Azure AD joined devices are the devices which are in workgroup. There is prerequisite for Azure AD joined is that the Windows device should not be joined to any domain to have the Azure AD joined in place.
Now if the device is not joined to any on-premise domain then you cannot access any on-premies resources from that device.
Provided, if you are trying to access any on-premises application from this AAD joined device then you will have to deploy that application via Azure AD app proxy.
https://learn.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy
Or if this approach is not feasible for you then you will have to configure the Windows device as Hybrid Azure AD joined. For this you will have to join the devices to on-premises domain.
Do let me know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.