Intune Enrollment

Joe Robinson 1 Reputation point
2022-12-27T22:54:29.527+00:00

Greetings:

Looking for a little guidance to help with the scenario I find myself in. I understand the scenario isn't optimal, but there isn't much I can to.

I have an on-premise synching to azure ad via AD Connect. I also have SCCM on premise. This combination provide a Hybrid-Ad experience that works rather well and was super simple to implement.

A business requirement mandates that one of our segments is going to be disconnected from our parent company and no connectivity can be established between sites. The machines will transition to a new .local domain, but the users will continue to use resources in the parten companies Azure tenant (exchange, sharepoint, teams, intune, etc).

Enabling Hybrid was easy with AD Connect and SCCM, but I'm struggling to find a good reliable way to bring this disconnected domain into Azure. My end goal is to provision the machine in Intune (preferably in an automated fashion) so I can deploy updates and software.

I've looked at a few different options...

  • Standing up a second AD connect server. Not supported, but I expect it would work until it didn't, and could blow lots of things up. (this isn't going to happen)
  • Using GPO to register machines with Intune. This just didn't work for me; gave me weird errors.
  • Autopilot. This worked for me, but when I handed the process off it didn't work for the remote techs.
  • Manual Registration. Struggled a little bit with this, and decided to spend some more time looking for automated methods.

I'm going to be looking at Hybird Autopilot tomorrow, but I thought I'd drop a message here and see if anyone had any advice. I'm not looking for a how-to or help with the error messages, I'm really just looking at what others have done and suggest doing in this type of a scenario. Any thoughts on this being a the best path for this type of topology, or should I move on and look at some other method.

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,436 Reputation points MVP
    2022-12-28T08:40:18.947+00:00

    So, if you want to keep a copy of disconnected domain (AD DS), how about to migrate DC to Azure? Not sure did I get your main problem right, just throwing ideas :)


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.