Howto Arc Sign In Windows
In brief
The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.
What Entra admins need to know
Plan domain membership before enabling the capability and follow the documented disconnect step when a different domain join is required.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Support for passwordless authentication methods and password-based authentication depending on your security requirements and Windows Server version.
Requirements
Requirements
@@ -27,7 +27,7 @@ There are many security benefits of using Microsoft Entra ID-based authenticatio - Support for passwordless authentication methods and password-based authentication depending on your security requirements and Windows Server version. > [!IMPORTANT]-> After you enable this capability, your Arc-enabled machine will be Microsoft Entra joined. You can't join them to another domain, like on-premises Active Directory or Microsoft Entra Domain Services. If you need to do so, disconnect the device from Microsoft Entra by uninstalling the extension. In addition, if you deploy a supported golden image, you can enable Microsoft Entra ID authentication by installing the extension. Conditional Access isn't supported with Windows Server with Microsoft Entra join extension in Azure Arc-enabled servers.+> After you enable this capability, your Arc-enabled machine will be Microsoft Entra joined. This scenario is for machines that are planned to not be joined to another domain, like on-premises Active Directory or Microsoft Entra Domain Services. If you need to do so, disconnect the device from Microsoft Entra by uninstalling the extension and instead use the [Entra hybrid join](/concept-hybrid-join) solution. In addition, if you deploy a supported golden image, you can enable Microsoft Entra ID authentication by installing the extension. Conditional Access isn't supported with Windows Server with Microsoft Entra join extension in Azure Arc-enabled servers. ## Requirements 