Browse Docs
-
Introduction
-
Deployment
- Deployment via RMM
- Operating System Agent
- Deployment via GPO
- Deployment via Intune
- VDI and Remote Desktop Services (RDS)
- Windows Manual Deployment
- Mac MDM Deployment
- Mac Manual Deployment
- Network Deployment
- Secure Mobile Browser
- Bypass Option
- SaaS Restrictions
- Bookmark Manager
- Remote Uninstall
- Bulk Create Customers
-
Management
-
Integrations
-
Nexi AI
-
Policy Management
-
Secure Access (ZTBA, formerly ZTNA)
-
Auto Pilot
-
Training Videos
-
Questions & Answers
-
MSP Automation
ONLINE DOCUMENTATION
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Domain checks in Trust ProfileIn this document
Domain checks ask who manages the computer. On Windows that means Active Directory membership and Microsoft Entra ID (formerly Azure AD) join. On macOS it means MDM enrollment. Use them to tell company-managed devices apart from personal ones.
Supported platforms: [Windows, macOS]
Active DirectoryWindows Machine Role
Checks the computer’s role with respect to an Active Directory domain:
Unlike the other Active Directory checks, this one answers on every Windows computer, because a computer outside a domain still has a role. Use it to require domain membership, for example equals MemberWorkstation. Windows AD Domain DNS Name
Compares the DNS name of the Active Directory domain the computer is joined to, for example This is the usual way to require joined to our domain. Windows AD Domain NETBIOS Name
Compares the short (NetBIOS) name of the domain. This is the part before the backslash in
Windows AD Domain GUID
Compares the unique identifier of the domain. A domain can be renamed but its GUID never changes, so this is the most precise way to identify our domain. Enter the GUID without braces. To find it, run Things to know for the Active Directory checks
Microsoft Entra ID
EntraID Join Type
To require company-owned devices, use equals Device. EntraID Device Joined Tenant ID
Checks that the computer is joined to a specific Entra ID tenant. This is a strict check. Computers that are only registered (join type Workplace) fail it, even when the account on them belongs to your tenant. You can find your Tenant ID in the Microsoft Entra admin center under Overview. On a computer, run macOSmacOS machine role
Checks whether the Mac is enrolled in an MDM. Type one of these two values:
To require MDM-managed Macs, use equals
MDMManaged covers every kind of MDM enrollment, including a user-approved enrollment that the user can remove. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||