Controlled validation of hybrid Azure AD join

%3CLINGO-SUB%20id%3D%22lingo-sub-1253872%22%20slang%3D%22en-US%22%3EControlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1253872%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20sure%20if%20this%20should%20be%20here%20or%20in%20the%20Azure%20AD%20section.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20looking%20to%20implement%20a%20Controlled%20validation%20of%20Hybrid%20Azure%20AD%20Join%20%2F%20Auto%20enrollment%20in%20Intune%20via%20GPO%2C%20using%20the%20MS%20guide%20below%20as%20a%20reference%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-control%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-control%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20questions%20are%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EDo%20I%20set%20the%20GPO%20to%20my%20test%20deployment%20OU%3C%2FLI%3E%3CLI%3EDo%20I%20simply%20remove%20the%20GPO%20from%20my%20test%20deployment%20OU%20on%20successful%20testing%3C%2FLI%3E%3C%2FUL%3E%3CP%3EWould%20like%20to%20hear%20from%20anyone%20who%20has%20implemented%20this%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1253872%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1258499%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1258499%22%20slang%3D%22en-US%22%3EFrom%20my%20experience%2C%20I%20just%20create%20registry%20keys%20and%20assign%20them%20to%20the%20devices.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20are%20done%20testing%2C%20would%20you%20like%20to%20remove%20these%20devices%20from%20AAD%2FIntune%20or%20add%20all%20devices%20to%20AAD%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1258611%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1258611%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Buddy%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20I%20would%20like%20to%20do%20is%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EHybrid%20Azure%20AD%20Join%20my%20devices%20in%20my%20TEST%20%2F%20PILOT%20%2F%20UAT%20group%20only%3C%2FLI%3E%3CLI%3EOnce%20successful%3C%2FLI%3E%3CLI%3EApply%20to%20the%20whole%20on-premise%20AD%20domain%20%2F%20devices%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1258753%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1258753%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20the%20way%20I%20do%20it%3A%3C%2FP%3E%3CP%3E-%20Create%20GPO%20with%20registry%20edits%20and%20apply%20to%20test%20OU%3C%2FP%3E%3CP%3E-%20If%20succesfull%2C%20delete%20GPO%3C%2FP%3E%3CP%3E-%20Assign%20domain%20wide%20policy%20through%20AAD%20connect%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-managed-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-managed-domains%3C%2FA%3E)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBTW%3A%20best%20make%20sure%20all%20the%20computers%20are%20W10%201803%20in%20order%20to%20avoid%20dual%20state%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-plan%23review-controlled-validation-of-hybrid-azure-ad-join%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-plan%23review-controlled-validation-of-hybrid-azure-ad-join%3C%2FA%3E)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1261029%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1261029%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Buddy%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20the%20process%20would%20be%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EControlled%20Hybrid%20Azure%20AD%20Join%20on%20Test%20OU%3C%2FLI%3E%3CLI%3EThen%20once%20successful%3C%2FLI%3E%3CLI%3EConfigure%20AADC%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20essence%2C%20DO%20NOT%20TOUCH%20AADC%20until%26nbsp%3BControlled%20Hybrid%20Azure%20AD%20Join%20is%20verified%20OK%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1264595%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1264595%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3Bthat's%20correct%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Elet%20me%20know%20how%20it%20goes!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1284814%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1284814%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESorry%2C%20I%20did%20mention%20before%20about%20applying%20the%20Controlled%20Hybrid%20GPO%20to%20the%20test%20OU%20BEFORE%20touching%20AADC%2C%20but%20I%20assume%20the%20TEST%20OU%20must%20be%20included%20in%20the%20AADC%20sync%20with%20the%20syncing%20of%20devices%20as%20per%20below%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22filter2.png%22%20style%3D%22width%3A%20872px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F182367iF0015E7BCF5F8F67%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22filter2.png%22%20alt%3D%22filter2.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1284820%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1284820%22%20slang%3D%22en-US%22%3EYes%2C%20the%20OU%20needs%20to%20be%20sync'ed%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20doesn't%20enable%20Hybrid%20join%20by%20itself%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1284895%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1284895%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20the%20devices%20need%20to%20be%20in%20a%20group%20or%20is%20the%20OU%20sufficient%20for%20the%20Controlled%20Hybrid%20test%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1284901%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1284901%22%20slang%3D%22en-US%22%3EDependant%20on%20how%20you%20configure%20the%20GPO%3CBR%20%2F%3EIf%20you%20put%20the%20GPO%20on%20a%20OU%2C%20than%20a%20OU%20is%20sufficient%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285265%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285265%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EApplied%20GPO%20to%20OU%20and%20OU%20to%20sync%2C%20still%20no%20device%20in%20AAD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20I%20missing%20something%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1284904%22%20slang%3D%22en-US%22%3ERe%3A%20Controlled%20validation%20of%20hybrid%20Azure%20AD%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1284904%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EExcellent%20thanks%2C%20testing%20now.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

Hi All

 

Not sure if this should be here or in the Azure AD section.

 

I'm looking to implement a Controlled validation of Hybrid Azure AD Join / Auto enrollment in Intune via GPO, using the MS guide below as a reference:

 

https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-control

 

My questions are:

 

  • Do I set the GPO to my test deployment OU
  • Do I simply remove the GPO from my test deployment OU on successful testing

Would like to hear from anyone who has implemented this

 

Regards

12 Replies
Highlighted
From my experience, I just create registry keys and assign them to the devices.

If you are done testing, would you like to remove these devices from AAD/Intune or add all devices to AAD?
Highlighted

@Thijs Lecomte 

 

Hi Buddy

 

What I would like to do is:

 

  • Hybrid Azure AD Join my devices in my TEST / PILOT / UAT group only
  • Once successful
  • Apply to the whole on-premise AD domain / devices

 

Regards

Highlighted

@Stuart King 

 

This is the way I do it:

- Create GPO with registry edits and apply to test OU

- If succesfull, delete GPO

- Assign domain wide policy through AAD connect (https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains)

 

BTW: best make sure all the computers are W10 1803 in order to avoid dual state (https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan#review-cont...)

Highlighted

@Thijs Lecomte 

 

Hi Buddy

 

So the process would be:

 

  • Controlled Hybrid Azure AD Join on Test OU
  • Then once successful
  • Configure AADC

 

In essence, DO NOT TOUCH AADC until Controlled Hybrid Azure AD Join is verified OK?

 

Regards

Highlighted

@Stuart King that's correct :)

 

let me know how it goes!

@Thijs Lecomte 

 

Sorry, I did mention before about applying the Controlled Hybrid GPO to the test OU BEFORE touching AADC, but I assume the TEST OU must be included in the AADC sync with the syncing of devices as per below?

 

filter2.png

Highlighted
Yes, the OU needs to be sync'ed

This doesn't enable Hybrid join by itself
Highlighted

@Thijs Lecomte 

 

Do the devices need to be in a group or is the OU sufficient for the Controlled Hybrid test?

 

Regards

Highlighted
Dependant on how you configure the GPO
If you put the GPO on a OU, than a OU is sufficient
Highlighted

@Thijs Lecomte 

 

Excellent thanks, testing now.

Highlighted

@Thijs Lecomte 

 

Applied GPO to OU and OU to sync, still no device in AAD.

 

Am I missing something?

Highlighted