Forum Discussion
Red Flag
Aug 05, 2020Iron Contributor
Hybrid AAD Join with non-routable UPNs on onpremise AD
Does Hybrid AAD Join support non-routable UPNs on local AD? The issue: all requirements for hybrid AAS Join are met except of routable UPNs on on-prem AD (no SF). Effect: device state is changing to ...
Moe_Kinani
Bronze Contributor
As mentioned, this piece not going to work because the domain in not routable. Primary UPN/ ProxyAddress attribute needs to match the verified domain so Intune can can validate the request.
If xyz.com is verified domain->The synced user needs to be user@xyz.com, primary upn NOT alias.
Moe
If xyz.com is verified domain->The synced user needs to be user@xyz.com, primary upn NOT alias.
Moe
Red Flag
Aug 06, 2020Iron Contributor
Thanks, Moe, for clarification. The docs are not clear enough - as devices are going to the hybrid state but MDM enrollment will not happen. Thanks again!