I need to know how best to move a set of workstations from a failed on-premise domain to Azure AD

Jeffrey Quibell 20 Reputation points
2023-01-17T16:09:26.31+00:00

I have a small client with an on-premise domain. The domain controller has failed and there is no backup. Their workstations are domain joined. They all have Microsoft 365 business premium licenses. The Azure AD Domain is not synced or even aware of the on-premise domain. What is the least disruptive way to move the user workstation to Azure AD management without losing any of their personal files. I moved one of them by creating a local administrator account and then unjoining the workstation from the domain. Logged in as the local user. connected that user to the Azure AD. As it connected, they were prompted to create a windows hello pin but failed to do so because they had MFA enabled and they could not logon or restore the authenticator. They can complete logging in using their azure ad user account and just skip the pin. The move was successful.

two questions

  1. is there a smoother way to make this transition.
  2. How do we complete the pin creation without the authenticator or at least get the authenticator back working?
Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,771 questions
Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
557 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,296 questions
0 comments No comments
{count} votes

1 additional answer

Sort by: Most helpful
  1. Thameur-BOURBITA 35,596 Reputation points
    2023-01-17T17:25:27.2566667+00:00

    Hi,

    If the the on-premise domain is dead, you can disable directory synchronization , in order to be able to manage synchronized accounts in azure AD through azure portal : Disable Azure AD synchronization without losing synchronized accounts

    Once the synchronization is disabled , you can go to Azure portal to fix the MFA/authicator setting on impacted user account.

    Please don't forget to accept helpful answer


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.