Windows 10: How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices

Discus and support How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices in Windows 10 Gaming to solve the problem; Hello Microsoft Community,We are currently working on securing our Milestone servers running Windows 11. These devices are not domain joined, and we... Discussion in 'Windows 10 Gaming' started by Dom_214, May 14, 2025 at 9:27 AM.

  1. Dom_214 Win User

    How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices


    Hello Microsoft Community,We are currently working on securing our Milestone servers running Windows 11. These devices are not domain joined, and we are looking for Microsoft-supported options to prevent brute force attacks, particularly on local login and RDP if enabled.We need to understand what built-in or supported tools and configurations are available to mitigate brute force attacks on:Non-domain joined Windows 11 devicesAzure AD joined Windows 11 devices OS: Windows 11 Pro RDP: May be enabled for remote accessNo third-party endpoint protection currently in useWhat are t

    :)
     

  2. Join Azure Ad or Local domain

    We have recently migrated to Office 365 with a hybrid AD setup. I am setting up a new laptop for a user, first one since the migration, and in the original setup it had me join the Azure AD. However, I usually set these laptops up to join the local domain so the users can access the file shares. The shares are accessed via Mapped Drives from Group Policy, and being joined to the Azure AD did not map these drives. When I go to join the laptop to the local domain, I get an error saying "The device is joined to an Azure AD. To join an Active Directory domain, you must .... disconnect your device from your work or school." So there's no way to be joined to the Azure, even though its syncing with my local AD? I want the best of both worlds. What's the best way of doing that? I feel if I unjoin from the Azure AD I'm kind of going backwards, but they need access to those local file stores. Any brilliant workarounds out there? Thanks!
     
  3. Mr Davo Win User
    Image W10 workstations for Azure AD join?

    Hi All,

    I want to image Windows 10; but more importantly I need to join Azure AD 'Out of the Box'!

    I don't have a 'master' Azure AD account. I am not even sure that such a thing exits, e.g.: the Administrator account on a standard Active Directory Domain.

    Where should I be looking for configuration, where it comes to Azure AD automatic joining?

    My thoughts are PowerShell DST! But that is just a rumour.

    Any suggestions would be amazing.

    Regards,

    Davo
     
  4. Kari Win User

    How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices

    Join Windows 10 PC to a Domain  


    That would explain it.

    Active Directory is the way, the tool local domains use for user control and management. There are three different methods a user / device can join AD: joining local domain and signing in with domain credentials, joining through Azure AD and signing in with Azure AD credentials, and the "lowest level" so called workplace join, connect a local or Microsoft sign-in account to an Azure AD (workplace) account.

    Joining a local domain and Azure AD basically is the same. Of course there are administrative differences from IT departement's point of view, but for the most the only difference end user sees is the sign-in credentials.

    Once you have joined a local domain, you cannot join Azure AD, and vice versa. It's one or the other.

    Joining Azure AD instead of joining a domain is in my opinion the future, Microsoft's clear goal being to get corporate users to move from local domains and on-premises domain controllers to Azure AD. I posted an opinion piece about that just a few days ago on my site: Secure Windows on a Secure Device Win10.Guru

    Azure AD gives you two levels to join: Workplace join simply adds your Azure AD account to Windows 10 for single-sign-on to all your workplace services, but you will continue signing in to Windows with your current local or Microsoft account:

    How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices 176852d1518470567-join-windows-10-pc-domain-workplace-join.jpg


    This will be shown as a connected account:

    How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices 176853d1518470567-join-windows-10-pc-domain-workplace-joined.jpg


    As you will continue signing in with your local or Microsoft account, you are still pretty much in control. You can use workplace services, company store and such but IT admin cannot set up any restrictions on your device. A workplace joined user / device can still join a local domain.

    If you select Join Azure AD instead, your sign-in account will be changed to Azure AD account. This is shown as Azure AD joined:

    How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices 176851d1518470567-join-windows-10-pc-domain-azure-ad-joined.jpg


    Once joined to Azure AD, joining a local domain is no longer possible.

    I'm not sure if the above explains this clear enough. The point is, a local domain and Azure AD effectively chooses the way you are joined to your workplace. Only one of these methods to join can be used.
     
Thema:

How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices

Loading...
  1. How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices - Similar Threads - Prevent Brute Force

  2. How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices

    in Windows 10 Software and Apps
    How to Prevent Brute Force Attacks on Windows 11 Non-Domain Joined & Azure AD Joined Devices: Hello Microsoft Community,We are currently working on securing our Milestone servers running Windows 11. These devices are not domain joined, and we are looking for Microsoft-supported options to prevent brute force attacks, particularly on local login and RDP if enabled.We...
  3. Azure User AD not Joined

    in Windows 10 Gaming
    Azure User AD not Joined: Dears I hope u're doing great, I'm working in a hybrid environment and sometimes the devices can't sync with the cloud Intune, however to fix this problem I have to disjoin and rejoin again with the command dsregcmd /debug /leave and rejoin it manually from Settings >...
  4. Azure User AD not Joined

    in Windows 10 Software and Apps
    Azure User AD not Joined: Dears I hope u're doing great, I'm working in a hybrid environment and sometimes the devices can't sync with the cloud Intune, however to fix this problem I have to disjoin and rejoin again with the command dsregcmd /debug /leave and rejoin it manually from Settings >...
  5. How to prevent Windows from joining a domain?

    in Windows 10 Gaming
    How to prevent Windows from joining a domain?: Hi,I've asked this question earlier: https://answers.microsoft.com/cs-cz/windows/forum/all/nelze-se-p%c5%99ihl%c3%a1sit-ke-sv%c3%a9mu/76d7a786-45f3-4dee-9bad-c2b6466dfa68In short - my home PC joined a school domain which exposed it to the school administrators. You and...
  6. How to prevent Windows from joining a domain?

    in Windows 10 Software and Apps
    How to prevent Windows from joining a domain?: Hi,I've asked this question earlier: https://answers.microsoft.com/cs-cz/windows/forum/all/nelze-se-p%c5%99ihl%c3%a1sit-ke-sv%c3%a9mu/76d7a786-45f3-4dee-9bad-c2b6466dfa68In short - my home PC joined a school domain which exposed it to the school administrators. You and...
  7. How to prevent Windows from joining a domain?

    in AntiVirus, Firewalls and System Security
    How to prevent Windows from joining a domain?: Hi,I've asked this question earlier: https://answers.microsoft.com/cs-cz/windows/forum/all/nelze-se-p%c5%99ihl%c3%a1sit-ke-sv%c3%a9mu/76d7a786-45f3-4dee-9bad-c2b6466dfa68In short - my home PC joined a school domain which exposed it to the school administrators. You and...
  8. Login to Windows11 machines with Azure ad joined domain users

    in Windows 10 Software and Apps
    Login to Windows11 machines with Azure ad joined domain users: Hello All,I'm new to Intune and trying to test MDM functionality to our Mac, Windows & Linux machines. We are using Google workspace as our primary IDP and I federated Google workspace as IDP and Azure AD as SP and enabled Single sign on that works fine When I login to...
  9. Does disabling a domain-joined device in Azure AD prevent local sign-in using PIN?

    in Windows Hello & Lockscreen
    Does disabling a domain-joined device in Azure AD prevent local sign-in using PIN?: This query relates to a standard Windows 10/Office 365 Business Premium subscription, on a domain-joined device - with no other local accounts created (aside from local Admin, not shared with employees). The O365 support team confirmed that resetting a password/signing out...
  10. Dis-Join Azure AD

    in Windows 10 Network and Sharing
    Dis-Join Azure AD: Hello - Setting up a new install of Windows 10, when I attempt to join our domain active directory I get the message Joined to Azure AD, choose disconnect your device first. Researched how and the option to disconnect is not there. One person who also reported this same issue...