Migrating from Hybrid to pure Azure AD

%3CLINGO-SUB%20id%3D%22lingo-sub-1505903%22%20slang%3D%22en-US%22%3ERe%3A%20Migrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1505903%22%20slang%3D%22en-US%22%3EBiggest%20concern%20is%20if%20you%20have%20any%20on-prem%20servers%20(File%20shares%20%2F%20printers%20etc.)%20that%20would%20still%20need%20local%20creds.%20Also%20you're%20going%20to%20need%20or%20probably%20want%20to%20invest%20into%20a%20profile%20moving%20tool.%20This%20is%20a%20newer%20one%20that%20supports%20migrating%20to%20AzureAD.%20There%20is%20another%20profwiz%20but%20I%20had%20issues%20with%20that%2C%20but%20you%20can%20check%20this%20one%20as%20well%3A%20%3CA%20href%3D%22https%3A%2F%2Fppm.laplink.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fppm.laplink.com%2F%3C%2FA%3E%20%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20will%20make%20it%20less%20painful%20to%20migrate%20users%2C%20otherwise%20you%20will%20have%20to%20setup%20new%20profiles%20when%20joining%20to%20azure.%20%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20are%20going%20to%20use%20InTune%20there%20are%20other%20considerations%20as%20to%20just%20joining%20them%20to%20azure%20AD%20doesn't%20fulling%20install%20the%20Intune%20management%20agent%20on%20the%20machine%2C%20not%20sure%20if%20this%20has%20been%20fixed%20since%20we%20did%20our%20migration%20but%20you%20used%20to%20have%20to%20completly%20put%20the%20machine%20in%20a%20reset%20state%20and%20join%20with%20the%20computer%20join%20experience%20in%20order%20to%20get%20this%20agent%20to%20install%2C%20which%20provided%20most%20of%20the%20GPO%20functionalities%20running%20as%20system%20etc.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1507195%22%20slang%3D%22en-US%22%3ERe%3A%20Migrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1507195%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20insights%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F869%22%20target%3D%22_blank%22%3E%40Chris%20Webb%3C%2FA%3E%26nbsp%3B!%20Much%20appreciated.%20There%20aren't%20any%20plans%20to%20get%20them%20Intune%20managed%2C%20but%20its%20in%20the%20pipeline.%20I%20guess%20i'll%20know%20soon%20enough%20if%20the%20problem%20you%20mentioned%20is%20fixed.%20Out%20of%20curiosity%2C%20when%20did%20you%20experience%20this%20problem...was%20it%20recently%2C%20or%20years%20ago%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1507206%22%20slang%3D%22en-US%22%3ERe%3A%20Migrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1507206%22%20slang%3D%22en-US%22%3ELast%20Year.%20But%20Did%20a%20quick%20search%20it's%20no%20longer%20an%20issue%20apparently.%20%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Foliverkieselbach.com%2F2017%2F11%2F29%2Fdeep-dive-microsoft-intune-management-extension-powershell-scripts%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foliverkieselbach.com%2F2017%2F11%2F29%2Fdeep-dive-microsoft-intune-management-extension-powershell-scripts%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%22UPDATE%3A%20Intune%20In-Development%20announcement%20March%202020%3CBR%20%2F%3EPowerShell%20scripts%20support%20for%20BYOD%20devices.%20PowerShell%20scripts%20will%20support%20Azure%20AD%20registered%20devices%20in%20Intune.%20This%20functionality%20does%20not%20support%20devices%20running%20Windows%2010%20Home%20edition.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20workflow%20is%20basically%20like%20this.%20If%20a%20PowerShell%20script%20is%20assigned%20to%20a%20user%20group%20(device%20groups%20are%20not%20supported%20since%2022th%20of%20Oct.)%20and%20the%20agent%20is%20not%20installed%2C%20it%20will%20be%20pushed%20down%20automatically%20to%20the%20device%20via%20EnterpriseDesktopAppManagement%20CSP%20by%20Intune.%20Microsoft%20Intune%20network%20requirements%20and%20endpoints%20that%20must%20be%20reachable%20can%20be%20found%20here.%20This%20can%20be%20verified%20and%20traced%20in%20the%20%E2%80%9CAdvanced%20Diagnostics%20Report%E2%80%9D%20of%20the%20MDM%20management.%22%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1507868%22%20slang%3D%22en-US%22%3ERe%3A%20Migrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1507868%22%20slang%3D%22en-US%22%3EBe%20aware%2C%20if%20you%20join%20to%20AAD%20only%20and%20don't%20have%20Intune%20setup%2C%20there%20is%20no%20way%20to%20automatically%20enroll%20all%20of%20your%20computers%20in%20Intune.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20strongly%20advise%20to%20join%20to%20AAD%20and%20Intune%20at%20the%20same%20time.%3CBR%20%2F%3E%3CBR%20%2F%3EOtherwise%2C%20the%20join%20to%20Intune%20has%20to%20be%20initiated%20locally%20by%20users%20who%20need%20local%20admin%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1510198%22%20slang%3D%22en-US%22%3ERe%3A%20Migrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1510198%22%20slang%3D%22en-US%22%3EI%20hadn't%20considered%20that%2C%20thanks%20for%20the%20insights.%20May%20need%20to%20reconsider%20our%20approach%20now.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1505851%22%20slang%3D%22en-US%22%3EMigrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1505851%22%20slang%3D%22en-US%22%3E%3CP%3EWe've%20currently%20got%20our%20domain%2Fenvironment%20setup%20in%20a%20Hybrid%20AD.%20We've%20got%20a%20DC%20with%20AzureAD%20Connect%20installed%20and%20syncing%20to%20Azure.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20plan%20is%20to%20uninstall%20AzureAD%20connect%2C%20demote%20the%20DC%20server%2C%20manually%20join%20computers%20to%20AzureAD.%20Will%20this%20work%3F%20I'm%20trying%20to%20understand%20if%20there%20is%20any%20consideration%20when%20uninstalling%20the%20AzureAD%20connect%20or%20disconnecting%20the%20server%20from%20Azure.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1505851%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2035871%22%20slang%3D%22en-US%22%3ERe%3A%20Migrating%20from%20Hybrid%20to%20pure%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2035871%22%20slang%3D%22en-US%22%3E%3CP%3ESome%20organizations%20may%20not%20be%20able%20to%20move%20some%20of%20their%20applications%20to%20a%20public%20cloud%2C%20such%20as%20Microsoft%20Azure%20or%20any%20other%20public%20cloud%2C%20due%20to%20their%20own%20policies.%20However%2C%20any%20organization%20can%20benefit%20from%20having%20some%20of%20its%20applications%20in%20the%20public%20cloud%20and%20other%20on-premises%20applications.%20But%20a%20hybrid%20environment%20can%20create%20an%20extremely%20complex%20environment%20for%20the%20various%20platforms%20and%20technologies%20used%20in%20public%20clouds%20compared%20to%20on-premises%20environments.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMicrosoft%20provides%20the%20best%20hybrid%20cloud%20solution%20that%20allows%20you%20to%20optimize%20your%20existing%20assets%20on%20campus%20and%20in%20the%20public%20cloud%20for%20stability%20in%20the%20Azure%20hybrid%20cloud.%20With%20Azure%20Stack%20(local)%20and%20Azure%20(public%20cloud)%2C%20make%20the%20most%20of%20your%20existing%20skills%20and%20get%20a%20flexible%20and%20integrated%20approach%20to%20building%20applications%20that%20can%20run%20in%20the%20cloud%20or%20on%20campus.%3C%2FP%3E%3CP%3EWhen%20it%20comes%20to%20security%2C%20you%20can%20centralize%20management%20and%20security%20in%20a%20hybrid%20cloud.%20You%20can%20control%20all%20your%20assets%20from%20the%20data%20center%20to%20the%20cloud%20by%20logging%20in%20to%20on-premises%20and%20cloud%20applications.%20This%20can%20be%20achieved%20by%20extending%20Active%20Directory%20to%20the%20hybrid%20cloud%20and%20using%20identity%20management.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20do%20this%20it%20is%20suggested%20to%20hire%20the%20services%20of%20Microsoft%20Azure%20experts%20who%20have%20experience%2C%20skills%20and%20verified%20their%20credentials%20with%20the%20%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fwww.justcerts.com%2Fmicrosoft%2Faz-900-practice-questions.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20Azure%20Certification%3C%2FA%3E%3C%2FSTRONG%3E%20with%20good%20scores.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFinally%2C%20you%20can%20naturally%20distribute%20and%20analyze%20data%2C%20use%20similar%20query%20languages%20for%20cloud%20and%20on-premises%20assets%2C%20and%20implement%20analysis%20and%20in-depth%20training%20in%20Azure%20to%20enrich%20your%20data.%20It%20can%20be%2C%20regardless%20of%20its%20source.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fblog%2Fhybrid-cloud-just-got-easier-new-azure-migration-resources-and-tools-available%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fblog%2Fhybrid-cloud-just-got-easier-new-azure-migration-resources-and-tools-available%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

We've currently got our domain/environment setup in a Hybrid AD. We've got a DC with AzureAD Connect installed and syncing to Azure. 

 

The plan is to uninstall AzureAD connect, demote the DC server, manually join computers to AzureAD. Will this work? I'm trying to understand if there is any consideration when uninstalling the AzureAD connect or disconnecting the server from Azure. 

 

Thanks!

6 Replies
Biggest concern is if you have any on-prem servers (File shares / printers etc.) that would still need local creds. Also you're going to need or probably want to invest into a profile moving tool. This is a newer one that supports migrating to AzureAD. There is another profwiz but I had issues with that, but you can check this one as well: https://ppm.laplink.com/

This will make it less painful to migrate users, otherwise you will have to setup new profiles when joining to azure.

If you are going to use InTune there are other considerations as to just joining them to azure AD doesn't fulling install the Intune management agent on the machine, not sure if this has been fixed since we did our migration but you used to have to completly put the machine in a reset state and join with the computer join experience in order to get this agent to install, which provided most of the GPO functionalities running as system etc.

Thanks for the insights @Chris Webb ! Much appreciated. There aren't any plans to get them Intune managed, but its in the pipeline. I guess i'll know soon enough if the problem you mentioned is fixed. Out of curiosity, when did you experience this problem...was it recently, or years ago?

 

Cheers

Last Year. But Did a quick search it's no longer an issue apparently.

https://oliverkieselbach.com/2017/11/29/deep-dive-microsoft-intune-management-extension-powershell-s...

"UPDATE: Intune In-Development announcement March 2020
PowerShell scripts support for BYOD devices. PowerShell scripts will support Azure AD registered devices in Intune. This functionality does not support devices running Windows 10 Home edition.

The workflow is basically like this. If a PowerShell script is assigned to a user group (device groups are not supported since 22th of Oct.) and the agent is not installed, it will be pushed down automatically to the device via EnterpriseDesktopAppManagement CSP by Intune. Microsoft Intune network requirements and endpoints that must be reachable can be found here. This can be verified and traced in the “Advanced Diagnostics Report” of the MDM management."
Be aware, if you join to AAD only and don't have Intune setup, there is no way to automatically enroll all of your computers in Intune.

I strongly advise to join to AAD and Intune at the same time.

Otherwise, the join to Intune has to be initiated locally by users who need local admin
I hadn't considered that, thanks for the insights. May need to reconsider our approach now.

Some organizations may not be able to move some of their applications to a public cloud, such as Microsoft Azure or any other public cloud, due to their own policies. However, any organization can benefit from having some of its applications in the public cloud and other on-premises applications. But a hybrid environment can create an extremely complex environment for the various platforms and technologies used in public clouds compared to on-premises environments.

 

Microsoft provides the best hybrid cloud solution that allows you to optimize your existing assets on campus and in the public cloud for stability in the Azure hybrid cloud. With Azure Stack (local) and Azure (public cloud), make the most of your existing skills and get a flexible and integrated approach to building applications that can run in the cloud or on campus.

When it comes to security, you can centralize management and security in a hybrid cloud. You can control all your assets from the data center to the cloud by logging in to on-premises and cloud applications. This can be achieved by extending Active Directory to the hybrid cloud and using identity management.

 

To do this it is suggested to hire the services of Microsoft Azure experts who have experience, skills and verified their credentials with the Microsoft Azure Certification with good scores.

 

Finally, you can naturally distribute and analyze data, use similar query languages ​​for cloud and on-premises assets, and implement analysis and in-depth training in Azure to enrich your data. It can be, regardless of its source.

https://azure.microsoft.com/en-us/blog/hybrid-cloud-just-got-easier-new-azure-migration-resources-an...