Migrate Azure AD Registered to Azure AD Joined

Iron Contributor

Hello,

 

I have ~100 Windows devices that are currently enrolled in Intune and all of them are now Azure AD Registered. I don't see anything in the "Access work or school" dialog that will let me change then to Azure AD Joined. Is there a procedure for migrating these systems to ADD Joined?

 

TIA

~DGM~

11 Replies

HI, what happens when you disconnect first, remove the object in azure and then go to settings - ->Work or school account --> Join to Azure AD option.

But Microsoft is recommending to change the ownership of the registered device so the device can be converted to an autopilot device (of course you need to configure autopilot and make sure you enable the option to convert existing devices)
After the device is registered as an autopilot device, you need to wipe it and enroll it into azure ad


 

guess my blog about aadr vs aadj needs some updating :) 

Azure Ad joined vs Azure Ad Registered | AADR vs AADJ | PRT (call4cloud.nl)

I did those steps - disconnect, remove AAD object, then reconnect through "Access work or school" - but the option to join AAD doesn't show. The only option is the 'Connect' button in the middle.

I think you're right about the Autopilot option and it's a path I'm investigating. But that poses a profile challenge. Most of these systems have been in user for 9+ months so there is a a significant amount of data in the local profile and other things like browser-stored passwords and such. I'm beginning to think that migration isn't an option.

Thx
Maybe an obvious question but are those devices windows 10pro?
Yes, all of the systems in question are Win 10 Pro except for a couple that are Win 10 Enterprise.
Is the user who want to join azure ad a local admin?
Yes they are.
ANy old enrollments still stuck in the registry? Another totally different question but how is the MDM scope configured
There are no old enrollments - the current configuration is the only one that's been attempted. All of these systems were Hybrid Azure Ad Joined and I think that's the sticking point. They'll each have to be disconnected, have their object wiped from Azure AD, then a restart and a re-join to get them Azure AD Joined. And I expect that means that any existing profile will be pushed aside and a new one created for the join. That will mean a post-join migration process.

RE: MDM scope - it's configured for 'All'.
Ahhhh owkay.. that part i missed... True... true... true and true.. I will cost you some time to make sure the user profile is migrated. I guess they users didn't had onedrive and kfm active?
What I've found is even with OneDrive and such, if they were using a browser for password management we have to dig that out. And there are other apps that seem to have local profile-based configuration information. So many potential variations that I'm not sure we're even going to push down that road. We may leave them AAD Registered and configure all new systems through Autopilot. Eventually the current config will be upgraded.

Thx