- Active Directory domain environment limitations
Arm-based Surface devices (including Snapdragon-based Surface Pro models) run Windows 11 and participate in enterprise environments similarly to x64 devices. The context does not document any AD domain join–specific limitations for Arm-based Surface devices. Devices can be joined to Active Directory or Microsoft Entra ID, including hybrid join, and then managed with standard enterprise tools.
- Group Policy, domain authentication, SMB, and management
The provided guidance for Arm-based Surface devices focuses on app/driver compatibility rather than core Windows features. There are no documented issues in the context with:
- Domain authentication
- Group Policy processing
- SMB file sharing
Enterprise management is supported via:
- Microsoft Intune with Device Firmware Configuration Interface (DFCI) for firmware-level control on Arm-based Surface devices
- Management via Microsoft Entra ID and Intune, or co-management with Configuration Manager (using the 32-bit x86 ConfigMgr client)
See “Deploy, manage, and service Arm-based Surface devices” for details on Intune, Entra ID, co-management, and DFCI.
- Printer drivers and enterprise print management
For Arm-based Windows 11 devices, printer and scanner support depends on driver availability:
- Drivers must be designed for Arm-based devices, or be built into Windows.
- Peripheral compatibility (including printers and scanners) depends on Arm64 drivers provided by the hardware vendor or included in Windows.
- If the hardware developer does not provide Arm64 drivers, functionality may be limited. In such cases, installing the printer via Windows’ built-in mechanisms may still provide basic functionality. See “Install a printer in Windows” in the referenced FAQ.
The context does not list specific enterprise print-management products, but any solution that depends on custom kernel-mode or user-mode drivers must have Arm64-compatible components to be fully supported.
- Categories of software with potential compatibility limitations
The documentation highlights several software categories that may have limitations on Arm-based Surface devices:
- Drivers and hardware-dependent apps: Any app that relies on drivers must have Arm64-compatible drivers.
- Certain games: Titles that require OpenGL > 3.3 or anti-cheat drivers not updated for Arm may not work.
- Customization and shell-modifying apps: Input Method Editors (IMEs), cloud storage sync clients, and other apps that modify the Windows experience may have limited functionality unless optimized for Arm64.
- Antivirus/endpoint security: Many non-Microsoft antivirus products now support Arm-based PCs, but compatibility must be confirmed with the vendor. Some non-Microsoft antivirus software cannot be installed on Arm-based processors.
- Windows Fax and Scan: Not available on Arm-based devices.
More generally, the app-compat guidance for Windows on Arm notes:
- Most x86 Win32 apps are supported via emulation.
- Native Arm64 and Microsoft Store UWP apps provide the best performance and battery life.
- x64 emulation in Windows 11 significantly broadens app compatibility.
- Apps that do not meet these criteria should be checked with the publisher for an Arm64 version.
Microsoft also points to an evolving third-party list of compatible apps and games at www.worksonwoa.com.
- Enterprise deployment considerations and best practices
Key considerations and recommendations for deploying Arm-based Surface devices in enterprise environments include:
- App compatibility and testing
- Most x86 Win32 apps and many x64 apps run via emulation; however, any app that installs drivers, low-level security components, or shell extensions should be validated for Arm64 support.
- Use native Arm64 versions of apps where available (for example, Microsoft 365 Apps, Microsoft Teams, Adobe Photoshop/Lightroom, Microsoft Edge, and other Arm64-optimized software) for best performance and battery life.
- For apps with issues, commercial customers can use the App Assure program (part of Microsoft FastTrack) at no extra cost to help remediate compatibility problems for Windows 10/11 on Arm.
- Management and security
- Manage Arm-based Surface devices with Intune and DFCI for firmware-level control, just as with other Surface devices.
- Integrate with Microsoft Entra ID for cloud-based management and policy enforcement.
- Co-manage with Configuration Manager using the 32-bit x86 ConfigMgr client where required.
- Microsoft Defender is fully supported and protects Windows 10/11 on Arm-based PCs throughout the device lifecycle. Non-Microsoft AV/EDR solutions must be validated with the vendor for Arm64 support.
- Virtual desktops and remote workloads
- Azure Virtual Desktop is supported and can be used to deliver Windows desktops and apps to Arm-based Surface devices, which can be useful when specific line-of-business apps or tools are not yet Arm64-compatible.
- General platform characteristics
- Arm-based Surface devices (e.g., Surface Pro 11th Edition and Surface Laptop 7th Edition with Snapdragon X series) are positioned for strong performance, excellent battery life, and high compatibility with both native and emulated apps.
- Prism, the emulation engine, optimizes x86/x64 app performance and reduces CPU usage, helping emulated apps perform on par with or better than older x64 Surface models.
For any specific third-party products in the environment (Trend Micro endpoint/XDR, ManageEngine ServiceDesk Plus, print management solutions), the vendor’s documentation should be checked for Windows 11 on Arm/Arm64 support, especially for components that install drivers, kernel hooks, or low-level agents.
References: