Convert Hybrid Azure AD Join Device to Azure AD Join Only

%3CLINGO-SUB%20id%3D%22lingo-sub-2107335%22%20slang%3D%22en-US%22%3EConvert%20Hybrid%20Azure%20AD%20Join%20Device%20to%20Azure%20AD%20Join%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2107335%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%2C%20We%20are%20in%20Hybrid%20state%20(%20SCCM%2B%20Intune%20%3DCoManaged%20)%20and%20Hybrid%20Azure%20AD%20Join%20.%20Now%20as%20next%20step%20moving%20to%20cloud%20only%20%2C%20We%20are%20moving%20device%20from%20Hybrid%20to%20Azure%20only%20State%20.%20While%20testing%20Manually%20remove%20a%20device%20from%26nbsp%3B%20AD%20domain%20post%20reboot%20noticed%20that%20not%20able%20to%20even%20login%20with%20Azure%20that%20means%20loose%20the%20complete%20state%20(%20AD%20as%20well%20as%26nbsp%3B%20Azure%20)%20%2C%20Login%20with%20Local%20account%20found%20with%20DSREGCMD%20that%20device%20is%20not%20attached%20to%20any%20.%20If%20I%20just%20removed%20the%20AD%20domain%20why%20this%20has%20removed%20from%26nbsp%3B%20Azure%20AD%20Join%20as%20well%20.What%20is%20best%20way%20to%20Remove%20domain%20join%20but%26nbsp%3B%20keep%20Azure%20AD%20join%20%2C%20Loose%20Users%20settings%20as%20well.%3C%2FP%3E%3CP%3EThanks%20MSB%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2107504%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20Hybrid%20Azure%20AD%20Join%20Device%20to%20Azure%20AD%20Join%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2107504%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EAzure%20community%20and%20all%20of%20its%20sub%20communities%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure%2Fct-p%2FAzure%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure%2Fct-p%2FAzure%3C%2FA%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2110095%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20Hybrid%20Azure%20AD%20Join%20Device%20to%20Azure%20AD%20Join%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2110095%22%20slang%3D%22en-US%22%3EWhen%20you%20are%20in%20a%20hybrid%20state%2C%20computers%20are%20sync'ed.%3CBR%20%2F%3E%3CBR%20%2F%3EThat%20means%20that%20when%20you%20remove%20the%20AD%20computer%20on-prem%2C%20it's%20also%20removed%20in%20the%20cloud.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20want%20to%20change%20a%20PC%20from%20hybrid%20to%20AAD%2C%20you%20need%20to%20remove%20the%20device%20from%20AD%20and%20add%20it%20to%20add%20manually.%20This%20will%20remove%20the%20current%20AD%20profile%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2290893%22%20slang%3D%22en-US%22%3ERe%3A%20Convert%20Hybrid%20Azure%20AD%20Join%20Device%20to%20Azure%20AD%20Join%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2290893%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F453161%22%20target%3D%22_blank%22%3E%40MSBSKBMKB%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethat%20migration%20path%20simply%20does%20not%20exist%20...%20i%20am%20also%20exploring%20options%20for%20the%20same%20objective%3A%20migrating%20from%20hjaad%20to%20aad%20only%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethe%20only%20option%20you%20will%20find%20in%20official%20MS%20doc%20is%20to%20reset%20computer%2C%20preferably%20using%20autopilot%20-%20that%20will%20allow%20you%20to%20remove%20admin%20right%20if%20you%20need%20so.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Visitor

Hi , We are in Hybrid state ( SCCM+ Intune =CoManaged ) and Hybrid Azure AD Join . Now as next step moving to cloud only , We are moving device from Hybrid to Azure only State . While testing Manually remove a device from  AD domain post reboot noticed that not able to even login with Azure that means loose the complete state ( AD as well as  Azure ) , Login with Local account found with DSREGCMD that device is not attached to any . If I just removed the AD domain why this has removed from  Azure AD Join as well .What is best way to Remove domain join but  keep Azure AD join , Loose Users settings as well.

Thanks MSB

3 Replies
When you are in a hybrid state, computers are sync'ed.

That means that when you remove the AD computer on-prem, it's also removed in the cloud.

If you want to change a PC from hybrid to AAD, you need to remove the device from AD and add it to add manually. This will remove the current AD profile

@MSBSKBMKB 

 

that migration path simply does not exist ... i am also exploring options for the same objective: migrating from hjaad to aad only

 

the only option you will find in official MS doc is to reset computer, preferably using autopilot - that will allow you to remove admin right if you need so.