Jump to content

Recommended Posts

Posted

Hi all, not sure where to post this so thought this would be the best place. Currently I am running a school network that runs off of Intune. I have an onsite server with AD on it which is then linked to Azure AD through the Azure AD link tool. This was all setup under the previous Network Manager. For pupils to sign in they have to put their email address in to the computers (e.g. child1@pupil.$schoolname$.net) and then their password. Staff are complaining that it is causing problems and don't want to have to use the full email, and I admin that it is a bit of a pain for children in a Primary School to do, but I am not sure of anyway to change this without ripping up the whole network and starting again purely onsite.

 

Since I plan on transitioning us to a full cloud setup in the near future, running as little onsite as I can, would it be possible to do this? I currently am under the understanding that this cannot be done with Azure AD as it need to log in through the cloud and not onsite etc.

 

So in short (worried I made that far too complicated), is there anyway for users to login to a machine that logs in through Intune and Azure AD without using their full email address but still access their full account and be signed in to everything on logon etc, or is that not possible?

 

Does anyone know if this can be done?

 

Thanks

Posted (edited)

You need to add a device restrictions policy. The setting is in the Passwords section and is called "Preferred Azure AD tenant domain"

I have a mixture of Azure only and Hybrid joined devices. Users can logon to either type using just their firstname.lastname or their email address which is [email protected]

Edited by Squelch
  • 4 months later...
Posted

Sorry to bring up an old topic once again, I am still trying to get this to work and not having a lot of luck.

 

I have setup the policy described above and assigned it to the relevant machines which are hybrid joined to both the local onsite domain and to azure ad/Intune. I want to skip having to type in the full email address e.g. [email protected] so they just have to type in child1 and their password. When I set the policy up, the hybrid machines still want to default to logging into the onsite domain instead of the azure ad/Intune domain, meaning the full email address is still needing to be typed to get it to login via Intune etc.

 

I have tried setting a gpo to sign in to the schoolname.net domain but this did not make any difference. Any ideas as to how I can get this to work? I feel like I am doing the right things but for some reason nothing is changing.

 

Thanks in advance!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...