Azure AD设备加入及本地权限相关技术咨询
Azure AD设备加入及本地权限相关技术咨询
Hey Vic85, let's break down your questions one by one based on real-world Azure AD deployment practices:
问题1:使用全局管理员账号加入所有设备后,其他用户能否用自己的账号登录?
Absolutely, this approach works perfectly fine, especially if you're dealing with a small number of devices. Here's the breakdown:
- When you join a device to Azure AD using your
admin@abc.comglobal admin account, the device becomes registered in your Azure AD tenant. - Once joined, any user in your Azure AD tenant (with valid licenses, if required for your setup) can sign in to that device using their own email credentials.
- That said, if you have a larger fleet of devices, you might want to look into Azure AD Join Bulk Registration or Automatic Device Join (for Windows devices) to streamline the process instead of manually joining each one with the admin account—it'll save you a ton of time.
问题2:本地管理员权限与普通用户的操作限制
By default, here's how the permissions shake out for Azure AD-joined devices:
- Your
admin@abc.comglobal admin account will automatically be added to the local Administrators group on every device you join to Azure AD. - Regular users who sign in to the device will be standard users by default—they can't perform actions that require admin rights (like installing software, changing system settings, etc.) without entering an admin's credentials (in this case,
admin@abc.com). - If you want to grant local admin rights to specific users or groups (instead of relying solely on the global admin), you can configure this via Azure AD:
- Go to the Azure AD portal, navigate to Devices > Device settings.
- Look for the Additional local administrators on Azure AD joined devices option, then add the users or security groups you want to assign local admin rights to. This way, those users can perform admin tasks without needing the global admin's credentials.
备注:内容来源于stack exchange,提问作者Vic85
相关产品推荐
相关产品推荐

