Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community
SOLVED

Duplicate Azure Device when onboarding Defender for Endpoint

Brass Contributor

Hi

I have a device which is "Microsoft Entra registered" with a owner assigned, they have logged into Microsoft account their device.

We have onboarded the device to Defender for Endpoint and it now shows a 2nd device entry with the same name, no join type but Microsoft Defender for Endpoint as its Security Settings Management. This is obviously created when onboarded but why does AZ not sort out duplicate devices?

 

Wen assigning the device to a group it causes issues as the device shows twice

8 Replies

@Fhilp do you have the below setting enabled in your MDE settings in the advanced features?

eliekarkafy_1-1697037251585.png

 

 

@eliekarkafy 

hi yes this setting is on.

 

These aren't duplicates in defender but duplicates in Azure Devices. As per below

 

Fhilp_1-1697115968148.png

 

Thanks

Are your devices joined to on prem domain ? Azure AD ? Workgroup?
Yes they are on Prem devices domain joined, but dont sync to Azure using ADConnect, they show only registered as a user logs on with their MS account to office Apps
When the same device ends up with two different identities in Azure AD, it is known as a Dual state in AAD terminology. In your case when you onboarded the device in MDE it will register the device with different ID . For you current setup the best pratice is to sync your devices as hybrid ad join since they are joined to onprem AD and delete the registered devices because always hybrid ad join take precedence on registered device type
So i guess that means using ADConnect to get the devices Sync'd as hybrid?
best response confirmed by Fhilp (Brass Contributor)
Solution
Correct in your ENTRA Connect enable the hybrid AD join features and sync your devices to Entra Connect and delete the registered devices and any stale device
Great thanks for the help and explanation!
1 best response

Accepted Solutions
best response confirmed by Fhilp (Brass Contributor)
Solution
Correct in your ENTRA Connect enable the hybrid AD join features and sync your devices to Entra Connect and delete the registered devices and any stale device

View solution in original post