Lukas Beran · @lukasberancz
12 followers · 18 posts · Server infosec.exchange

My previous post about in mentioned . There can be three types of device states in Azure AD - Azure AD Join, Azure AD Hybrid Join and Azure AD Registered. All these device types can get PRT and hence benefit.

Azure AD Joined are devices running Windows 10+ or Windows Server 2019+. These devices are considered corporate devices. PRT is obtained as part of the Windows login through the Cloud Authentication Provider ().

Azure AD Registered are devices that don't have a full join done (such as or phones), but we can have the SSO benefit on them. PRT is obtained through the Windows Authentication Manager () plugin. The user does not log in to these devices with a corporate account, so CloudAP cannot be used.

#prt #azuread #devicejoin #sso #cloudap #byod #wam

Last updated 3 years ago