Domain join installation and configuration

Read this section to learn the prerequisites and the tasks to install ODJ service to set up your environment to enroll Windows devices and join Active Directory domain or both Active Directory and Azure AD domain.

BigFix MCM supports Active Directory (AD) Domain Join and Hybrid Domain Join through Offline Domain Join (ODJ) service. This facilitates you to manage your Windows 10 and Windows 11 endpoints through both on-premises AD and Azure AD.

A domain join establishes a trust relationship between a computer running a Windows operating system and an Active Directory domain.

BigFix MCM provides the device management capabilities necessary for managing and securing the device. Azure Active Directory provides the identity management and authentication services.

ODJ service facilitates you to manage your Windows endpoints in the following ways:
  • To automatically deploy a huge number of Windows endpoints seamlessly without user intervention
  • To enable an Autopilot endpoint to connect with AD even when the endpoint is offline and there is no VPN connectivity while enrolling.
  • To enable users to join a Windows laptop to an AD domain without requiring any special privileges in AD.
  • To join computers to the domain when they first start up after an operating system installation without requiring additional restart to complete the domain join.
  • To manage Autopilot enrolled laptops to inherit existing policies through AD, including the certificate policy. This makes it possible for you to domain join Windows laptops as part of a policy group configuration.
Hybrid Domain Join
If you want to join your Azure AD joined Windows laptops to your AD DS domain, you can accomplish this by using the Offline Domain Join service. This is especially useful to perform Autopilot enrollments.
AD Domain Join
If you have an on-premises Active Directory Domain Services (AD DS) environment, and if you want your Windows laptops to join your AD DS domain on enrollment, you can do this by using the Offline Domain Join service. When you configure the environment for this, the Windows devices enrolled through the following enrollment methods automatically join the AD DS domain.