Device Management
Documentation for Intune MDM, Azure AD device enrollment, and compliance policies.
Contents
- Azure AD Join Guide — How to properly Azure AD Join a Windows device
- Device Compliance & Troubleshooting — Diagnosing enrollment and compliance issues
- Device Offboarding & Reuse — Handling devices from former employees
Related Runbooks
- Device Compliance Audit — Auditing and remediating non-compliant devices
Key Concepts
| Term | Meaning |
|---|---|
| Azure AD Registered (Workplace Join) | Device is registered but not managed. No PRT, no Intune MDM, no compliance enforcement. Typically personal/BYOD devices. |
| Azure AD Joined | Device is fully joined to Azure AD. Gets a PRT for SSO, Intune auto-enrolls, compliance policies enforced. For org-owned devices. |
| Hybrid Azure AD Joined | Device is joined to both on-prem AD and Azure AD. For orgs with existing Active Directory infrastructure. |
| PRT (Primary Refresh Token) | Token issued to Azure AD Joined devices enabling SSO across cloud services. Without it, authentication can hang or fail. |
Tenant Info
- Tenant: Authentica Solutions
- Tenant ID:
43598f0d-0b98-4383-bf42-ad1283cf5012