Enforcing policies and configurations
In Chapter 6, Administration and Policy Management, we covered the differences between domain, hybrid, and Azure AD join for devices. Traditionally, when devices join an Active Directory domain, they connect to a domain controller and receive specific user and computer configurations controlled by Group Policy. This is still applicable in the hybrid Azure AD join model, but the approach to managing policies may begin to change, depending on your administration preferences. When a device becomes fully Azure AD joined, Group Policy is no longer an option, but it opens new opportunities to administer configurations and enforce policies. For companies not starting with fresh configurations or are greenfield, this can present a challenge as many organizations have years' worth of GPOs they rely on to harden their Windows systems and enforce baseline controls. The question becomes how to move and enforce these policies if GPO isn't an option...