Microsoft Entra ID
Troubleshooting

Manage Device Identities

In brief

The documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.

What Entra admins need to know

Admins supporting macOS or Linux device onboarding should include this setting when troubleshooting registration or join failures.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

You can use a device ID to verify the device ID details on the device or to troubleshoot via PowerShell. To access the copy option, select the device.

Screenshot that shows a device ID and the copy button.

View or copy BitLocker keys

You can view and copy BitLocker keys to allow users to recover encrypted drives. These keys are available only for Windows devices that are encrypted and store their keys in Microsoft Entra ID. You can find these keys when you view a device's details by selecting Show Recovery Key. Selecting Show Recovery Key generates an audit log entry, which you can find in the KeyManagement category.

Screenshot that shows device settings related to Microsoft Entra ID.

  • Users may join devices to Microsoft Entra ID: This setting enables you to select the users who can register their devices as Microsoft Entra joined devices. The default is All.
  • Users may register their devices with Microsoft Entra ID: You need to configure this setting to allow users to register Windows 10 or newer personal, iOS, Android, and macOS devices with Microsoft Entra ID. If you select None, devices aren't allowed to register with Microsoft Entra ID. Enrollment with Microsoft Intune or mobile device management for Microsoft 365 requires registration. If you've configured either of these services, ALL is selected, and NONE is unavailable.
  • Require multifactor authentication to register or join devices with Microsoft Entra ID:
    • We recommend organizations use the Register or join devices user action in Conditional Access to enforce multifactor authentication. You must configure this toggle to No if you use a Conditional Access policy to require multifactor authentication.
    • This setting allows you to specify whether users are required to provide another authentication factor to join or register their devices to Microsoft Entra ID. The default is No. We recommend that you require multifactor authentication when a device is registered or joined. Before you enable multifactor authentication for this service, you must ensure that multifactor authentication is configured for users that register their devices. For more information on Microsoft Entra multifactor authentication services, see getting started with Microsoft Entra multifactor authentication. This setting might not work with third-party identity providers.
  • Maximum number of devices: This setting enables you to select the maximum number of Microsoft Entra joined or Microsoft Entra registered devices that a user can have in Microsoft Entra ID. If users reach this limit, they can't add more devices until one or more of the existing devices are removed. The default value is 50. You can increase the value up to 100. If you enter a value above 100, Microsoft Entra ID sets it to 100. You can also use Unlimited to enforce no limit other than existing quota limits.
  • Manage Additional local administrators on Microsoft Entra joined devices: This setting lets you select users who are granted local administrator rights on all Microsoft Entra joined devices in the tenant. These users are assigned to the Microsoft Entra Joined Device Local Administrator role, which applies tenant-wide.
  • Registering user is added as local administrator on the device during Microsoft Entra join: This setting controls whether users who perform Microsoft Entra join are added to the local Administrators group on the device they join. This setting affects local device administrator membership only. It doesn't assign a Microsoft Entra directory role, such as Global Administrator, and it doesn't add the user to the Microsoft Entra Joined Device Local Administrator role. To verify the result, check the local Administrators group on the device or use a device management tool. In Microsoft Graph, this setting is represented by the azureADJoin.localAdmins.registeringUsers property of the device registration policy.
  • Enable Microsoft Entra Local Administrator Password Solution (LAPS) (preview): LAPS is the management of local account passwords on Windows devices. LAPS provides a solution to securely manage and retrieve the built-in local admin password. With cloud version of LAPS, customers can enable storing and rotation of local admin passwords for both Microsoft Entra ID and Microsoft Entra hybrid join devices. To learn how to manage LAPS in Microsoft Entra ID, see the overview article.

Next steps

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…