Change Azure AD joined to Hybrid Joined Device

Elmi Almonte Morel 106 Reputation points
2020-09-20T13:25:07.157+00:00

Hello, Guys

In my environment we have set in AD connected Azure AD Joined devices, we also have Pass hash Sync, now we want to get config some conditional access but it need to be state Hybrid Joined.

The devices has Azure AD joined, how can we migrate to Hybrid Joined, without impact users, we need to change in AD connect in that it?

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} vote

3 answers

Sort by: Most helpful
  1. ESWARARAJU KONETI 2,206 Reputation points MVP Volunteer Moderator
    2020-09-20T14:26:29.153+00:00

    For devices that are purely AAD joined cannot be changed to hybrid-AAD unless you use auto-pilot with hybrid AAD join profile or manually join the devices to on-prem domain.
    The hybrid azure AD joined refers to a device joined to on-prem domain+ joined to AAD.
    For conditional access, the hybrid AAD is not mandatory, you can use other options to configure the in conditional access such as device compliant state (if have intune enrolled and compliant).

    1 person found this answer helpful.
    0 comments No comments

  2. Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
    2020-09-20T21:06:23.25+00:00

    +1 to Eswar's answers.

    To summarize:

    • You can't directly convert.
    • You don't want or need to convert for conditional access.

    The requirement for conditional access is for the system and user to have an Azure AD identity. This is perfectly fulfilled when a device is full Azure AD joined.

    1 person found this answer helpful.

  3. CiciWu-MSFT 1,206 Reputation points
    2020-09-21T03:42:15.027+00:00
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.