Skip to main content

Alternatives - Deployment/Enrollment with UPN - Based on Postman-SCIM - Users - Groups

Hello community, how's it going? Good afternoon, I hope you're all well.

 

I have a specific case to discuss:

In a scenario where we have a complete refusal to touch anything in Azure AD or AD-onprem (nothing at all, no way - no agent, no directory import, no enterprise app, no ID entry, etc., nothing at all, it's not possible because there's absolutely no option), here we already know, we use our beloved Postman to use SCIM and start generating users/groups, so to speak, "manually." Then we have the AD users with UPNs, everyone happy without touching AD but with the AD-onprem UPN users, already in the Tenant using the Postman SCIM API.

We can deploy with tools like System Center, DesktopCentral, or anything else for .msi files with UPN values. Everything's OK here too. We install, the Windows users of the AD domain start, and the UPN registration and enrollment are OK, as expected.

 

Now, here's my big question. Well, not so much a question, it just didn't affect me, but finally, my question is... for everything that involves computers outside the domain/not associated with the domain, AD not joining the domain, Windows outside the domain, macOS in the domain... Thinking about the process:

Installation and, above all, enrollment, the beloved enrollment... In this case, if I can't use an IDP (I can't use an IDP, I can't touch anything, not even with business applications, Azure AD, or anything else), what's left for me, guys?
I understand that manual installation with an invitation would be one of the few options left, right? Or is there a way to do an MSI install and, above all, a parameterized enrollment... manual registration "without an IDP"? Understanding that this is all about everything outside the domain, an endpoint completely outside the AD domain…

 

Resigned, documentation revisited... but does anyone have any ideas, alternatives, solutions, or tips for this curious scenario?

 

Thank you all in advance for reading, thank you for your comments, your collaboration, your time, and above all, your good vibes.

Excuse me for referring to you directly. Thank you for your time and collaboration:

@munster ​@jschuele  ​@hagi  ​@nduda ​@secproceo ​@elawaetz ​@wilson  ​@Rohit_Bhaskar  ​@Mandeep Singh   ​@sshiflett   ​@Aaron_Zhang ​@ejang ​@shyman 

I remain attentive.

Best regards.

Be the first to reply!

Reply