smarties11 Posted August 30, 2022 Posted August 30, 2022 Hi All, Came across this today - and wasn't aware myself so a heads up really. By default, Microsoft allows any users to domain join their personal devices to your Azure AD. I wasn't aware that this was the case. With Windows 11, 'connecting to work or School' is part of the initial OOBE setup with a new machine - and users that do this innocently, probably expecting it to just set up their e-mail account/OneDrive/O365 end up with a laptop that is domain joined - and is then fair game for remote wiping, InTune management etc. This became an issue for one of our employees yesterday, as her laptop brought up the BitLocker recovery screen. Despite her using her personal Microsoft account to sign-in to the laptop, the recovery key wasn't saved there. Thankfully she read the MS article on recovery keys and got to the bit about work/School accounts and asked the question of me - I was dubious at first but indeed her recovery key was in our AAD, because she had 'connected to work or School' on the Win11 OOBE. It is possible to prevent this happening in AAD at Devices | Device Settings, as below. This setting shouldn't effect user-less domain joins e.g. hybrid, autopilot etc - however I can't test that as we use SCCM here and haven't moved across to InTune (yet). Hope this helps some others. 2
FN-GM Posted August 30, 2022 Posted August 30, 2022 Thanks for the post. By default standard users can also join computers to an on premise domain. 1
Davit2005 Posted August 30, 2022 Posted August 30, 2022 Thanks for the post. By default standard users can also join computers to an on premise domain. 10 devices before it stops I think :-)
psydii Posted August 31, 2022 Posted August 31, 2022 We found this in lockdown. A student needed me to unwind it. Was a bit on the busy side, so didn't get to it for a while. After a couple of weeks they gently chased me up, then sent through a step by step instructions with screen shots and a pointer to this setting to stop it happening again. They'd set up an evaluation E5 tenant for the purpose. Really should have employed them TBH.
pete Posted August 31, 2022 Posted August 31, 2022 Note that if you're using InTune or have ever touched MDM in 365 (have ever configured anything in there), the option to prevent users registering devices with Azure AD is turned off: Users may register their devices with Azure AD: You need to configure this setting to allow users to register Windows 10 or newer personal, iOS, Android, and macOS devices with Azure AD. If you select None, devices aren't allowed to register with Azure AD. Enrollment with Microsoft Intune or mobile device management for Microsoft 365 requires registration. If you've configured either of these services, ALL is selected and NONE is unavailable. https://docs.microsoft.com/da-dk/azure/active-directory/devices/device-management-azure-portal#configure-device-settings There's a /r/sysadmin thread on the topic recently too:
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now