
Active Directory Administration Cookbook, Second Edition
By :

This recipe shows how to limit the Azure AD join and Azure AD registration features for your organization, and allow the Enterprise State Roaming functionality.
To complete this recipe, sign in to the Azure AD tenant with an account that has the Global administrator role assigned to it. If the organization uses the Azure AD PIM feature, activate the Global administrator role in advance.
Configuring additional accounts with local administrator privileges on Azure AD-joined devices and enabling Enterprise State Roaming requires Azure AD Premium P1 licenses or Microsoft licenses that include the P1 license, such as Azure AD Premium P2, EMS E3, EMS A3, Microsoft 365 E3, or Microsoft 365 Business licenses.
Configuring the Azure AD join and Azure AD registration features consists of these three distinct configuration changes: