Windows devices to Azure AD provides a centralized location to manage all your security policies, view devices, associated risks, and compliance status.
To join a new Windows machine, you must follow the ‘out of the box experience’ process. The steps involve logging into the machine with your corporate email address, approving the device from your mobile, and configuring the device settings.
The steps to join an existing corporate device to Azure AD are as follows:
- Open the Settings app, and then go to Accounts. And again you must connect to your account.
- On the next window, click Join this device to Azure Active Directory and then complete the login using your credentials.
The Windows device will now be joined to Azure AD! And that is it. In a following article, I will show you how to improve security by enabling Windows Hello for Business for your Windows devices.
If you experience any problems joining Windows to Azure AD, check out the following two articles on Petri for more help:
More in Security
Build 2022: Microsoft Boosts Data Analytics and Cybersecurity in New Training & Certifications
May 24, 2022 | Rabia Noureen
Microsoft Defender for Office 365 to Get Preset Security Policy Improvements In June
May 23, 2022 | Rabia Noureen
Microsoft Detects 254% Spike in XorDDoS Attacks on Linux Servers
May 23, 2022 | Rabia Noureen
CISA Warns Federal Agencies to Mitigate Critical VMware Vulnerabilities by May 23
May 20, 2022 | Rabia Noureen
CISA Warns Windows Admins Against Applying May Patch Tuesday Updates on Domain Controllers
May 17, 2022 | Rabia Noureen
F5 Confirms New Remote Code Execution Flaw in BIG-IP Systems
May 9, 2022 | Rabia Noureen
Most popular on petri