Computer joined to Azure AD, however is not visible in AD DS, group policies not applying

Stef Hambi 1 Reputation point
2022-09-20T13:07:45.27+00:00

The device is logged in using an Azure AD account, and the device is listed in the DS as "joined", however when I created the domain service and went through the devices, the only one visible is the virtual machine, there is no other device.
Why hasn't the device transferred over, and is there a way to make this happen?

Thanks

Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,367 questions
{count} votes

4 answers

Sort by: Most helpful
  1. JimmySalian-2011 42,166 Reputation points
    2022-09-20T13:19:06.987+00:00

    Hi Stef,

    In Azure AD DS, only computer objects for computers that have explicitly domain-joined to the managed domain are shown. Also to note computer objects for computers joined to an on-premises AD DS environment aren't synchronized to Azure AD DS. These computers don't have a trust relationship with the managed domain and only belong to the on-premises AD DS environment.

    Check the sync objects in scope, and User accounts, group memberships, and credential hashes are synchronized one way from Azure AD to Azure AD DS. This synchronization process is automatic. You don't need to configure, monitor, or manage this synchronization process.

    243026-image.png

    ----
    Please don't forget to upvote and Accept as answer if the reply is helpful

    If this answer helped you please mark it as "Verified" so other users can reference it.

    0 comments No comments

  2. Stef Hambi 1 Reputation point
    2022-09-20T13:29:39.513+00:00

    Thanks for the reply Jimmy, so I'd need to rename the domain of the PC with the DNS of my AD, and that should allow it to be trusted and visible to AD DS? If that's the case, I receive an error when trying, stating that the AD DC for the domain could not be contacted - Do you have any guidance?

    Thanks again!

    0 comments No comments

  3. JimmySalian-2011 42,166 Reputation points
    2022-09-20T13:32:44.507+00:00

    Hi Stef

    Apologies if my answer was not clear I meant there is no way to sync device to AD DS as it is not supported and only devices that are connected or joined to managed domain are allowed. Hope this helps.

    242999-image.png

    ----
    Please don't forget to upvote and Accept as answer if the reply is helpful

    If this answer helped you please mark it as "Verified" so other users can reference it.

    0 comments No comments

  4. Stef Hambi 1 Reputation point
    2022-09-20T14:13:57.833+00:00

    Oh okay Jimmy I see, I appreciate you getting back to me so fast! Apologies for my misunderstanding but I have a few questions in regards to how this all works:

    So if computers can't be synchronised in AD DS, when I configure the group policies which are machined based, such as blocking USBs, that isn't possible? Only User based policies work?
    This is my main concern at the moment, trying to set policies and apply them to machines - Is there a method around this?

    Thank you!


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.