Automatic device join in single AD - multiple Azure topology

Ruslan Nalivaika 106 Reputation points
2020-02-25T08:29:16.72+00:00

Hi all,

Our customer is considering implementing topology with single onprem AD synchronized to multiple Azure AD tenants, using a single ADFS farm. The customer needs availability of Autopilot with Hybrid AD join for devices in all Azure AD tenants.

The document in the link below suggests that this is not supported, but maybe somebody has experience with this kind of set up and can comment ?

MS documentation also says that device writeback is not supported in such topology. But as I understand, that should not be an issue when using Autopilot, because it is the Intune connector (and not the AD sync agent) that creates onprem AD account for the machine, is that correct ?

https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-single-adfs-multitenant-federation

BR, Ruslan

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,187 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,389 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Nagappan Veerappan 651 Reputation points Microsoft Employee
    2020-02-25T19:58:09.907+00:00

    Thank you for reaching out. Since this Intune supporting multiple connector and doing Domain join (offline) for Hybrid Azure AD Join. I would recommend to check with Intune and Auto pilot team on supportability point.

    As long as Intune connector have the ability to reach correct on-prem AD forest to create/delete computer objects. it should work. Since I am from Azure AD team, I can't comment on support points of view from Intune/Autopilot.

    Please reach out to Autopilot and Intune to get their comment on this implementation.