azureblog.co.uk
← cd ~/posts

BYOD Windows access with Entra registration is now GA

Users, partners and internal guests can now reach corporate resources from personal Windows devices using Entra registration, without joining them to anything.

2 min read✓ checked 15 Jul 2026Entra ID · Windows · What's new
On this page
  1. Registered, not joined
  2. Controlling what personal devices can do
  3. A sensible policy set
  4. Registering a device
  5. Questions users ask

Personal Windows PCs have always been awkward. You don't want to join them to your directory, but users still need a supported way to reach email, Teams and web apps. Support for BYOD Windows devices using Entra registration is now generally available. It covers users, partners and internal guests.

Entra registered

personal devices

  • User adds a work account
  • User owns and controls the device
  • Light-touch identity for Conditional Access

Entra joined

corporate cloud devices

  • Organisation owns the device
  • Sign in with work account
  • Fully managed with Intune

Hybrid joined

corporate AD devices

  • Joined to on-premises AD
  • Also registered in Entra
  • Managed by GPO and/or Intune
The three ways a Windows device relates to Entra ID.

Registered, not joined

  • Entra joined devices are corporate machines whose identity belongs to your organisation.
  • Entra registered devices are personal machines where the user adds a work account. The device gets an identity in your tenant, but the user keeps control of it.

Controlling what personal devices can do

Registration on its own isn't a security control. Pair it with :

  • Allow browser-only access to sensitive apps from unmanaged devices, using app-enforced restrictions in SharePoint and Exchange to block downloads.
  • Require from personal devices.
  • Use Intune app protection policies, or Edge for Business protections, to keep corporate data inside managed apps.
Plan for offboarding: when someone leaves, revoke their sessions and remove the registered device. Personal devices don't come back to IT.

A sensible policy set

What is the user trying to open?
Email and Teams in the browserAllow, with phishing-resistant MFA
SharePoint filesBrowser only, downloads blocked
Admin portals or sensitive appsBlock: managed devices only
Access from a personal Windows device.

Registering a device

  1. On the personal PC, open Settings → Accounts → Access work or school and select Connect.
  2. Sign in with the work account and complete MFA.
  3. The device appears in Entra under the user's devices as registered.

Make sure users know they can remove the work account from the same screen, and that IT can't see their personal files.

Questions users ask

Can IT see my personal files or browsing?

No. Registration gives the device an identity for sign-in. Without Intune enrolment, IT can't see or manage your files, apps or settings.

Can IT wipe my PC?

Not from registration alone. If app protection is used, IT can remove company data from managed apps, not your personal data.

How do I remove my work account?

Settings → Accounts → Access work or school, select the account and choose Disconnect.

Putting these answers in your onboarding guide removes most of the hesitation users have about connecting a personal PC.

Next in Shrinking hybrid identity · part 5 of 5Cross-tenant group sync is GA: one group, many tenants →