Forum Discussion
Question regarding Hybrid Azure AD join and policy
Hi,
I got a question regarding Hybrid Azure AD Joined and policies assigned to UPNs.
I read that "Hybrid Azure AD joined Windows 10 devices don't have an owner." from Microsoft Docs.
I have several compliance and profiles configured which are assigned to a group. I always add the UPNs as members of these groups, to receive the policies to have full control of every policy. and what each user is receiving.
This works perfect with all my azure ad joined devices. Haven't tried the Hybrid Azure AD joined computers yet since I haven't enabled the UPNs which are cloud only at the ,yet to be AD synced.
My question is, since Hybrid Azure AD joined devices won't have a owner. Will the Hybrid Azure AD joined device still receive the policies and apps if I add the user to the group the policies are assigned to, once the computers are hybrid joined and users are AD synced?
Or is the only option to assign it to "all devices"? 😕
Thanks for your help
- Hi,
Owner is something else than the (primary) user of the device 🙂 . Should otherwise be weird that azure hybrid devices couldn't be managed with Intune 🙂
- Hi,
Looking at the screenshot you have hybrid enrolled devices into azure ad, but the Intune MDM is missing... no mdm --> no compliance
Please read these 2 blogs
https://call4cloud.nl/2021/08/the-battle-between-aadj-and-aadr/
https://call4cloud.nl/2021/08/the-death-of-compliance/
And did you configured this gpo like mentioned in this ms docs?
https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy- FreppyCopper ContributorThanks for you answer.
It was actually only a example screenshot I got from google. Not the tenant which I am setting up.
To answer your question regarding the GPO. I got brand new machines only, which are not domain joined at the moment, which I will do manually.- Hi,
Ahhh okay.. 🙂 Normally with hybrid and you configured intune, you will receive the apps and policies you configured in intune.. But maybe a stupid question... why do you want to go hybrid?