I registered the device recently. Why can't I see the device under my user info in the Azure portal? Or why is the device owner marked as N/A for hybrid Azure Active Directory (Azure AD) joined devices?
Windows 10 or newer devices that are hybrid Azure AD joined don't show up under USER devices. Use the All devices view in the Azure portal. You can also use a PowerShell Get-MsolDevice cmdlet.
Only the following devices are listed under USER devices:
- All personal devices that aren't hybrid Azure AD joined.
- All non-Windows 10 or newer and Windows Server 2016 or later devices.
- All non-Windows devices.
How do I know what the device registration state of the client is?
In the Azure portal, go to All devices. Search for the device by using the device ID. Check the value under the join type column. Sometimes, the device might be reset or reimaged. So it's essential to also check the device registration state on the device:
- For Windows 10 or newer and Windows Server 2016 or later devices, run
- For down-level OS versions, run
%programFiles%\Microsoft Workplace Join\autoworkplace.exe.
For troubleshooting information, see these articles:
I see the device record under the USER info in the Azure portal. And I see the state as registered on the device. Am I set up correctly to use Conditional Access?
The device join state, shown by deviceID, must match the state on Azure AD and meet any evaluation criteria for Conditional Access. For more information, see Require managed devices for cloud app access with Conditional Access.
Why do my users see an error message saying "Your organization has deleted the device" or "Your organization has disabled the device" on their Windows 10/11 devices?
On Windows 10/11 devices joined or registered with Azure AD, users are issued a Primary refresh token (PRT) which enables single sign on. The validity of the PRT is based on the validity of the device itself. Users see this message if the device is either deleted or disabled in Azure AD without initiating the action from the device itself. A device can be deleted or disabled in Azure AD one of the following scenarios:
- User disables the device from the My Apps portal.
- An administrator (or user) deletes or disables the device in the Azure portal or by using PowerShell
- Hybrid Azure AD joined only: An administrator removes the devices OU out of sync scope resulting in the devices being deleted from Azure AD
- Upgrading Azure AD connect to the version 1.4.xx.x. Understanding Azure AD Connect 1.4.xx.x and device disappearance.
See below on how these actions can be rectified.
I disabled or deleted my device in the Azure portal or by using Windows PowerShell. But the local state on the device says it's still registered. What should I do?
This operation is by design. In this case, the device doesn't have access to resources in the cloud. Administrators can perform this action for stale, lost, or stolen devices to prevent unauthorized access. If this action was performed unintentionally, you'll need to re-enable or re-register the device as described below
If the device was disabled in Azure AD, an administrator with sufficient privileges can enable it from the Azure AD portal
If you are syncing devices using Azure AD Connect, hybrid Azure AD joined devices will be automatically re-enabled during the next sync cycle. So, if you need to disable a hybrid Azure AD joined device, you need to disable it from your on-premises AD
If the device is deleted in Azure AD, you need to re-register the device. To re-register, you must take a manual action on the device. See below for instructions for re-registration based on the device state.
To re-register hybrid Azure AD joined Windows 10/11 and Windows Server 2016/2019 devices, take the following steps:
- Open the command prompt as an administrator.
dsregcmd.exe /debug /leave.
- Sign out and sign in to trigger the scheduled task that registers the device again with Azure AD.
For down-level Windows OS versions that are hybrid Azure AD joined, take the following steps:
- Open the command prompt as an administrator.
"%programFiles%\Microsoft Workplace Join\autoworkplace.exe /l".
"%programFiles%\Microsoft Workplace Join\autoworkplace.exe /j".
For Azure AD joined devices Windows 10/11 devices, take the following steps:
- Open the command prompt as an administrator
dsregcmd /forcerecovery(You need to be an administrator to perform this action).
- Click "Sign in" in the dialog that opens up and continue with the sign in process.
- Sign out and sign in back to the device to complete the recovery.
For Azure AD registered Windows 10/11 devices, take the following steps:
- Go to Settings > Accounts > Access Work or School.
- Select the account and select Disconnect.
- Click on "+ Connect" and register the device again by going through the sign in process.
Why do I see duplicate device entries in the Azure portal?
- For Windows 10 or newer and Windows Server 2016 or later, repeated tries to unjoin and rejoin the same device might cause duplicate entries.
- Each Windows user who uses Add Work or School Account creates a new device record with the same device name.
- For down-level Windows OS versions that are on-premises Azure Directory domain joined, automatic registration creates a new device record with the same device name for each domain user who signs in to the device.
- An Azure AD joined machine that's wiped, reinstalled, and rejoined with the same name shows up as another record with the same device name.
Does Windows 10/11 device registration in Azure AD support TPMs in FIPS mode?
Windows 10/11 device registration is only supported for FIPS-compliant TPM 2.0 and not supported for TPM 1.2. If your devices have FIPS-compliant TPM 1.2, you must disable them before proceeding with Azure AD join or Hybrid Azure AD join. Microsoft does not provide any tools for disabling FIPS mode for TPMs as it is dependent on the TPM manufacturer. Contact your hardware OEM for support.
Why can a user still access resources from a device I disabled in the Azure portal?
It takes up to an hour for a revoke to be applied from the time the Azure AD device is marked as disabled.
For enrolled devices, we recommend that you wipe the device to make sure users can't access the resources. For more information, see What is device enrollment?.
I can't add more than 3 Azure AD user accounts under the same user session on a Windows 10/11 device, why?
Azure AD added support for multiple Azure AD accounts starting in Windows 10 1803 release. However, Windows 10/11 restricts the number of Azure AD accounts on a device to 3 to limit the size of token requests and enable reliable single sign on (SSO). Once 3 accounts have been added, users will see an error for subsequent accounts. The Additional problem information on the error screen provides the following message indicating the reason - "Add account operation is blocked because account limit is reached".
What are the MS-Organization-Access certificates present on our Windows 10/11 devices?
The MS-Organization-Access certificates are issued by Azure AD Device Registration Service during the device registration process. These certificates are issued to all join types supported on Windows - Azure AD joined, hybrid Azure AD joined and Azure AD registered devices. Once issued, they are used as part of the authentication process from the device to request a Primary Refresh Token (PRT). For Azure AD joined and hybrid Azure AD joined devices, this certificate is present in Local Computer\Personal\Certificates whereas for Azure AD registered devices, certificate is present in Current User\Personal\Certificates. All MS-Organization-Access certificates have a default lifetime of 10 years, however these certificates are deleted from the corresponding certificate store when the device is unregistered from Azure AD. Any inadvertent deletion of this certificate will lead to authentication failures for the user, and will require re-registration of the device in such cases.
Azure AD join FAQ
How do I unjoin an Azure AD joined device locally on the device?
For pure Azure AD joined devices, make sure you have an offline local administrator account or create one. You can't sign in with any Azure AD user credentials. Next, go to Settings > Accounts > Access Work or School. Select your account and select Disconnect. Follow the prompts and provide the local administrator credentials when prompted. Reboot the device to finish the unjoin process.
Can my users' sign in to Azure AD joined devices that are deleted or disabled in Azure AD?
Yes. Windows has a cached username and password capability that allows users who signed in previously to access the desktop quickly even without network connectivity.
When a device is deleted or disabled in Azure AD, it's not known to the Windows device. So users who signed in previously continue to access the desktop with the cached username and password. But as the device is deleted or disabled, users can't access any resources protected by device-based Conditional Access.
Users who didn't sign in previously can't access the device. There's no cached username and password enabled for them.
Can a disabled or deleted user sign in to an Azure AD joined device?
Yes, but only for a limited time. When a user is deleted or disabled in Azure AD, it's not immediately known to the Windows device. So users who signed in previously can access the desktop with the cached username and password.
Typically, the device is aware of the user state in less than four hours. Then Windows blocks those users' access to the desktop. As the user is deleted or disabled in Azure AD, all their tokens are revoked. So they can't access any resources.
Deleted or disabled users who didn't sign in previously can't access a device. There's no cached username and password enabled for them.
Can a guest user sign in to an Azure AD joined device?
No, currently, guest users can not sign in to an Azure AD joined device.
Why do my users have issues on Azure AD joined devices after changing their UPN?
Currently, UPN changes are not fully supported on Azure AD joined devices. So their authentication with Azure AD fails after their UPN changes. As a result, users have SSO and Conditional Access issues on their devices. At this time, users need to sign in to Windows through the "Other user" tile using their new UPN to resolve this issue. We are currently working on addressing this issue. However, users signing in with Windows Hello for Business do not face this issue.
UPN changes are supported starting with Windows 10 2004 update and also applicable to Windows 11. Users on devices with this update will not have any issues after changing their UPNs
My users can't search printers from Azure AD joined devices. How can I enable printing from those devices?
To deploy printers for Azure AD joined devices, see Deploy Windows Server Hybrid Cloud Print with Pre-Authentication. You need an on-premises Windows Server to deploy hybrid cloud print. Currently, cloud-based print service isn't available.
How do I connect to a remote Azure AD joined device?
Why do my users see 'You can't get there from here'?
Did you configure certain Conditional Access rules to require a specific device state? If the device doesn't meet the criteria, users are blocked, and they see that message. Evaluate the Conditional Access policy rules. Make sure the device meets the criteria to avoid the message.
Why do I get a 'username or password is incorrect' message for a device I just joined to Azure AD?
Common reasons for this scenario are as follows:
- Your user credentials are no longer valid.
- Your computer can't communicate with Azure Active Directory. Check for any network connectivity issues.
- Federated sign-ins require your federation server to support WS-Trust endpoints that are enabled and accessible.
- You enabled pass-through authentication. So your temporary password needs to be changed when you sign in.
How can users change their temporary or expired password on Azure AD joined devices?
Currently, Azure AD joined devices do not force users to change password on the lock screen. So, users with temporary or expired passwords will be forced to change passwords only when they access an application (that requires an Azure AD token) after they login to Windows.
Why do I see the 'Oops… an error occurred!' dialog when I try to Azure AD join my PC?
This error happens when you set up Azure Active Directory auto-enrollment with Intune without proper license assigned. Make sure that the user who tries to Azure AD join has the correct Intune license assigned. For more information, see Set up enrollment for Windows devices.
Why did my attempt to Azure AD join a PC fail, although I didn't get any error information?
A likely cause is that you signed in to the device by using the local built-in administrator account. Create a different local account before you use Azure Active Directory join to finish the setup.
What are the MS-Organization-P2P-Access certificates present on our Windows 10/11 devices?
The MS-Organization-P2P-Access certificates are issued by Azure AD to both, Azure AD joined and hybrid Azure AD joined devices. These certificates are used to enable trust between devices in the same tenant for remote desktop scenarios. One certificate is issued to the device and another is issued to the user. The device certificate is present in
Local Computer\Personal\Certificates and is valid for one day. This certificate is renewed (by issuing a new certificate) if the device is still active in Azure AD. The user certificate is not persistent and is valid for one hour, but it is issued on-demand when a user attempts a remote desktop session to another Azure AD joined device. It is not renewed on expiry. Both these certificates are issued using the MS-Organization-P2P-Access certificate present in the
Local Computer\AAD Token Issuer\Certificates. This certificate is issued by Azure AD during device registration.
Hybrid Azure AD join FAQ
How do I unjoin a Hybrid Azure AD joined device locally on the device?
For hybrid Azure AD joined devices, make sure to turn off automatic registration in AD using the Controlled validation article. Then the scheduled task won't register the device again. Next, open a command prompt as an administrator and enter
dsregcmd.exe /debug /leave. Or run this command as a script across several devices to unjoin in bulk.
Where can I find troubleshooting information to diagnose hybrid Azure AD join failures?
For troubleshooting information, see these articles:
Why do I see a duplicate Azure AD registered record for my Windows 10/11 hybrid Azure AD joined device in the Azure AD devices list?
When your users add their accounts to apps on a domain-joined device, they might be prompted with Add account to Windows? If they enter Yes on the prompt, the device registers with Azure AD. The trust type is marked as Azure AD registered. After you enable hybrid Azure AD join in your organization, the device also gets hybrid Azure AD joined. Then two device states show up for the same device.
In most cases, Hybrid Azure AD join takes precedence over the Azure AD registered state, resulting in your device being considered hybrid Azure AD joined for any authentication and Conditional Access evaluation. However, sometimes, this dual state can result in a non-deterministic evaluation of the device and cause access issues. We strongly recommend upgrading to Windows 10 version 1803 and above where we automatically clean up the Azure AD registered state. Learn how to avoid or clean up this dual state on the Windows 10 machine.
Why do my users have issues on Windows 10/11 hybrid Azure AD joined devices after changing their UPN?
Currently UPN changes are not fully supported with hybrid Azure AD joined devices. While users can sign in to the device and access their on-premises applications, authentication with Azure AD fails after a UPN change. As a result, users have SSO and Conditional Access issues on their devices. At this time, you need to unjoin the device from Azure AD (run "dsregcmd /leave" with elevated privileges) and rejoin (happens automatically) to resolve the issue. We are currently working on addressing this issue. However, users signing in with Windows Hello for Business do not face this issue.
UPN changes are supported with Windows 10 2004 update and also applicable to Windows 11. Users on devices with this update will not have any issues after changing their UPNs
Do Windows 10/11 hybrid Azure AD joined devices require line of sight to the domain controller to get access to cloud resources?
No, except when the user's password is changed. After Windows 10/11 hybrid Azure AD join is complete, and the user has signed in at least once, the device doesn't require line of sight to the domain controller to access cloud resources. Windows 10/11 can get single sign-on to Azure AD applications from anywhere with an internet connection, except when a password is changed. Users who sign in with Windows Hello for Business continue to get single sign-on to Azure AD applications even after a password change, even if they don't have line of sight to their domain controller.
What happens if a user changes their password and tries to sign in to their Windows 10/11 hybrid Azure AD joined device outside the corporate network?
If a password is changed outside the corporate network (for example, by using Azure AD SSPR), then the user sign in with the new password will fail. For hybrid Azure AD joined devices, on-premises Active Directory is the primary authority. When a device does not have line of sight to the domain controller, it is unable to validate the new password. So, user needs to establish connection with the domain controller (either via VPN or being in the corporate network) before they're able to sign in to the device with their new password. Otherwise, they can only sign in with their old password because of cached sign in capability in Windows. However, the old password is invalidated by Azure AD during token requests and hence, prevents single sign-on and fails any device-based Conditional Access policies until the user authenticates with their new password in an app or browser. This issue doesn't occur if you use Windows Hello for Business.
Azure AD register FAQ
How do I remove an Azure AD registered state for a device locally?
- For Windows 10/11 Azure AD registered devices, Go to Settings > Accounts > Access Work or School. Select your account and select Disconnect. Device registration is per user profile on Windows 10/11.
- For iOS and Android, you can use the Microsoft Authenticator application Settings > Device Registration and select Unregister device.
- For macOS, you can use the Microsoft Intune Company Portal application to unenroll the device from management and remove any registration.
For Windows 10 version 2004 and older, this process can be automated with the Workplace Join (WPJ) removal tool
This tool removes all SSO accounts on the device. After this operation, all applications will lose SSO state, and the device will be unenrolled from management tools (MDM) and unregistered from the cloud. The next time an application tries to sign in, users will be asked to add the account again.
How can I block users from adding more work accounts (Azure AD registered) on my corporate Windows 10/11 devices?
Enable the following registry to block your users from adding additional work accounts to your corporate domain joined, Azure AD joined, or hybrid Azure AD joined Windows 10/11 devices. This policy can also be used to block domain joined machines from inadvertently getting Azure AD registered with the same user account.
Can I register Android or iOS BYOD devices?
Yes, but only with the Azure device registration service and for hybrid customers. It's not supported with the on-premises device registration service in Active Directory Federation Services (AD FS).
How can I register a macOS device?
Take the following steps:
- The users included in your Conditional Access policy need a supported version of Office for macOS to access resources.
- During the first access try, your users are prompted to enroll the device by using the company portal.