Hybrid Azure Join

%3CLINGO-SUB%20id%3D%22lingo-sub-1656738%22%20slang%3D%22en-US%22%3EHybrid%20Azure%20Join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1656738%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20want%20to%20use%20the%20Hybrid%20Azure%20Join%3C%2FP%3E%3CP%3ENow%20my%20question%20is%2C%20can%20we%20use%20Cloud%20GPO's%20(CSP%2FADMX)%20AND%20On%20Prem%20GPO's%3F%3C%2FP%3E%3CP%3ESo%20for%20example%2C%20can%20I%20roll%20out%20printers%20via%20local%20GPO%20and%20software%2C%20onedrive%20settings%20via%20Intune%20from%20the%20cloud%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20I%20can't%20find%20any%20information%20here%2C%20if%20Google%20is%20not%20my%20friend%20today%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20Regards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhil%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1656738%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Egpo%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EGroup%20Policy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EGroup%20Policy%20Object%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%20Azure%20AD%20Join%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1659636%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Azure%20Join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1659636%22%20slang%3D%22en-US%22%3EYes%2C%20Windows%2010%20has%20the%20possibility%20to%20be%20member%20of%20a%20on-prem%20active%20directory%20domain%20and%20MDM%20managed%20with%20Endpoint%20Manager.%20In%20Windows%2010%2C%20version%201709%20or%20later%2C%20when%20the%20same%20policy%20is%20configured%20in%20GP%20and%20MDM%2C%20the%20GP%20policy%20wins%20(GP%20policy%20takes%20precedence%20over%20MDM).%20Since%20Windows%2010%2C%20version%201803%2C%20a%20new%20setting%20allows%20you%20to%20change%20the%20policy%20conflict%20winner%20to%20MDM.%20In%20order%20to%20add%20some%20stability%20to%20conflicting%20scenarios%20you%20should%20configure%20the%20CSP%20policy%20called%20ControlPolicyConflict%2FMDMWinsOverGP.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1663487%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Azure%20Join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1663487%22%20slang%3D%22en-US%22%3Ethanks.%3CBR%20%2F%3ESo%20that%20means%2C%20i%20can%20use%20the%20Autopilot%20feature.%20But%20i%20must%20be%20in%20my%20Company%20Netzwork%20for%20the%20Domain%20Join%3F%3CBR%20%2F%3EAfter%20the%20Domain%20Join%2C%20i%20can%20set%20Policys%20in%20Intune%20and%20can%20use%20my%20old%20GPO%C2%B4s%20to%20manage%20my%20Computers%3F%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hello everyone,

 

we want to use the Hybrid Azure Join

Now my question is, can we use Cloud GPO's (CSP/ADMX) AND On Prem GPO's?

So for example, can I roll out printers via local GPO and software, onedrive settings via Intune from the cloud?

 

Unfortunately I can't find any information here, if Google is not my friend today

 

Best Regards,

 

Phil

3 Replies
Highlighted
Yes, Windows 10 has the possibility to be member of a on-prem active directory domain and MDM managed with Endpoint Manager. In Windows 10, version 1709 or later, when the same policy is configured in GP and MDM, the GP policy wins (GP policy takes precedence over MDM). Since Windows 10, version 1803, a new setting allows you to change the policy conflict winner to MDM. In order to add some stability to conflicting scenarios you should configure the CSP policy called ControlPolicyConflict/MDMWinsOverGP.
Highlighted
thanks.
So that means, i can use the Autopilot feature. But i must be in my Company Netzwork for the Domain Join?
After the Domain Join, i can set Policys in Intune and can use my old GPO´s to manage my Computers?
Highlighted

@RauschNauti 

 

Yes. You can perform a user-driven Hybrid Azure AD Join deployment over the internet, using a VPN connection. Otherwise the device need network connection to domain controller for domain join. After domain join the PCs can get GPOs from on-premise and device configuration policies from endpoint manager (Intune).