Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.2.3. Device Join and Registration

💡 First Principle: Devices get identities for the same reason users do: policy needs a trustworthy signal about the machine before it can require "compliant device" or grant SSO. The three relationship types encode ownership: personal devices register, corporate cloud devices join, and corporate AD devices hybrid join — and each unlocks different controls.

Entra registeredEntra joinedEntra hybrid joined
Ownership modelPersonal / BYODOrganization, cloud-firstOrganization, AD-joined
User signs in withLocal/personal account (+ work account added)Entra credentialsAD credentials
OS supportWindows, macOS, iOS, Android, LinuxWindows, (macOS via SSO extensions evolving)Windows (domain-joined)
How it happensAdd work account / MDM enrollmentOOBE/Settings, Autopilot, bulk enrollmentConfigured via Entra Connect + GPO/auto
Typical controlsApp protection, CA device checksFull Intune management, WHfB, SSOCo-management, SSO to both worlds

The pairing with Conditional Access is the point: "require compliant device" needs the device known to Entra and managed/evaluated by Intune (compliance flows from Intune to the device object); "require hybrid joined device" targets the AD-fleet pattern. Device settings from 3.1.3 govern who may join/register and how many devices per user; local administrator on Entra-joined machines defaults to the joining user plus roles you configure (and the LAPS successor for local admin passwords lives in this space). Devices support enable/disable (a disabled device fails device-based CA immediately — a fast containment lever) and BitLocker key escrow for joined devices.

Migration logic for stems: cloud-first org, new Windows fleet → Entra join (+ Autopilot); existing AD fleet needing cloud CA signals without re-imaging → hybrid join; contractors' personal phones → register (+ app protection policies), never join.

⚠️ Exam Trap: Hybrid join is not "better join" — it's the compatibility state for AD-domain-joined machines. Microsoft's direction (and modern-answer stems) prefer pure Entra join for new deployments; hybrid join answers stems that already have AD-joined devices to bring along.

Reflection Question: A CA policy requires compliant devices for Finance apps. A finance user's personal iPhone is registered but not enrolled in Intune. Walk through why the sign-in fails and the two different resolutions (device-side vs policy-side).

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications