BYOD Windows Access with Entra-Registered Devices

Users can now reach internal apps from their own Windows machines via Entra registration and the Private Application traffic profile — no domain join, no full management, just registered-device trust.

What's new — a short, independent summary. Read Microsoft's original: Microsoft Learn →

BYOD on Windows has always been the awkward middle. Phones got mobile app management years ago; personal Windows machines were stuck with a binary choice — fully enrol the user’s own laptop (they hate it, rightly) or don’t let them near internal apps at all. Entra-registered BYOD support closes that gap without either extreme.

The model

Instead of enrolling the device, the user Entra-registers their own Windows machine, and you assign the Private Application traffic profile through Global Secure Access. That profile lets internal accounts — including internal guests — reach specific private apps from the registered device, without domain join and without full MDM enrolment. The trust is anchored in the registered device and the user’s identity, not in you owning the whole machine.

Why it’s the right shape

The old requirement that a Windows device be domain-joined to touch internal resources doesn’t fit a workforce that’s half on personal kit. Registration is a much lighter contract: the user keeps their machine, you get an identity-and-device signal you can gate on, and access is scoped to the private apps you publish rather than the whole network.

For contractors, partners, and “I just need to hit this one internal tool from my own laptop” scenarios, this is the piece that was missing — enough trust to grant access, not so much that nobody wants to opt in.

Source: Microsoft Learn. Summarised independently — check the source for the latest detail.