I have a scenario where the client has no on-premises AD and wants to use Azure AD. Now my first question is, should I use one account like [email protected] to join all the computers to Azure AD and once joined get other users to login with their own email address?
Second question, So, here admin keeps the local admin account and newly signed in user cannot make changes without admin's email account?
Currently only [email protected] has global administrator rights in 365.
I couldn't get clear answer anywhere. Your help is much appreciated.
Yes, you could do that.
Yes, that is correct.
Have a read of this:
https://learn.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin