Targeted Hybrid Azure AD Join without clearing SCP?

Andrew Sader 0 Reputation points
2023-04-28T12:47:03.85+00:00

Hi All,

We are wanting to do a targeted HAADJ to test before rolling it out company wide. Everything i can find mentions clearing the SCP to our Azure tenant in AD, and pushing registry changes to the machines we want to HAADJ. The issue here is we are currently using the SCP to azure, and so we cant remove it.

All of our devices are currently listed in azure as Azure AD Registered if that helps.

As far as i understand it, whenever windows devices login they check locally for the azure tenant details, and if they dont find them they check AD.

Are we able to manage this via group policy to tell them not to try to hybrid join?

I have found instances online where this did not work, and all of the devices tried to hybrid join despite group policy.

Advice is appreciated.
Thanks,

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
3,697 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
17,577 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 36,666 Reputation points Microsoft Vendor
    2023-05-01T02:09:51.8966667+00:00

    @Andrew Sader, Thanks for posting in Q&A. Based on my previous testing in my lab. I find when I choose one OU with the devices which I want to do Hybrid Azure AD join to enable Password Synchronization, only the devices in this OU will do Hybrid Azure AD join, others will not.

    You can reconfigure the "Custom synchronization options" in Azure AD connect to see if it can meet your requirement.

    User's image

    User's image

    User's image

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.