Forum Discussion
From Azure AD Registered devices to Hybrid Azure AD joined
- RuJul 12, 2019MVP
JonasBack Just wanted to say thank you for this clarification as I am about to do this for my environment to prepare for an upgrade from O365 (with AD registered devices but not AAD Connect synced) to M365 (with hybrid join and AAD Connect synced). The documentation from Microsoft here says
If your Windows 10 domain joined devices are already Azure AD registered to your tenant, we highly recommend removing that state before enabling Hybrid Azure AD join.
without really explaining the result of not doing this. If the only consequence of this is a doubling up, that's no problem; we'll just delete the redunant ones from AAD via the Azure Portal.
- JonasBackAug 15, 2019Iron Contributor
Ru We have seen strange behaviors when running a device both Azure AD registered + Hybrid Azure AD joined at the same time when it comes to Conditional Access. For example if we set a rule in Conditional Access NOT to force MFA for Hybrid Azure AD joined it will still sometimes ask for MFA if the device is both.
So I still recommend making sure you don't end up there. Only way we found effective (without manual work on every client) - make sure to update them to 1809+ before starting.
- symm_adrianSep 27, 2019Brass Contributor
I'm trying to work through this today. I've set a GPO to set the SCP as I'm attempting a controlled setup against one machine. However, when sync the OU with the computer and the GPO is applied, the machine doesn't appear to do anything and the state of the machine doesn't change from Azure AD Registered to Hybrid Azure AD Joined. Any ideas?