教程:首次运行期间使用 Azure AD 加入新的 Windows 10 设备Tutorial: Join a new Windows 10 device with Azure AD during a first run

使用 Azure Active Directory (Azure AD) 中的设备管理,可以确保用户从满足安全性和符合性标准的设备访问资源。With device management in Azure Active Directory (Azure AD), you can ensure that your users are accessing your resources from devices that meet your standards for security and compliance. 有关详细信息,请参阅 Azure Active Directory 中的设备管理简介For more information, see the introduction to device management in Azure Active Directory.

对于 Windows 10,可在首次运行体验 (FRX) 期间将新的设备加入 Azure AD。With Windows 10, You can join a new device to Azure AD during the first-run experience (FRX).
通过这样可将打包的设备分发给员工或学生。This enables you to distribute shrink-wrapped devices to your employees or students.

如果设备安装了 Windows 10 专业版或 Windows 10 企业版,则体验将默认为公司所拥有设备的设置过程。If you have either Windows 10 Professional or Windows 10 Enterprise installed on a device, the experience defaults to the setup process for company-owned devices.

Windows 全新体验中不支持加入本地 Active Directory (AD) 域。In the Windows out-of-box experience, joining an on-premises Active Directory (AD) domain is not supported. 如果打算将计算机加入 AD 域,在设置期间就应选择链接“使用本地帐户设置 Windows”。If you plan to join a computer to an AD domain, during setup, you should select the link Set up Windows with a local account. 然后可通过计算机上的设置加入域。You can then join the domain from the settings on your computer.

本教程介绍如何在 FRX 期间将设备加入 Azure AD:In this tutorial, you learn how to join a device to Azure AD during FRX:

  • 先决条件Prerequisites
  • 加入设备Joining a device
  • 验证Verification

先决条件Prerequisites

若要加入 Windows 10 设备,必须配置设备注册服务以允许注册设备。To join a Windows 10 device, the device registration service must be configured to enable you to register devices. 除具有在 Azure AD 租户中加入设备的权限外,注册设备的数量必须少于所配置的最大数。In addition to having permission to joining devices in your Azure AD tenant, you must have fewer devices registered than the configured maximum. 有关详细信息,请参阅配置设备设置For more information, see configure device settings.

此外,如果你的租户为联合租户,标识提供者必须支持 WS-Fed 和 WS-Trust 用户名/密码终结点。In addition, if your tenant is federated, your Identity provider MUST support WS-Fed and WS-Trust username/password endpoint. 这可以是版本 1.3 或 2005。This can be version 1.3 or 2005. 无论是将设备加入 Azure AD,还是使用密码登录设备,都必须有此协议支持。This protocol support is required to both join the device to Azure AD and sign in to the device with a password.

加入设备Joining a device

FRX 期间将 Windows 10 设备加入 Azure AD:To join a Windows 10 device to Azure AD during FRX:

  1. 打开新设备并启动设置过程时,应该会看到“正在准备”消息。When you turn on your new device and start the setup process, you should see the Getting Ready message. 请按照提示来设置设备。Follow the prompts to set up your device.

  2. 首先,自定义区域和语言。Start by customizing your region and language. 然后接受 Microsoft 软件许可条款。Then accept the Microsoft Software License Terms.

    为区域自定义

  3. 选择要用来连接到 Internet 的网络。Select the network you want to use for connecting to the Internet.

  4. 单击“此设备属于我的组织”。Click This device belongs to my organization.

    “谁是这台电脑的所有者”屏幕

  5. 输入组织提供的凭据,然后单击“登录”。Enter the credentials that were provided to you by your organization, and then click Sign in.

    登录屏幕

  6. 设备会查找 Azure AD 中的匹配租户。Your device locates a matching tenant in Azure AD. 如果在联盟域中,系统会将你重定向到本地安全令牌服务 (STS) 服务器,例如,Active Directory 联合身份验证服务 (AD FS)。If you are in a federated domain, you are redirected to your on-premises Secure Token Service (STS) server, for example, Active Directory Federation Services (AD FS).

  7. 如果是非联盟域中的用户,请直接在 Azure AD 托管页上输入凭据。If you are a user in a non-federated domain, enter your credentials directly on the Azure AD-hosted page.

  8. 系统会提示完成多重身份验证质询。You are prompted for a multi-factor authentication challenge.

  9. Azure AD 会检查是否需要在移动设备管理中进行注册。Azure AD checks whether an enrollment in mobile device management is required.

  10. Windows 会在 Azure AD 的组织目录中注册设备,并将其注册到移动设备管理中(如果适用)。Windows registers the device in the organization’s directory in Azure AD and enrolls it in mobile device management, if applicable.

  11. 相应流程:If you are:

    • 如果为托管用户,Windows 会通过自动登录过程你将转到桌面。A managed user, Windows takes you to the desktop through the automatic sign-in process.
    • 如果为联合用户,则会定向到 Windows 登录屏幕以输入凭据。A federated user, you are directed to the Windows sign-in screen to enter your credentials.

验证Verification

若要验证设备是否已加入 Azure AD,请查看 Windows 设备上的“访问工作单位或学校”。To verify whether a device is joined to your Azure AD, review the Access work or school dialog on your Windows device. 此对话框应会指示你已连接到 Azure AD 目录。The dialog should indicate that you are connected to your Azure AD directory.

访问工作单位或学校

后续步骤Next steps