Windows 10: Using Teams in HyperV with Company domain

Discus and support Using Teams in HyperV with Company domain in Windows 10 Virtualization to solve the problem; I have a company laptop with Teams and obviously that works fine. However, I wanted to install Teams on my personal pc and decided to use a HyperV vm... Discussion in 'Windows 10 Virtualization' started by cereberus, Sep 2, 2020.

  1. cereberus Win User

    Using Teams in HyperV with Company domain


    I have a company laptop with Teams and obviously that works fine. However, I wanted to install Teams on my personal pc and decided to use a HyperV vm to run as it needs to use a company domain and that takes over control of certain aspects.

    In particular, it requires you to use a PIN of at least 6 digits.

    This is where I ran into a big issue with HyperV.

    I made a previous post about using HyperV with a PIN i.e. it will not use enhanced mode.

    I thought this was a bug but it turns out this is BY DESIGN.

    If you have a PIN, you can only use HyperV in BASIC mode which is no use for Teams as you do not get any audio!

    I really thought I was screwed i.e.to use Teams for company account, I would have to join domain and install it on host accepting restrictions which I really did not want to do.

    As it happens, my Company also accepts two factor account authentication for Teams but when you install and set it up, it asks you to join the domain and set pin, and then bitlocker whole drive.

    However, it also gives option NOT to join a domain and only sign into Teams. I tried this and it installs and it runs ok without need for PIN or bitlocker. I cannot access my company onedrive account directly as I have not joined a domain.

    However, I can still access company onedrive via MS Office 365 so no big deal just slightly less convenient. Strangely, 2FA is allowed Company for this with no need for PIN or bitlocker.

    So I now have a nice VM dedicated to work use without "polluting" my main PC.

    However, not being able to use HyperV and a PIN in enhanced mode is a PITA as I have to type in full password each time I run VM (and less secure in theory).

    :)
     
    cereberus, Sep 2, 2020
    #1
  2. cereberus Win User

    Using Teams in HyperV with Company domain

    I have a company laptop with Teams and obviously that works fine. However, I wanted to install Teams on my personal pc and decided to use a HyperV vm to run as it needs to use a company domain and that takes over control of certain aspects.

    In particular, it requires you to use a PIN of at least 6 digits.

    This is where I ran into a big issue with HyperV.

    I made a previous post about using HyperV with a PIN i.e. it will not use enhanced mode.

    I thought this was a bug but it turns out this is BY DESIGN.

    If you have a PIN, you can only use HyperV in BASIC mode which is no use for Teams as you do not get any audio!

    I really thought I was screwed i.e.to use Teams for company account, I would have to join domain and install it on host accepting restrictions which I really did not want to do.

    As it happens, my Company also accepts two factor account authentication for Teams but when you install and set it up, it asks you to join the domain and set pin, and then bitlocker whole drive.

    However, it also gives option NOT to join a domain and only sign into Teams. I tried this and it installs and it runs ok without need for PIN or bitlocker. I cannot access my company onedrive account directly as I have not joined a domain.

    However, I can still access company onedrive via MS Office 365 so no big deal just slightly less convenient. Strangely, 2FA is allowed Company for this with no need for PIN or bitlocker.

    So I now have a nice VM dedicated to work use without "polluting" my main PC.

    However, not being able to use HyperV and a PIN in enhanced mode is a PITA as I have to type in full password each time I run VM (and less secure in theory).
     
    cereberus, Sep 2, 2020
    #2
  3. ZenZimZaliben, Sep 2, 2020
    #3
  4. changari Win User

    Using Teams in HyperV with Company domain

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Sep 2, 2020
    #4
Thema:

Using Teams in HyperV with Company domain

Loading...
  1. Using Teams in HyperV with Company domain - Similar Threads - Using Teams HyperV

  2. How to remove a work account not connected to company's domain?

    in Windows 10 Gaming
    How to remove a work account not connected to company's domain?: I have been experiencing single sign on errors, and when I go to office.com or portal.office.com to sign in - I get the message that I have multiple accounts. I should only have one account connected to my company's domain; however that does not appear to be the case. The...
  3. How to remove a work account not connected to company's domain?

    in Windows 10 Software and Apps
    How to remove a work account not connected to company's domain?: I have been experiencing single sign on errors, and when I go to office.com or portal.office.com to sign in - I get the message that I have multiple accounts. I should only have one account connected to my company's domain; however that does not appear to be the case. The...
  4. Getting a Microsoft Account with a company domain mail

    in Windows 10 Gaming
    Getting a Microsoft Account with a company domain mail: Hello,We use Google Workspace as our mail provider with our company's domain. We are using local accounts as Windows accounts for our PCs. I want to switch to Microsoft Accounts to be used as Windows users, but the system rejects me creating it with our company's domain email...
  5. Getting a Microsoft Account with a company domain mail

    in Windows 10 Software and Apps
    Getting a Microsoft Account with a company domain mail: Hello,We use Google Workspace as our mail provider with our company's domain. We are using local accounts as Windows accounts for our PCs. I want to switch to Microsoft Accounts to be used as Windows users, but the system rejects me creating it with our company's domain email...
  6. Getting a Microsoft Account with a company domain mail

    in Windows Hello & Lockscreen
    Getting a Microsoft Account with a company domain mail: Hello,We use Google Workspace as our mail provider with our company's domain. We are using local accounts as Windows accounts for our PCs. I want to switch to Microsoft Accounts to be used as Windows users, but the system rejects me creating it with our company's domain email...
  7. Installing Company MS Teams in HyperV with Bitlocker

    in Windows 10 Virtualization
    Installing Company MS Teams in HyperV with Bitlocker: Here is a tip for those of you wanting to use MS Teams on your PC. Many companies expect you to join a domain when using MS Teams and then you give over control of aspects of your PC. My Company not only expects you to join a domain but also use Bitlocker. I was not prepared...
  8. Stuck at "Welcome" after logging into company domain?

    in Windows 10 Ask Insider
    Stuck at "Welcome" after logging into company domain?: Recently started having an influx of issues with newly imaged Win10 1903 setups, these are joined to a corporate domain and some of my users will get stuck at "Welcome" after entering their password to login. I've tried a number of things, but no profiles are able to log in...
  9. "my company uses a network without a domain" won't stick

    in Windows 10 Network and Sharing
    "my company uses a network without a domain" won't stick: We had our three computers connected together on Win 7. Upgraded all to Win 10 - two on Enterprise and one on Pro. Trying to get them set up with a workgroup without a domain but they won't share with each other. All are on ethernet on same network and all can ping each...
  10. Cannot connect to shared drive on company domain network.

    in Windows 10 Network and Sharing
    Cannot connect to shared drive on company domain network.: At my work, we are upgrading all computers from Windows 7 to Windows 10 (roughly about 12 computers total). So far 6 of them have been upgraded successfully with not network issues. There is a company domain in place. After upgrading the 7th computer, a Dell Latitude E6410,...