ASD's Blueprint for Secure Cloud

Device settings

This page describes the configuration of device settings within Microsoft Entra ID associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 2 minutes

Microsoft Entra join and registration settings

ItemValue
Users may join devices to Microsoft EntraAll
Users may register their devices with Microsoft EntraAll
Require Multifactor Authentication to register or join devices with Microsoft EntraNo
Maximum number of devices per userUnlimited

Local administrator settings

ItemValue
Global administrator role is added as local administrator on the device during Microsoft Entra join (Preview)No
Registering user is added as local administrator on the device during Microsoft Entra join (Preview)None
Enable Microsoft Entra Local Administrator Password Solution (LAPS)Yes

Other settings

ItemValue
Restrict users from recovering the BitLocker key(s) for their owned devicesNo

Security & Governance

Design

Configuration

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra