Windows 10 AutoPilot from on-prem AD to Azure AD - Migration Options

%3CLINGO-SUB%20id%3D%22lingo-sub-1046215%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20AutoPilot%20from%20on-prem%20AD%20to%20Azure%20AD%20-%20Migration%20Options%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1046215%22%20slang%3D%22en-US%22%3EHey%20David%2C%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20be%20honest%20it%20seems%20like%20going%20through%20the%20autopilot%20options%20opens%20the%20door%20for%20more%20issues%20then%20setting%20up%20AD%20connect%20and%20syncing%20the%20objects%2C%20insure%20that%20GPOs%20and%20other%20computer%20properties%20are%20moved%20over%20as%20well%2C%20then%20start%20cutting%20ties%20to%20the%20legacy%20DC%20servers.%20The%20other%20part%20to%20look%20at%20is%20if%20O365%20or%20other%20applications%20are%20federated%20with%20the%20%22old%22%20domain%20that%20the%20applications%20are%20prepare%20to%20take%20the%20new%20sign%20in.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1047538%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20AutoPilot%20from%20on-prem%20AD%20to%20Azure%20AD%20-%20Migration%20Options%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1047538%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F426650%22%20target%3D%22_blank%22%3E%40ericjk4%3C%2FA%3E%26nbsp%3BI%20see%20what%20you%20are%20saying%2C%20but%20where%20does%20the%20migration%20of%20the%20PC%20to%20Azure-AD%20come%20into%20your%20plan.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1049084%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20AutoPilot%20from%20on-prem%20AD%20to%20Azure%20AD%20-%20Migration%20Options%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1049084%22%20slang%3D%22en-US%22%3EAre%20you%20keeping%20your%20current%20forest%20or%20getting%20rid%20of%20everything%20and%20creating%20a%20new%20forest%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1049676%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20AutoPilot%20from%20on-prem%20AD%20to%20Azure%20AD%20-%20Migration%20Options%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1049676%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F426650%22%20target%3D%22_blank%22%3E%40ericjk4%3C%2FA%3E%26nbsp%3Bno%20on-premises%20infrastructure%2C%20everything%20will%20be%20consolidated%20to%20PaaS%2FSaaS%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1045307%22%20slang%3D%22en-US%22%3EWindows%2010%20AutoPilot%20from%20on-prem%20AD%20to%20Azure%20AD%20-%20Migration%20Options%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1045307%22%20slang%3D%22en-US%22%3E%3CP%3ECurrently%20looking%20into%20migration%20options%20for%20an%20existing%20fleet%20of%20Windows%2010%20AD%20domain-joined%20PCs%20to%20Azure%20AD-joined%20in%20a%20target%20Azure%20AD%20tenant%20(no%20synchronization%20in%20place%2C%20don't%20want%20to%20put%20in%20place%20either%20due%20to%20'cloud%20only'%20model)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20three%20migration%20options%20I%20see%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20%3CSTRONG%3EManual%3C%2FSTRONG%3E%20-%20Manually%20unjoin%20AD%20domain%2C%20user%20joins%20azure%20ad%20domain%2C%20reboot%20and%20user%20logs-in%2C%20move%20legacy%20profile%20contents%20over%20to%20new%20azure%20ad%20profile%20(manual%20or%20third%20party)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2)%20%3CSTRONG%3EAutoPilot%20User-Driven%3C%2FSTRONG%3E%20-%20Register%20devices%20in%20AutoPilot%20to%20target%20tenant%2C%20create%20deployment%20profile%20in%20target%20tenant%2C%20add%20the%20device%20to%20deployment%20group%20in%20target%20tenant%20and%20reboot%20PC%2C%20user%20logs%20in%20and%20goes%20through%20autopilot%20process%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3)%20%3CSTRONG%3EAutoPilot%20User-Driven%20with%20White%20Glove%20-%26nbsp%3B%3C%2FSTRONG%3ERegister%20devices%20in%20AutoPilot%20in%20target%20tenant%2C%20create%20deployment%20profile%20in%20target%20tenant%2C%20add%20the%20device%20to%20deployment%20group%20in%20target%20tenant%20and%20reboot%20PC%2C%20technician%20pre-provisions%20new%20profile%20then%20reseals%2C%20user%20logs%20in%20and%20goes%20through%20autopilot%20process%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20confirm%20that%20%3CSTRONG%3E2%3C%2FSTRONG%3E%20and%20%3CSTRONG%3E3%3C%2FSTRONG%3E%20are%20valid%20options%2C%20or%20if%20there%20are%20any%20methods%20I%20am%20missing%3F%20As%20in%20I%20can%20register%20a%20Windows%2010%20on-prem%20domain-joined%20PC%20to%20an%20Azure%20AD%20instance%20(no%20synchronization)%20and%20use%20autopilot%20to%20migrate%20the%20PC%20to%20being%20Azure%20AD%20joined.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1045307%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAutopilot%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDeployment%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ewindows%2010%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1049823%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20AutoPilot%20from%20on-prem%20AD%20to%20Azure%20AD%20-%20Migration%20Options%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1049823%22%20slang%3D%22en-US%22%3EIf%20your%20not%20creating%20a%20new%20domain%20and%20just%20moving%20everything%20to%20the%20cloud%20then%20you%20should%20be%20able%20to%20migrate%20the%20domain%20to%20the%20cloud%20and%20verify%20that%20the%20computers%20are%20authenticating%20with%20the%20cloud.%20That%20way%20you%20wont%20have%20to%20unjoin%20or%20rejoin%20any%20computers.%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Currently looking into migration options for an existing fleet of Windows 10 AD domain-joined PCs to Azure AD-joined in a target Azure AD tenant (no synchronization in place, don't want to put in place either due to 'cloud only' model)

 

The three migration options I see:

 

1) Manual - Manually unjoin AD domain, user joins azure ad domain, reboot and user logs-in, move legacy profile contents over to new azure ad profile (manual or third party)

 

2) AutoPilot User-Driven - Register devices in AutoPilot to target tenant, create deployment profile in target tenant, add the device to deployment group in target tenant and reboot PC, user logs in and goes through autopilot process

 

3) AutoPilot User-Driven with White Glove - Register devices in AutoPilot in target tenant, create deployment profile in target tenant, add the device to deployment group in target tenant and reboot PC, technician pre-provisions new profile then reseals, user logs in and goes through autopilot process

 

Can someone confirm that 2 and 3 are valid options, or if there are any methods I am missing? As in I can register a Windows 10 on-prem domain-joined PC to an Azure AD instance (no synchronization) and use autopilot to migrate the PC to being Azure AD joined.

 

Thank you

 

 

5 Replies
Highlighted
Hey David,

To be honest it seems like going through the autopilot options opens the door for more issues then setting up AD connect and syncing the objects, insure that GPOs and other computer properties are moved over as well, then start cutting ties to the legacy DC servers. The other part to look at is if O365 or other applications are federated with the "old" domain that the applications are prepare to take the new sign in.
Highlighted

@ericjk4 I see what you are saying, but where does the migration of the PC to Azure-AD come into your plan.

Highlighted
Are you keeping your current forest or getting rid of everything and creating a new forest?
Highlighted

@ericjk4 no on-premises infrastructure, everything will be consolidated to PaaS/SaaS

Highlighted
If your not creating a new domain and just moving everything to the cloud then you should be able to migrate the domain to the cloud and verify that the computers are authenticating with the cloud. That way you wont have to unjoin or rejoin any computers.