MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.24k stars 21.41k forks source link

Clarify ADFS client-side Implications in Note #93361

Open jeffjfield opened 2 years ago

jeffjfield commented 2 years ago

Under "Configure AD FS Settings" there is a note which says:

"If you failed to configure client-side SCP on your AD FS servers, the source for device identities would be considered as on-premises. ADFS will then start deleting device objects from on-premises directory after the stipulated period defined in the ADFS Device Registration's attribute "MaximumInactiveDays". "

Does that mean that device objects would be deleted from just the OU that the GPO configuring the client-side registry setting is linked to for the targeted deployment or would it start deleting all computer objects in the on-premises AD?

Thanks in advance!


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

JamesTran-MSFT commented 2 years ago

@jeffjfield Thanks for your feedback! We will investigate and update as appropriate.