SSO to on-premises resources with Azure AD Joined devices – Use AADJ unless you are certain you need Hybrid.
In this post I’ll take a closer look at how AADJ machines authenticated with an AD Synced identity can seamlessly access on-prem resources. This includes things like SMB file shares or other applications that require AD USER authentication. It’s important to remember if you have services utilizing machine authentication, those devices will need to remain AD joined […]