Home

Intune - Hybrid Active Directory with Autopilot

%3CLINGO-SUB%20id%3D%22lingo-sub-312958%22%20slang%3D%22en-US%22%3EIntune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-312958%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20started%20to%20make%20some%20tests%20on%20Intune%2C%20but%20I%20had%20some%20struggles%20to%20register%20machines%20and%20also%20to%20understand%20some%20what%20the%20system%20does%20in%20background.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20follow%20the%20steps%20from%20Microsoft%20page%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Fintune%2Fwindows-autopilot-hybrid%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3ELink%3C%2FA%3E)%20and%20I%20think%20there%20is%20everything%20setup%20correctly.%20I%20choose%20this%20method%20because%20we%20have%20Active%20Directory%20on-premise%20that%20is%20synchronize%20with%20Azure%20AD%2C%20so%20this%20is%20an%20Hybrid%20Active%20Directory.%3C%2FP%3E%3CP%3EAlso%20I%20setup%20Intune%20connector%20to%20synchronize%20all%20machines%20that%20we%20had%20register%20on%20our%20Active%20Directory%20(on-premise)%20and%20after%20that%20I%20was%20able%20to%20see%20all%20my%20machines.%3C%2FP%3E%3CP%3EMy%20first%20doubt%20is%20something%20related%20with%20this%20(probably).%20Once%20we've%20our%20machines%20register%20in%20our%20Active%20Directory%20(on-premise)%20and%20they%20are%20synchronized%20with%20Azure%20AD%2C%20why%20do%20I%20need%20to%20create%20a%20Organization%20Unit%20(OU)%20in%20our%20Active%20Directory%20(on-premise)%20with%20Delegation%20Control%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnother%20question%20that%20I%20have%20is%20about%20Autopilot%20Deployment.%20I%20run%20the%20script%20%22Get-WindowsAutoPilotInfo%22%20on%20my%20machine%20to%20import%20it%20on%20Intune%20AutoPilot%20(that%20was%20imported%20successfully)%20after%20the%20import%20I%20check%20the%20Azure%20devices%20and%20my%20machine%20was%20duplicated%2C%20as%20you%20can%20see%20on%20the%20screenshoot%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F65730iCF46C4FCAB2379B6%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Screenshoot1.jpg%22%20title%3D%22Screenshoot1.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EThe%20differences%20on%20the%20screenshoot%20is%20the%20%22Hybrid%20Azure%20AD%20Joined%22%20that%20is%20the%20synchronization%20from%20Intune%20connector%20and%20the%20%22Azure%20AD%20Joined%22%20is%20from%20AutoPilot%20import.%20I%20supose%20that%20second%20register%20is%20because%20I%20created%20a%20Device%20Configuration%20Profile%20(like%20as%20said%20on%20the%20link%20that%20I%20follow)%2C%20see%20the%20screenshoot%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F65731iFD6278F3AC7B2B8F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Screenshoot2.jpg%22%20title%3D%22Screenshoot2.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EDo%20I%20really%20need%20this%20profile%2C%20once%20I%20already%20have%20the%20machine%20registered%20on%20Azure%20AD%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-312958%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-328387%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-328387%22%20slang%3D%22en-US%22%3EBrilliant%20thank%20you%2C%20yes%20that%20exact%20issue.%20Again%20I%20only%20see%20this%20with%20AutoPilot%20Hybrid%20Join%20not%20Hybrid%20Join%20in%20general.%20I%20have%20several%20customers%20with%20Hybrid%20Join%20with%20no%20issues%20at%20all.%20I%20see%20this%20issue%20with%20Bulk%20Enrollment%2C%20Intune%20Deployment%20Enrollment%20Manager%2C%20Windows%20Configuration%20Designer%20and%20now%20AutoPilot%20Hybrid%20Join.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-328384%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-328384%22%20slang%3D%22en-US%22%3EHi%20Frank%2C%20can%20I%20just%20confirm%20I%20am%20not%20stating%20it%20isn%E2%80%99t%20supported%2C%20I%20am%20stating%20that%20MICROSOFT%20Intune%20support%20responded%20and%20said%20that%20Autopilot%20Hybrid%20Join%20does%20not%20yet%20support%20Federation.%20Both%20those%20links%20you%20sent%20are%20for%20hybrid%20join%20which%20is%20very%20much%20supported%20with%20Federation%2C%20neither%20of%20those%20links%20are%20for%20the%20Preview%20Intune%20for%20Active%20Directory%20connector%20which%20this%20discussion%20is%20about.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-328381%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-328381%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20mean%20that%20problem%3F%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FIntune-Customer-Success%2FSupport-Tip-Enrolled-Windows-10-devices-not-able-to-use-the-CP%2Fba-p%2F325399%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FIntune-Customer-Success%2FSupport-Tip-Enrolled-Windows-10-devices-not-able-to-use-the-CP%2Fba-p%2F325399%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20I%20am%20encountering%20this%20issue%20for%20a%20few%20days%20now.%20I%20contacted%20MS%20Support%20they%20are%20working%20on%20it%2C%20but%20they%20did%20not%20tell%20me%20it%20is%20an%20ADFS%2FHybrid%20AAD%20issue.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-328375%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-328375%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20worked%20with%20quite%20a%20few%20customers%20using%20federation%20and%20it%20is%20very%20much%20supported%20for%20ADFS%20found%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-federated-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E%20and%203rd%20party%20federation%20(depending%20on%203rd%20party%20support)%20found%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-manual%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-328258%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-328258%22%20slang%3D%22en-US%22%3Eit%20isn't%20in%20the%20documentation%2C%20it%20isn't%20stated%20anywhere%20as%20far%20as%20I%20can%20tell.%20I%20got%20that%20information%20directly%20from%20Intune%20support%2C%20which%20is%20what%20I%20had%20copied%20previously%20in%20this%20thread.%20With%20the%20two%20computer%20object%20accounts%20the%20issue%20was%20more%20to%20do%20with%20the%20user%20trying%20to%20sign%20into%20the%20Company%20Portal%20on%20their%20device.%20It%20says%20their%20device%20isn't%20connected%20yet%20when%20they%20try%20to%20connect%20they%20receive%20and%20error%20that%20the%20device%20is%20already%20being%20managed.%20Do%20you%20have%20that%20problem%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-327777%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-327777%22%20slang%3D%22en-US%22%3EWe%20have%202%20objects%20too%2C%20but%20everything%20else%20works%20fine.%20I%20deleted%20a%20device%20Azure%20AD%20registered%20object%2C%20kept%20the%20hybrid%20azure%20ad%20one%20and%20everything%20is%20still%20ok.%3CBR%20%2F%3EI%20can%E2%80%99t%20find%20any%20documentation%20stating%20that%20it%20is%20not%20supported%2C%20could%20you%20please%20send%20me%20a%20link%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-326158%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-326158%22%20slang%3D%22en-US%22%3EHi%20I%20did%20open%20a%20ticket%20and%20that%20was%20the%20response%20which%20as%20the%20client%20does%20have%20a%20federated%20domain%20means%20it%20is%20technically%20unsupported%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-326157%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-326157%22%20slang%3D%22en-US%22%3EWell%20I%E2%80%99d%20be%20very%20interested%20to%20know%20your%20setup%20and%20autopilot%20process.%20The%20official%20word%20from%20support%20is%20that%20federated%20environments%20are%20not%20yet%20supported.%20We%20always%20end%20up%20with%20two%20computer%20objects%20in%20Azure%20AD%20one%20hybrid%20joined%20and%20one%20Azure%20ad%20joined%20which%20causes%20many%20issues.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-326049%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-326049%22%20slang%3D%22en-US%22%3E%3CP%3EMy%20Company%20has%20a%20federated%20domain%2C%20ADFS%20configured%20in%20Azure%20AD%20Connect%20and%20uses%20Windows%20Autopilot%20Hybrid%20Azure%20AD%20join%20without%20issue%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-321680%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-321680%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F28468%22%20target%3D%22_blank%22%3E%40Christian%20Redgewell%3C%2FA%3E%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20recommend%20you%20to%20open%20a%20ticket%20with%20Microsoft%20(Microsoft%20Intune%20-%26gt%3B%20Help%20and%20support%20menu).%3CBR%20%2F%3EFor%20some%20reason%20my%20devices%20cannot%20get%20the%20profiles%20or%20policies%20that%20I%20set.%20Microsoft%20technician%20will%20analyze%20my%20issue%20with%20the%20enrollment%20and%20soon%20I'll%20have%20some%20feedback.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-319717%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-319717%22%20slang%3D%22en-US%22%3E%3CP%3Ethis%20is%20the%20message%20I%20received%20from%20Intune%20Support%20As%20you%20requested%2C%20below%20are%20the%20details%20regarding%20the%20process%20of%20setting%20up%20Hybrid%20Azure%20AD%20join%20support%20for%20Autopilot%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPre-requisites%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Intune%201810%3C%2FP%3E%3CP%3E2.%20Windows%2010%20with%20October%202018%20update%3C%2FP%3E%3CP%3E3.%20Successfully%20configure%20Hybrid%20Azure%20Active%20Directory%20Join%20for%20Managed%20Domains%3C%2FP%3E%3CP%3E4.%20Federated%20domains%20are%20not%20supported%20at%20this%20time%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-319589%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-319589%22%20slang%3D%22en-US%22%3EMy%20environment%20is%20not%20using%20ADFS.%20Where%20did%20you%20get%20that%20information%3F%3CBR%20%2F%3ECan%20you%20share%20it%3F%3CBR%20%2F%3EThank%20you%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-319173%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-319173%22%20slang%3D%22en-US%22%3Eis%20your%20environment%20using%20ADFS%3F%20I%20have%20just%20discovered%20that%20this%20is%20not%20supported%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-314929%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20-%20Hybrid%20Active%20Directory%20with%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-314929%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20this%20exact%20same%20issue%2C%20the%20device%20joins%20local%20AD%2C%20reboots%20I%20sign%20in%2C%20the%20device%20joins%20Azure%20AD%20and%20I%20end%20up%20with%20two%20devices%20in%20Azure%20AD.%20One%20shows%20as%20Azure%20AD%20and%20the%20other%20as%20Hybrid%20Azure%20Joined.%20I%20also%20noticed%20that%20the%20Company%20Portal%20fails%20to%20recognise%20the%20device%20is%20joined%20and%20the%20user%20is%20not%20shown%20as%20the%20owner%20in%20Azure%20AD.%3C%2FP%3E%3C%2FLINGO-BODY%3E
tru_ldourado
New Contributor

Hi,

 

I'm started to make some tests on Intune, but I had some struggles to register machines and also to understand some what the system does in background.

 

I follow the steps from Microsoft page (Link) and I think there is everything setup correctly. I choose this method because we have Active Directory on-premise that is synchronize with Azure AD, so this is an Hybrid Active Directory.

Also I setup Intune connector to synchronize all machines that we had register on our Active Directory (on-premise) and after that I was able to see all my machines.

My first doubt is something related with this (probably). Once we've our machines register in our Active Directory (on-premise) and they are synchronized with Azure AD, why do I need to create a Organization Unit (OU) in our Active Directory (on-premise) with Delegation Control?

 

Another question that I have is about Autopilot Deployment. I run the script "Get-WindowsAutoPilotInfo" on my machine to import it on Intune AutoPilot (that was imported successfully) after the import I check the Azure devices and my machine was duplicated, as you can see on the screenshoot:

Screenshoot1.jpg

The differences on the screenshoot is the "Hybrid Azure AD Joined" that is the synchronization from Intune connector and the "Azure AD Joined" is from AutoPilot import. I supose that second register is because I created a Device Configuration Profile (like as said on the link that I follow), see the screenshoot:

Screenshoot2.jpg

Do I really need this profile, once I already have the machine registered on Azure AD?

 

Thank you.

14 Replies

I have this exact same issue, the device joins local AD, reboots I sign in, the device joins Azure AD and I end up with two devices in Azure AD. One shows as Azure AD and the other as Hybrid Azure Joined. I also noticed that the Company Portal fails to recognise the device is joined and the user is not shown as the owner in Azure AD.

is your environment using ADFS? I have just discovered that this is not supported
My environment is not using ADFS. Where did you get that information?
Can you share it?
Thank you

this is the message I received from Intune Support As you requested, below are the details regarding the process of setting up Hybrid Azure AD join support for Autopilot: 

 

Pre-requisites:

 

1. Intune 1810

2. Windows 10 with October 2018 update

3. Successfully configure Hybrid Azure Active Directory Join for Managed Domains

4. Federated domains are not supported at this time

Hi @Christian Redgewell,

I recommend you to open a ticket with Microsoft (Microsoft Intune -> Help and support menu).
For some reason my devices cannot get the profiles or policies that I set. Microsoft technician will analyze my issue with the enrollment and soon I'll have some feedback.

My Company has a federated domain, ADFS configured in Azure AD Connect and uses Windows Autopilot Hybrid Azure AD join without issue

Well I’d be very interested to know your setup and autopilot process. The official word from support is that federated environments are not yet supported. We always end up with two computer objects in Azure AD one hybrid joined and one Azure ad joined which causes many issues.
Hi I did open a ticket and that was the response which as the client does have a federated domain means it is technically unsupported
We have 2 objects too, but everything else works fine. I deleted a device Azure AD registered object, kept the hybrid azure ad one and everything is still ok.
I can’t find any documentation stating that it is not supported, could you please send me a link?
it isn't in the documentation, it isn't stated anywhere as far as I can tell. I got that information directly from Intune support, which is what I had copied previously in this thread. With the two computer object accounts the issue was more to do with the user trying to sign into the Company Portal on their device. It says their device isn't connected yet when they try to connect they receive and error that the device is already being managed. Do you have that problem?

I have worked with quite a few customers using federation and it is very much supported for ADFS found here and 3rd party federation (depending on 3rd party support) found here.

You mean that problem?

https://techcommunity.microsoft.com/t5/Intune-Customer-Success/Support-Tip-Enrolled-Windows-10-devic...

 

Yes I am encountering this issue for a few days now. I contacted MS Support they are working on it, but they did not tell me it is an ADFS/Hybrid AAD issue.

Hi Frank, can I just confirm I am not stating it isn’t supported, I am stating that MICROSOFT Intune support responded and said that Autopilot Hybrid Join does not yet support Federation. Both those links you sent are for hybrid join which is very much supported with Federation, neither of those links are for the Preview Intune for Active Directory connector which this discussion is about.
Brilliant thank you, yes that exact issue. Again I only see this with AutoPilot Hybrid Join not Hybrid Join in general. I have several customers with Hybrid Join with no issues at all. I see this issue with Bulk Enrollment, Intune Deployment Enrollment Manager, Windows Configuration Designer and now AutoPilot Hybrid Join.
Related Conversations
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies