Jump to content

Recommended Posts

Posted

Wondering if anyone else is doing this right now - would be useful to have some input...

 

We have some Surface 3 and Dell Venue 11 Pro devices that we're issuing to staff to use as a 1:1 device. We expect them to be used off-site as much as on-site so makes little sense to join them to the local domain that won't be contactable half the time.

 

Instead we'll use the connect to School or Work feature to "join" the devices to Azure AD and use Office 365 account to log in. That's neat as it gives SSO to O365 services then any further management would be more in an MDM model.

 

Microsoft keep bringing out new scenarios and naming conventions so I think I've got it down to these choices...

 

  1. machine stays in WORKGROUP but joins to Azure AD (as above)
  2. machine gets joined to AD domain only
  3. machine gets joined to AD domain AND Azure AD via Azure AD Connect

If the first option is the route we want to go down I basically need to make a tweak to MDT to stop it auto joining the domain as part of the Task Sequence. Seems like editing unattend.xml is the preferred method but has anyone done it a quicker way?

 

As an aside we need the domain join in a different TS for networked machines so wondering if to use two Deployment Shares or mess around with customsettings.ini and TS changes, any preferences \ feedback on either method?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...