Windows domain join enables your users to remotely connect to a work domain using active directory credentials or local device credentials. Use Workspace ONE UEM to deploy your domain join configurations for on-premises, workgroups, and hybrid domain joins for your Windows (Windows Desktop) devices.
Integration with Microsoft Autopilot (Hybrid Domain Join)
If you manage users in the cloud and on-premises, you can use Workspace ONE UEM to assign your hybrid domain join configurations to Windows devices leveraging Windows Autopilot + OOBE (Out of Box Experience).
Use a Windows Autopilot Profile for OOBE Enrollments
Windows Autopilot allows you to configure a profile that specifies the Domain Join type for devices going through OOBE. You must configure and assign an Autopilot profile with the hybrid domain join setting in Azure. The devices assigned this profile will go through the OOBE process and be Hybrid Azure AD joined.
Important: If you do not assign an Autopilot profile with the Hybrid Join specification in Azure, your Windows devices will go through OOBE and be Azure AD joined. Once devices are Azure AD joined, you cannot initiate a Hybrid domain join without completely resetting the devices.
For details on Autopilot, access the topics on Microsoft | Docs, Configure Autopilot profiles.
- If your users use a third-party VPN client to access resources (for example, users work from home), configure the Autopilot profile menu item Skip AD connectivity check (preview) as Yes.
- If your users do not use a third-party VPN client to access resources (for example, users are on the corporate network), configure the Autopilot profile menu item Skip AD connectivity check (preview) as No.
Requirements for Deploying Domain Join Configuration
Before deploying the Domain Join Configuration, check to make sure you have completed the following requirements:
- Windows Automatic Enrollment: Configure automatic enrollment in Azure with Workspace ONE UEM as the mobile device management (MDM) system.
- Workspace ONE UEM: Disable the Status Tracking Page for OOBE.
- In Workspace ONE UEM, go to Groups & Settings > All Settings > Device & Users > General > Enrollment.
- Select the Optional Prompt tab.
- Go to the Windows section and disable Enable the Status Tracking Page for OOBE.
- Microsoft Subscription: Use one of the Microsoft subscriptions that support Windows Autopilot licensing. Access the article in Microsoft | Docs titled Windows Autopilot licensing requirements.
- Windows Autopilot Profile: Configure this profile in Azure so that your Windows devices are assigned the hybrid domain join setting. For details, access the topics on Microsoft | Docs, Configure Autopilot profiles.
- Register Devices with the Autopilot Profile: For details on how to setup Autopilot devices, access the article in Microsoft | Docs titled Manually register devices with Windows Autopilot.
- AirWatch Cloud Connector (ACC): Use ACC to enable domain join for On-premises Active Directory in Workspace ONE UEM.
- Active Directory Users and Computers (ADUC): You need the MMC snap-in called ADUC to configure on-premises domain join through Workspace ONE UEM.
- Confirm that Windows automatic enrollment with Azure in Workspace ONE UEM is configured.
- Confirm that Autopilot profile in Azure so that devices join to Azure AD as Hybrid Azure AD joined is configured and assigned.
- Confirm that you registered your Windows devices in Azure and assigned the relevant Hybrid Join Autopilot profile.
- Confirm that you have domains and Organization Units in Active Directory.
- Confirm that you have configured Directory Services in the Workspace ONE UEM console if you are using Active Directory.
- Confirm that you have configured and assigned a Domain Join configuration in Workspace ONE UEM console.
Order of Tasks
-
In Azure, set up your Autopilot devices according to Microsoft | Docs. Currently, this process includes the following steps.
-
Configure on-premises domain join in ADUC, ACC, and Workspace ONE UEM.
- In ADUC, configure a user account with Windows Server delegate permissions, create a custom delegate task, and configure permissions.
- In ACC, update the Airwatch Cloud Connector service to login with the user account created in ADUC and add write permissions to the ACC folder.
- In Workspace ONE UEM, create a domain join configuration for on-premises Active Directory.
- In Workspace ONE UEM, specify the Organization Unit information by creating and deploying single or multiple assignments for the domain join configuration.
Configure Autopilot Devices
In Azure, set up your Autopilot devices according to Microsoft documentation. Currently, this process includes the following steps.
- Create a device group.
- Register your Autopilot devices.
- Create and assign an Autopilot deployment profile.
Configure On-Premises Domain Join
The steps below outline how to configure and assign a domain join configuration in Workspace ONE UEM. These steps allow a device to join an on-premises domain on enrollment into Workspace ONE. When configured along with a Hybrid Join Autopilot profile, devices go through OOBE to join Azure AD as Hybrid Azure AD joined. If you met all the requirements and assumptions for hybrid domain join, you have met them all for on-premises domain join so you can move on to setting this up, starting with Step One: Configure ADUC in the On-Premises Domain Join section.
On-Premises Domain Join Additional Requirements
If you use Active Directory to manage users, you can use Workspace ONE UEM to assign your on-premises domain join configurations. Confirm the following requirements have been completed before you begin:
- AirWatch Cloud Connector (ACC): Use ACC to configure domain join for on-premises Active Directory.
- Active Directory Users and Computers (ADUC): You need the MMC snap-in called ADUC to configure on-premises domain join. This snap-in is part of Remote Server Administration Tools (RSAT). See Microsoft | Docs for the latest documentation on Windows Server.
- You have domains and Organization Units set in your domain in Azure.
- You have configured Directory Services in the Workspace ONE UEM console if you are using Active Directory.
Order of Tasks
- In ADUC, configure a user account with Windows Server delegate permissions, create a custom delegate task, and configure permissions.
- In ACC, update the login with the user account created in ADUC and add write permissions. Ensure that the user also has local admin privileges on the ACC server so that they can successfully start the service.
- In Workspace ONE UEM, create a domain join configuration for on-premises Active Directory.
- In Workspace ONE UEM, specify the Organization Unit information by creating and deploying single or multiple assignments for the domain join configuration.
Configure the Active Directory Users and Computers (ADUC)
In ADUC, select the user with Windows Server delegate permissions, create a custom delegate task, and configure permissions.
-
Right-click the container or folder where you want to add devices and select Delegate Control. This selection displays the Delegation of Control Wizard.
-
Select Next in the Delegation of Control Wizard.
-
On the Users or Groups window, select the user with Windows Server delegate permissions from the list, select Add, and then select Next. If this user account is not a member of the Domain Administrators group, increase the computer account creation limit (ms-ds-machine-account-quota) from the default value of 10 to prevent failures after joining 10 devices to the domain.
-
On the Tasks to Delegate window, select Create a custom task to delegate and then select Next.
-
On the Active Directory Object Type window, select Only the following objects in the folder:, Computer Objects, and Create selected objects in this folder menu items, and then select Next.
-
On the Permissions window, select General, Creation/deletion of specific child objects, Write, and Create All Child Objects, and then select Next.
Configure the Airwatch Cloud Connector (ACC)
Update the login and add write permissions for ACC to the user edited in ADUC to delegate a custom task.
- Change the Log On As for the ACC to the user configured with Windows Server delegate permissions.
Note: Ensure that the user also has local admin privileges on the ACC server so that they can successfully start the service. - In the ACC Advanced Security Settings area, give the user WRITE permissions for the ACC folder at
<Drive>:\Omnissa\AirWatch\CloudConnector.
Create an On-Premises Domain Join
Deploy a domain join configuration in Workspace ONE UEM to enrolled Windows devices that use Active Directory credentials to access resources.
- In the Workspace ONE UEM console, go to Groups & Setting > Configurations and select Domain Join from the list.
- Select Add.
- Enter a meaningful entry in the Name field so you can recognize the domain join. For example, if your users and computers in Active Directory follow a geographic pattern, you can enter
Acme - South America. This entry does not have to match any settings in Active Directory but using similar patterns in both systems can help organize your devices in your domain joins. - Select On-Premises Active Directory for the Domain Join Type.
- View the Domain Name. The domain join configuration page enters the name of the Server configured on the Directory Services page. The Workspace ONE UEM directory services configuration allows one server for directory services, so this field is autocompleted. Find Directory Services settings in Groups & Settings > All Settings > System > Enterprise Integration > Directory Services.
Note: If you want to change the Server entry on the Directory Services page, you have to Disable the DNS SRV menu item. - Select the Domain Friendly Name. The domain join configuration page offers you a list of available friendly names added to the domain list for your directory services server on the Directory Services page. Find Directory Services in Groups & Settings > All Settings > System > Enterprise Integration > Directory Services.
- Enter your preferred machine name format in the Machine Name Format field. Use a supported format for your machine name. The tool tip specifies the accepted formats. Workspace ONE UEM uses a maximum of 15 characters from the
%SERIAL%or%RAND:[#]%formats. - Save the domain join configuration to assign it later or select to Save & Assign now.
Assign a Domain Join Configuration
Below are the steps to assign your domain join configuration:
Important: Assigning more than one Domain Join configuration to a single device is not supported. This includes configurations deployed through direct assignment (as outlined in this section) as well as those delivered via Freestyle Workflows. Applying multiple Domain Join configurations may lead to conflicts and unpredictable behavior on the device. To ensure proper functionality, each device should have only one active Domain Join configuration at any time.
-
In the Workspace ONE UEM console, navigate to an assignment page by selecting Assign from the domain join list view at Groups & Setting > Configurations and select Domain Join. This configuration window displays if you select to Save & Assign your domain join configuration.
-
Select the name of the domain join configuration unless the entry is prepopulated.
-
Add an Assignment Name that has meaning for you and that helps you identify the assignment. The entry does not need to match any setting in Active Directory.
-
Search for Organization Units configured in your ADUC settings, and select only one Organization Unit.
-
Search and select smart groups that are configured in Workspace ONE UEM. You can assign a smart group to one Organization Unit and no more. If you try to select a smart group that is already assigned an Organization Unit, the console displays an error message with information so you can troubleshoot and decide which smart groups to use to fit your current deployment scenario.
-
Create and save your assignment.
Note: In versions of Workspace ONE UEM prior to 2506, the Offline Domain Join configuration was applied only during device enrollment. Starting with Workspace ONE UEM 2506 and modern architecture enabled, this limitation has been removed — the Offline Domain Join configuration can now be applied at any point in the device lifecycle, providing greater flexibility in deployment scenarios. This in not applicable for Workgroup scenarios.
Computers Container in Active Directory (AD) and OU/Smart Groups Conflicts
Domain Join configuration assignment is determined by Smart Group membership. The Parent-Child Organizational Group (OG) hierarchy does not influence configuration assignment unless the device qualifies for Smart Groups in both the parent and child OGs.
If a device qualifies for Offline Domain Join configurations assigned at both the parent and child OG levels, the configuration from the child OG (more specific or "closed" OG) will take precedence and be applied to the device.
When a device receives multiple Offline Domain Join configurations, conflict resolution is determined based on the Domain Name and Type.
- If all configurations have the same Domain Name and Type, the Organization Unit (OU) is treated as optional. The system proceeds with the domain join, treating the OU as empty if necessary.
- If the Domain Name or Type differs, the domain join cannot proceed.
🔹 Scenario 1: Same Domain, Different OU
The device qualifies for SG1 and SG2.
| Device SG | Domain Name | Type | Organization Unit |
|---|---|---|---|
| SG1 | amst.ad | OfflineDomainJoin | OU=domainJoinOU,DC=amst,DC=ad |
| SG2 | amst.ad | OfflineDomainJoin | DC=amst,DC=ad |
Outcome:
Domain Name and Type match; Organization Unit differs. The OU is treated as empty, and domain join proceeds.
Effective Configuration:
| Domain Name | Type | Organization Unit |
|---|---|---|
| amst.ad | OfflineDomainJoin | (empty) |
Scenario 2: Identical Configurations
The device qualifies for SG1 and SG2.
| Device SG | Domain Name | Type | Organization Unit |
|---|---|---|---|
| SG1 | amst.ad | OfflineDomainJoin | OU=domainJoinOU,DC=amst,DC=ad |
| SG2 | amst.ad | OfflineDomainJoin | OU=domainJoinOU,DC=amst,DC=ad |
Outcome:
All fields match exactly. Domain join proceeds using the specified Organization Unit.
Effective Configuration:
| Domain Name | Type | Organization Unit |
|---|---|---|
| amst.ad | OfflineDomainJoin | OU=domainJoinOU,DC=amst,DC=ad |
Scenario 3: Different Domains
The device qualifies for SG1 and SG2.
| Device SG | Domain Name | Type | Organization Unit |
|---|---|---|---|
| SG1 | amst.ad | OfflineDomainJoin | OU=domainJoinOU,DC=amst,DC=ad |
| SG2 | dell.ad | OfflineDomainJoin | OU=domainJoinOU,DC=dell,DC=ad |
Outcome:
Domain Names differ. A device cannot be joined to multiple domains. Domain join will not be processed.
Effective Configuration:
No Domain Join possible
Device Receives Both Domain Join and Workgroup Configurations
When both a Domain Join and a Workgroup configuration are assigned to the same device, the system will prioritize and apply the Domain Join configuration. The Workgroup configuration will be ignored in this case.
Applying Domain Join Configuration
Before applying the Offline Domain Join configuration, Workspace ONE Intelligent Hub performs a check to determine whether the device is already joined to an Active Directory (AD) or Entra ID domain.
- If the device is not domain joined, the configuration will be applied.
- If the device is already domain joined, the configuration will be skipped.
To include domain join as part of a broader workflow, avoid assigning the configuration directly to a corporate (work) device outside that workflow.
Note: For devices not configured with Windows Autopilot, a manual reboot is required after applying the Offline Domain Join configuration.
Troubleshooting
To investigate issues with the Offline Domain Join process, you can gather and review logs directly from the device and analyze relevant system components.
Steps to Troubleshoot Collect Workspace ONE Intelligent Hub logs from the following paths:
- C:\ProgramData\AirWatch\UnifiedAgent\Logs\DomainJoin-%TIMESTAMP%.log
- C:\ProgramData\AirWatch\UnifiedAgent\Logs\DSM-%TIMESTAMP%.log
- C:\ProgramData\AirWatch\UnifiedAgent\Logs\TaskScheduler-%TIMESTAMP%.log
Inspect Workflow Log Entries if the Domain Join Config was assigned via Freestyle Workflow In the workflow logs, search for the following key phrase to confirm event processing: "Received domain join hub cache event"
Capture a Fiddler Trace A Fiddler trace may help identify communication issues or failures in the API calls between Workspace ONE components and the device.
Check Registry Settings Review the following registry path for Workspace ONE domain join-related configurations: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\AIRWATCH
These artifacts provide a detailed view of what occurred during the domain join attempt and help isolate root causes in case of failure.
Was this page helpful?