Nov 10 2023 11:36 AM - edited Nov 10 2023 11:38 AM
Currently in the planning and testing phase of deploying intune to our facility. Some quick pertinent facts:
I've consulted with some other sys-admins, and they've recommended making sure that the laptops are only entra joined, as there are limits as to what you can do with autopilot for hybrid devices.
I've been reading through the documentation, and have been getting dead links everywhere, as well as no clear path forward. I've gotten some test devices, set up during OOBE by logging in with a domain account, that when prompted with the dsregcmd I get the following results.
+----------------------------------------------------------------------+
| Device State |
+----------------------------------------------------------------------+
AzureAdJoined : NO
EnterpriseJoined : NO
DomainJoined : YES
DomainName : [DOMAIN NAME]
Device Name : [DEVICE NAME]
+----------------------------------------------------------------------+
| User State |
+----------------------------------------------------------------------+
NgcSet : NO
WorkplaceJoined : YES
WorkAccountCount : 1
WamDefaultSet : NO
+----------------------------------------------------------------------+
| SSO State |
+----------------------------------------------------------------------+
AzureAdPrt : NO
AzureAdPrtAuthority : NO
EnterprisePrt : NO
EnterprisePrtAuthority : NO
+----------------------------------------------------------------------+
| Work Account 1 |
+----------------------------------------------------------------------+
WorkplaceDeviceId : 7d32ce6a-d808-40e1-9b62-364cfe721c4a
WorkplaceThumbprint : D154009D6F6BEF2F1BE65CDCFCC3ACAD1ED9E560
DeviceCertificateValidity : [ 2023-11-09 17:08:45.000 UTC -- 2033-11-09 17:38:45.000 UTC ]
KeyContainerId : ebbd8f5a-ce98-4859-a071-6d46811a17f1
KeyProvider : Microsoft Platform Crypto Provider
TpmProtected : YES
WorkplaceIdp : login.windows.net
WorkplaceTenantId : 1bb841c5-79dd-4f6f-8ffa-1c73e03e5ab1
WorkplaceTenantName : ~
WorkplaceMdmUrl :
WorkplaceSettingsUrl :
NgcSet : NO
+----------------------------------------------------------------------+
| Diagnostic Data |
+----------------------------------------------------------------------+
Diagnostics Reference : www.microsoft.com/aadjerrors
User Context : UN-ELEVATED User
Client Time : 2023-11-09 19:00:10.000 UTC
AD Connectivity Test : PASS
AD Configuration Test : FAIL [0x80070002]
DRS Discovery Test : SKIPPED
DRS Connectivity Test : SKIPPED
Token acquisition Test : SKIPPED
Fallback to Sync-Join : ENABLED
Previous Registration : 2023-11-09 18:59:50.000 UTC
Error Phase : discover
Client ErrorCode : 0x801c001d
Executing Account Name : [domain account, domain account]
+----------------------------------------------------------------------+
| IE Proxy Config for Current User |
+----------------------------------------------------------------------+
Auto Detect Settings : YES
Auto-Configuration URL :
Proxy Server List :
Proxy Bypass List :
+----------------------------------------------------------------------+
| WinHttp Default Proxy Config |
+----------------------------------------------------------------------+
Access Type : DIRECT
+----------------------------------------------------------------------+
| Ngc Prerequisite Check |
+----------------------------------------------------------------------+
IsDeviceJoined : NO
IsUserAzureAD : NO
PolicyEnabled : NO
PostLogonEnabled : YES
DeviceEligible : YES
SessionIsNotRemote : YES
CertEnrollment : none
PreReqResult : WillNotProvision
For more information, please visit https://www.microsoft.com/aadjerrors
Nov 13 2023 10:12 AM
Nov 14 2023 04:04 AM
It seems there might be a slight confusion in terminologies. As of my last knowledge update in January 2022, there isn't a specific technology or service called "Entra Sync" directly associated with Microsoft or common IT deployment practices. However, I'll provide guidance on deploying Windows in a typical scenario using Microsoft Endpoint Manager (Intune) and Azure AD.
Deploying Windows with Microsoft Endpoint Manager (Intune) and Azure AD:
If I have answered your question, please mark your post as Solved If you like my response, please give it a Like Appreciate your Kudos! Proud to contribute! |
Nov 14 2023 04:38 AM
Nov 14 2023 04:40 AM