Update: Microsoft will be moving away from UserVoice sites on a product-by-product basis throughout the 2021 calendar year. We will leverage 1st party solutions for customer feedback. Learn more here.

Eric Calcagno

My feedback

  1. 27 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Azure Active Directory » Domain Join  ·  Flag idea as inappropriate…  ·  Admin →
    Eric Calcagno supported this idea  · 
    An error occurred while saving the comment
    Eric Calcagno commented  · 

    Huge security risk for our organization as well. Does moving the user to a different group break Azure AD joined integration? I opened a case with MS and they confirmed our suspicions.

    However, you are able to move the Azure identity to the local "Users" group and then remove it from the local Administrators group. Sync seems to continue to work but this has not been tested in production.

    Add account to Users group
    Add-LocalGroupMember -Group "User" -Member AzureDomain\AzureUser

    Remove account from Administrators group
    Remove-LocalGroupMember -Group "Administrators" -Member AzureDomain\AzureUser

Feedback and Knowledge Base