Domain Join Group Policy
Join computer to domain and specify ou path with powershell.
Domain join group policy. So i went ahead and enabled windows hello for business as well. Right click the default domain group policy and click edit. Thankfully we can automate this with powershell when we join the computers to the domain.
In the left side pane you can see a node with the domain name. Now this will open group policy object editor. The enrollment into intune is triggered by a group policy created on your local ad and happens without any user interaction.
If you prefer a controlled rollout rather than this auto registration you can use group policy to selectively enable or disable automatic rollout. Right click on it and then click on properties. This means you can.
When you join a computer to the domain it will by default go the computers folder. Open group policy management editor gpmc create a new group policy object and name it local administrators servers. Here are the steps to add local administrators via gpo.
Now select the appropriate group policy object in the list and then click on edit. It is best practice to move the computers from the default folder to a different ou. Under the windows hello section it states.
Starting in windows 10 version 1709 you can use a group policy to trigger auto enrollment to mdm for active directory ad domain joined devices. Now it will open a new window on which we need to select the group policy tab. All domain joined devices running windows 10 and windows server 2016 automatically register with azure ad once all configuration steps are complete.