windows autopilot - hybrid join

%3CLINGO-SUB%20id%3D%22lingo-sub-1414011%22%20slang%3D%22en-US%22%3Ewindows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1414011%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20folks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20setup%20a%20hybrid%20Autopilot%20deployment%20profile%20to%20test%20on%20my%20OOBE%20laptop%2C%20an%20issue%20with%20my%20test%20laptop%20is%20that%20it%20doesn't%20connect%20to%20Autopilot%20service%20and%20so%20doesn't%20give%20me%20the%26nbsp%3B%3CSTRONG%3E%3CEM%3EHi%3C%2FEM%3E%26nbsp%3B%3CEM%3Eusername!%20Welcome%20to%20Microsoft%20Services.%26nbsp%3B%3C%2FEM%3E%3C%2FSTRONG%3E%20It%20goes%20straight%20to%20%3CEM%3E%3CSTRONG%3Esign%20in%20to%20microsoft%20account%20as%20a%20standard%20Windows%2010%20setup.%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20i%20do%20Azure%20join%20profile%2C%20laptop%20connects%20to%20Autopilot%20service%20after%20joining%20the%20home%20wifi%20and%20starts%20the%20deployment.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20Hybrid%20setup%2C%20I%20have%20followed%20the%20below%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-autopilot-hybrid%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-autopilot-hybrid%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20active%20directory%20domain%20controller%20is%20a%20Azure%20VM.%20The%20Intune%20connector%2C%20AD%20connect%20all%20is%20setup%20correctly%20and%20shows%20green%20as%20healthy%20connection.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20will%20be%20much%20appreciated.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3Ev%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1414011%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1414057%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1414057%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F430794%22%20target%3D%22_blank%22%3E%40vishal1502%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20do%20you%20have%20a%20device%20security%20group%20associated%20with%20your%20deployment%20profile%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1414063%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1414063%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3BHi%20%2C%20yes.%20I%20have%20created%20the%20dynamic%20group%20for%20Device%20in%20Azure.%20The%20imported%20hardware%20id%20show%20up%20as%20a%20member%20in%20the%20group%20and%20I%20have%20assigned%20the%20test%20user%20that%20I%20am%20using.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1414067%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1414067%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F430794%22%20target%3D%22_blank%22%3E%40vishal1502%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20if%20you%20switch%20to%20just%20Azure%20AD%20join%2C%20it%20works%20OK%20right%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20only%20Hybrid%20Azure%20AD%20join%20where%20the%20autopilot%20deployment%20doesn't%20work%3F%20%26nbsp%3BDo%20I%20have%20that%20correct%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20Hybrid%20Azure%20AD%20join%20and%20Autopilot%2C%20TPM%20can%20cause%20issues%20as%20per%20this%20doc%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fwindows-autopilot%2Fself-deploying%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fwindows-autopilot%2Fself-deploying%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1414081%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1414081%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eyes%2C%20Azure%20AD%20works%20perfectly.%20No%20issues%20at%20all.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20not%20getting%20the%20'Hi%20username!%20Welcome%20to%20Microsoft%20Services!%20after%20I%20select%20the%20language%2C%20keyboard%20and%20connect%20to%20home%20wifi.%20Straight%20it%20goes%20in%20'sign%20to%20microsoft%20account'%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eplease%20note%20I%20am%20trying%20the%20Hybrid%20join%20from%20my%20home%2C%20my%20Domain%20controller%20is%20a%20in%20Azure%20VM.%20I%20can%20understand%20if%20the%20process%20fails%20at%20domain%20join%20step%2C%20but%20I%20am%20not%20able%20to%20figure%20why%20I%20don't%20get%20Welcome%20to%20Microsoft%20Services%20page.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1415856%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1415856%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F430794%22%20target%3D%22_blank%22%3E%40vishal1502%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20I%20would%20suggest%20opening%20a%20ticket%20with%20Microsoft%20is%20the%20next%20best%20step%20to%20resolve%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1422875%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1422875%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3Bcheers%20Peter.%20Seems%20that%20is%20the%20best%20option%20right%20now.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1423872%22%20slang%3D%22en-US%22%3ERe%3A%20windows%20autopilot%20-%20hybrid%20join%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1423872%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F430794%22%20target%3D%22_blank%22%3E%40vishal1502%3C%2FA%3E%26nbsp%3Byour%20DC%20is%20running%20in%20the%20cloud%20(Azure)%20and%20your%20client%20is%20local%2C%20that%20will%20never%20work%20without%20the%20VPN%20option%20which%20is%20not%20yet%20available.%20As%20your%20client%20needs%20to%20be%20able%20to%20contact%20the%20DC.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20suggest%20yo%20have%20a%20look%20at%20Michal%20Niehaus%20his%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Foofhours.com%2F2020%2F05%2F23%2Fdigging-into-hybrid-azure-ad-join%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foofhours.com%2F2020%2F05%2F23%2Fdigging-into-hybrid-azure-ad-join%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hello folks,

 

I have setup a hybrid Autopilot deployment profile to test on my OOBE laptop, an issue with my test laptop is that it doesn't connect to Autopilot service and so doesn't give me the Hi username! Welcome to Microsoft Services.  It goes straight to sign in to microsoft account as a standard Windows 10 setup.

 

If i do Azure join profile, laptop connects to Autopilot service after joining the home wifi and starts the deployment. 

 

For Hybrid setup, I have followed the below 

https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-autopilot-hybrid

 

My active directory domain controller is a Azure VM. The Intune connector, AD connect all is setup correctly and shows green as healthy connection. 

 

Any help will be much appreciated. 

 

thanks

v

 

7 Replies
Highlighted

@vishal1502 

 

Hi, do you have a device security group associated with your deployment profile?

Highlighted

@PeterRising Hi , yes. I have created the dynamic group for Device in Azure. The imported hardware id show up as a member in the group and I have assigned the test user that I am using. 

 

 

Highlighted

@vishal1502 

 

So if you switch to just Azure AD join, it works OK right?

 

It's only Hybrid Azure AD join where the autopilot deployment doesn't work?  Do I have that correct?

 

With Hybrid Azure AD join and Autopilot, TPM can cause issues as per this doc - https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/self-deploying

Highlighted

@PeterRising 

yes, Azure AD works perfectly. No issues at all. 

 

I am not getting the 'Hi username! Welcome to Microsoft Services! after I select the language, keyboard and connect to home wifi. Straight it goes in 'sign to microsoft account'

 

please note I am trying the Hybrid join from my home, my Domain controller is a in Azure VM. I can understand if the process fails at domain join step, but I am not able to figure why I don't get Welcome to Microsoft Services page.

Highlighted

@vishal1502 

 

Hi, I would suggest opening a ticket with Microsoft is the next best step to resolve this.

Highlighted

@PeterRising cheers Peter. Seems that is the best option right now.

Highlighted

@vishal1502 your DC is running in the cloud (Azure) and your client is local, that will never work without the VPN option which is not yet available. As your client needs to be able to contact the DC. 


I suggest yo have a look at Michal Niehaus his article https://oofhours.com/2020/05/23/digging-into-hybrid-azure-ad-join/