Home
%3CLINGO-SUB%20id%3D%22lingo-sub-730408%22%20slang%3D%22en-US%22%3EWindows%20Autopilot%20for%20existing%20devices%20now%20supports%20Hybrid%20Azure%20AD%20Join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-730408%22%20slang%3D%22en-US%22%3E%3CP%3EFirst%2C%20a%20quick%20refresher%20on%20Windows%20Autopilot%20for%20existing%20devices%3A%26nbsp%3B%20For%20customers%20looking%20for%20a%20path%20to%20migrate%20from%20Windows%207%20(or%208.1)%20to%20Windows%2010%20using%20Windows%20Autopilot%2C%20the%20challenge%20was%20always%20that%20you%20had%20to%20register%20the%20existing%20machines%20with%20Windows%20Autopilot%20in%20advance%2C%20but%20doing%20so%20was%20impossible%20because%20you%20couldn't%20grab%20the%20hardware%20hash%20from%20a%20device%20running%20Windows%207.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FNew-Windows-Autopilot-capabilities-and-expanded-partner-support%2Fba-p%2F260430%22%20target%3D%22_blank%22%3Ewe%20added%20the%20ability%20in%20Windows%2010%2C%20version%201809%3C%2FA%3E%20to%20use%20a%20JSON%20file%20containing%20the%20equivalent%20of%20the%20Windows%20Autopilot%20profile%20so%20that%20you%20didn't%20have%20to%20register%20the%20device%20in%20advance%3B%20you%20could%20then%20tell%20Microsoft%20Intune%20to%20harvest%20the%20hash%20from%20the%20device%20later%20and%20register%20the%20device%20after%20the%20fact.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20solution%20worked%20great%20and%20has%20been%20leveraged%20by%20a%20number%20of%20organizations%20to%20move%20from%20Windows%207%20and%20Active%20Directory%20to%20Windows%2010%20and%20Azure%20Active%20Directory%2C%20using%20Microsoft%20Intune%20(often%20with%20Configuration%20Manager%20for%20co-management)%20to%20deploy%20and%20manage%20the%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20some%20organizations%20weren't%20yet%20ready%20for%20Azure%20AD%20Join%20(even%20with%20the%20Administrative%20Templates%20support%20in%20Microsoft%20Intune%2C%20and%20full%20support%20for%20Kerberos%20authentication%20from%20an%20Azure%20AD-joined%20device%20to%20Active%20Directory-secured%20resources)%20and%20asked%20us%20to%20support%20this%20same%20process%2C%20but%20with%20Hybrid%20Azure%20AD%20Join.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fwhats-new%23device-enrollment%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20target%3D%22_blank%22%3Ethis%20month's%26nbsp%3BMicrosoft%20Intune%20updates%3C%2FA%3E%2C%20we%20can%20now%20support%20this.%20And%20no%20client%20changes%20are%20needed%3A%20this%20works%20with%20Windows%2010%2C%20version%201809%20and%20above.%20All%20you%20need%20to%20do%20is%20specify%20a%20JSON%20file%20that%20specifies%20to%20join%20Active%20Directory%20(via%20Hybrid%20Azure%20AD%20Join)%20instead%20of%20Azure%20Active%20Directory%20-%20the%20rest%20of%20the%20process%20(e.g.%20the%20Configuration%20Manager%20task%20sequence%20that%20deploys%20Windows%2010%20to%20the%20device)%20is%20unchanged.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENote%20that%20you%20will%20need%20to%20target%20a%20Domain%20Join%20profile%20(and%20any%20other%20device-targeted%20policies)%20to%20%22All%20devices%22%20since%20the%20device%20won't%20be%20known%20to%20Microsoft%20Intune%20in%20advance.%20(Don't%20worry%2C%20this%20Domain%20Join%20profile%20has%20no%20impact%20on%20already-deployed%20devices%2C%20as%20it's%20only%20used%20by%20Microsoft%20Intune%20to%20determine%20what%20domain%20and%20OU%20should%20be%20used%20when%20joining%20a%20device%20to%20Active%20Directory.)%26nbsp%3B%20See%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fwindows-autopilot%2Fexisting-devices%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20target%3D%22_blank%22%3Ethe%20updated%20documentation%3C%2FA%3E%20for%20more%20details.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-730408%22%20slang%3D%22en-US%22%3E%3CP%3ELearn%20about%20the%20new%20feature%20to%20help%20customers%20migrate%20from%20Windows%207%20to%20Windows%2010%20using%20Windows%20Autopilot.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-730408%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EWindows%20Autopilot%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-736061%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20for%20existing%20devices%20now%20supports%20Hybrid%20Azure%20AD%20Join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-736061%22%20slang%3D%22en-US%22%3E%3CP%3EWill%20this%20work%20on%26nbsp%3BAutopilot%20for%20white%20glove%20deployments%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-736592%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Autopilot%20for%20existing%20devices%20now%20supports%20Hybrid%20Azure%20AD%20Join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-736592%22%20slang%3D%22en-US%22%3E%3CP%3ENo%2C%20white%20glove%20deployments%20require%20registering%20the%20device.%26nbsp%3B%20If%20you%20think%20about%20it%2C%20using%20Windows%20Autopilot%20for%20existing%20devices%20is%20designed%20for%20a%20completely%20different%20scenario%3A%20an%20already-deployed%20device%20where%20the%20user%20is%20going%20to%20go%20through%20the%20process.%26nbsp%3B%20White%20glove%2C%20on%20the%20other%20hand%2C%20is%20for%20a%20technician-driven%20process%20for%20new%20machines%20before%20they%20are%20given%20to%20the%20user.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

First, a quick refresher on Windows Autopilot for existing devices:  For customers looking for a path to migrate from Windows 7 (or 8.1) to Windows 10 using Windows Autopilot, the challenge was always that you had to register the existing machines with Windows Autopilot in advance, but doing so was impossible because you couldn't grab the hardware hash from a device running Windows 7. 

 

So, we added the ability in Windows 10, version 1809 to use a JSON file containing the equivalent of the Windows Autopilot profile so that you didn't have to register the device in advance; you could then tell Microsoft Intune to harvest the hash from the device later and register the device after the fact.

 

This solution worked great and has been leveraged by a number of organizations to move from Windows 7 and Active Directory to Windows 10 and Azure Active Directory, using Microsoft Intune (often with Configuration Manager for co-management) to deploy and manage the device.

 

But some organizations weren't yet ready for Azure AD Join (even with the Administrative Templates support in Microsoft Intune, and full support for Kerberos authentication from an Azure AD-joined device to Active Directory-secured resources) and asked us to support this same process, but with Hybrid Azure AD Join.

 

With this month's Microsoft Intune updates, we can now support this. And no client changes are needed: this works with Windows 10, version 1809 and above. All you need to do is specify a JSON file that specifies to join Active Directory (via Hybrid Azure AD Join) instead of Azure Active Directory - the rest of the process (e.g. the Configuration Manager task sequence that deploys Windows 10 to the device) is unchanged.

 

Note that you will need to target a Domain Join profile (and any other device-targeted policies) to "All devices" since the device won't be known to Microsoft Intune in advance. (Don't worry, this Domain Join profile has no impact on already-deployed devices, as it's only used by Microsoft Intune to determine what domain and OU should be used when joining a device to Active Directory.)  See the updated documentation for more details.

2 Comments
Senior Member

Will this work on Autopilot for white glove deployments?

Microsoft

No, white glove deployments require registering the device.  If you think about it, using Windows Autopilot for existing devices is designed for a completely different scenario: an already-deployed device where the user is going to go through the process.  White glove, on the other hand, is for a technician-driven process for new machines before they are given to the user.