Azure-docs: ADFS Enable-AdfsDeviceRegistration

Created on 9 Mar 2019  Â·  12Comments  Â·  Source: MicrosoftDocs/azure-docs

This documentation never mention enabling ADFS Device Registration, is it a prerequisite or not?
https://blogs.technet.microsoft.com/taehee/2019/01/24/workplace-join-device-registration-to-azure-ad-for-local-domain-joined-windows-7-and-2012/#comment-535


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri1 active-directorsvc assigned-to-author doc-enhancement triaged

All 12 comments

@Martony78 Thanks for the question! We are investigating and will update you shortly.

Any update?

@MarkusVi
Markus, Do we have this documented elsewhere or can this be incorporated in this document ?

It has been a month and still no answer, does anyone at MSFT knows if ADFS Device Registration is a prerequisite or not?

@CHEEKATLAPRADEEP-MSFT any update?

We are an Okta shop and do not use AD FS. Unlike AD FS, Okta does not have the ability to issue device claims and therefore the "instantaneous Hybrid Azure AD Join" as mentioned below does not work. It would be helpful to point out that if you are NOT using AD FS you would be required to use this alternate approach of using AAD Connect to Sync the computer objects to AAD.

"Beginning with Windows 10 1803, if the instantaneous Hybrid Azure AD join for federated domain like AD FS fails, we rely on Azure AD Connect to sync the computer object in Azure AD that is subsequently used to complete the device registration for Hybrid Azure AD join."

It has been almost 4 months and still no answer, let me reformulate my question in case it is unclear:
Does this page enumerate all actions required to perform Hybrid AAD to current and down level devices or is there other actions to perform?

@Martony78 the doc should have everything you need.

@Martony78 sorry this issue got lost in the shuffle when I took over the docs and was getting up to speed on the content.

OK thank you for your reply.
You should tell your MS fellow Taehee Lee to remove the blog post posted last january, it is kind of confusing and made me and my client secops team lose time.
https://blogs.technet.microsoft.com/taehee/2019/01/24/workplace-join-device-registration-to-azure-ad-for-local-domain-joined-windows-7-and-2012/

@Martony78 I sent them a note to ask they pull their blog post.

please-close

Was this page helpful?
0 / 5 - 0 ratings

Related issues

jamesgallagher-ie picture jamesgallagher-ie  Â·  3Comments

monteledwards picture monteledwards  Â·  3Comments

Agazoth picture Agazoth  Â·  3Comments

varma31 picture varma31  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments