Forum Discussion
Device Migration from On-prem AD to Azure AD
Hello All,
We want to migrate our On-Prem AD devices to Azure AD and enroll into intune. We have Azure AD sync and all but needs to convert machine to Azure AD join only not Hybrid AD. So we would like to create new user profile on machine.
We have used two methods so far.
1) Reset the machine and use join to Azure AD from OOBE. ( Issue - This will make user a Administrator for that machine and we dont want that )
2) Unbind from on-prem AD, join to Azure AD manually but the same issue like number 1.
3) Using Hardware Hash, register devices to Autopilot and then reset all the machines. ( Issue - This will take too long to migrate 250 machines and helping remote workers are quite difficult )
Has anyone tried any different method or is there any expert suggestion ?
Thanks!
42 Replies
- AvinashGCopper Contributor
- DeyKilledKennyCopper Contributor
AvinashG Hey Avinash,
We have found out a work around to this.
While the machine is joined to a local domain domain1.com
To be able to enroll it in Intune MDM (without joining the doamin AzureCloud.com doamin).
You first have to remove any management tools for example (SCCM Client). Once that client is removed, you should be able to Enroll in Mobile Device management from Settings -> Accounts -> Access work or school. Under related settings, you will get an option to enroll in MDM, once you do it, it should be easy after that.
Hope this helps.
- CyxITNathanCopper Contributor
My company is attempting almost the exact same situation.... for 1800 devices.
Please, if anyone has a comprehensive strategy for this solution I'd appreciate it greatly.
My understanding developed from the linked articles is the steps for accomplishing this would be to:
1. create an AutoPilot profile which either acknowledges a present local administrator account or creates it when the device hits Azure2. create a Group which applies the required applications for my company
3. use the Bulk update to target my on-premises machines for moving to Azure (how do I make sure the devices i select for bulk autopilot are not flagged as "personal" in on-premises AD?)
4. Clear my on-premises record of devices after each device appears in Azure AD
5. Start a sync in Intune and allow it to push apps and add any missing administrator account based on the Group and Profile settings
Thank you for any clarifications available.- DeyKilledKennyCopper ContributorI'm in the same boat as you.
If anyone has a good approach to be able to join a machine to AzureAD while joined to local domain, that would be great!- Thijs LecomteBronze ContributorYou might be looking for hybrid Azure AD Join?
This way the device is joined to local AD and registered to AAD, which enables management through Intune
https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan
- JonasBackSteel ContributorWe use Autopilot to move computers over. But in general, we get them Azure AD joined/managed using Endpoint Manager whenever we replace the hardware and yes, this will take a long time if you don’t plan to replace computers within the next year or so. So sometimes we simply re-install computers.
If you have specific requirements of which users to set as local admin, we use this script: https://tech.xenit.se/add-you-own-local-admin-users-on-azure-ad-devices/- Amit_Trivedi112214Copper Contributor
JonasBack Thank you for your reply. We have almost 300 machines and would like to migrate by end of this year, so resetting machine/Auto Pilot will take more time and not efficient for us.
- JonasBackSteel ContributorI think you mean that you don’t want to reinstall (reset) every machine, correct?
Have not tried it but check the ”Bulk Enrollment” mentioned here: https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin