Step reference
Domain join
Join the device to an on-premises Active Directory domain, with the service credential resolved from the vault and never stored on the USB.
What it does
Joins the device to an on-premises Active Directory domain. The service-account credential used to perform the join is fetched from the vault at runtime and never written to the USB or the template. Domain join requires a restart, so this step triggers a reboot and the setup resumes automatically afterwards.
Options
| Option | What it controls |
|---|---|
| Domain (FQDN) | The fully-qualified domain name to join, e.g. corp.acme.local. Required. |
| OU path | Optional. Place the computer object in a specific organisational unit. |
| Service account password | The vault secret for the account permitted to join machines to the domain. Required. |
Good to know
- A reboot is part of the step. That's expected; the setup picks up where it left off once the machine is back.
- If the join fails, the setup stops by default.
Using Autopilot Hybrid Azure AD Join? Skip this step
Intune already performs the domain join through the Hybrid Join profile. This step is for clients who aren't using it.
Part of the step catalogue.
Related
Install Windows 11
True bare-metal Windows 11 install with the right OEM driver pack injected automatically. Wipes the target disk; runs only on the USB entry point.
OOBE configuration
Auto-answer the out-of-box screens (region, keyboard, device name, EULA, optional Wi-Fi) and optionally skip the account screen so the device lands ready, with no duplicate admin.
Language & region
Set the display language, keyboard layout, regional format, home location and timezone for the installed Windows and every new user. Autopilot-compatible.