maciejrebisz.com

IT

Where did the package user in Azure Active Directory come from?? – Mobile-First Cloud-First

maximios October 17, 2021

When playing around with  Windows 10 and modern device management – Automatic Azure AD enrollment is a part of this. With Windows 10 1703 you can “Enroll in Azure AD” with a provision packages created with Windows Configuration Designer.

When creating a provision packages to automatic enroll a device in Azure AD a user is created in Azure AD, it is a normal user – you dont know the password for the user.

The user will show up in your all user group, and other dynamic AzureAD groups – if you do not exclude it.

If you have a dynamic Azure AD group that’s get a licens assignment then you also need to exclude the package user. The packages does not need a specific licens assigned to be working.

When you use the Windows Configuration Designer – to create a provision packages.

“Bulk Token Expiry” date is to 30 days

You need to click on the “Get Bulk Token”

Sign in with you Azure AD account (This does not require administrative rights in your Azure AD)

Enter the password for the device enrollment manager

You have to allow WCD to access your account in Azure AD

Then the “Bulk Token Fetched Successfully” and the packages user is created.

Every time you create a new provision packages with WCD then a new packages user is created!

Remember that :

The default number of devices that can be joined to an Azure AD tenant is limited to 20 – so you need to change this is you need to enroll more then 20 devices with one provision packages.

The user never expire – it is not possible to set a expire date on a cloud only user at the moment – please vote for “Set an AzureAD account to expire on a specified date” : https://feedback.azure.com/forums/34192–general-feedback/suggestions/16390489-set-an-azuread-account-to-expire-on-a-specified-da

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ How to upgrade Windows 10 1607 with SCCM 1606 (Inplace Task Sequence) – Mobile-First Cloud-First › How to upgrade Windows 10 1607 with SCCM 1606 (Inplace Task Sequence) – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes