Intune Configuration to Join OnPrem Domain

Vij 306 Reputation points
2023-05-22T21:02:39.52+00:00

There are few machines has enrolled to Intune with Azure AD Joined. As per the organization norms all machines should be Hybride Azure AD join.
since machines already part of Intune, can we run powershell script to join the end-user machine with On-Prem Domain? there are entry in the configuration profile with "Domain Join".

to join On-Prem Domain join the credentials are different. In the intune configuration profile there is no option to add different credentials.

Could you please help me with how can I join the Intune enrolled workstation to the on-prem domain join?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,715 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,322 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 42,956 Reputation points Microsoft Vendor
    2023-05-23T01:49:30.4+00:00

    @Vij, Thanks for posting in Q&A.

    For the domain join profile, it is only used during Autopilot Hybrid Azure AD join enrollment. And it is not supported in your scenario. Here is a link with more details:

    https://learn.microsoft.com/en-us/mem/autopilot/windows-autopilot-hybrid#create-and-assign-a-domain-join-profile

    If you want these devices to both join on premise domain and register to Azure AD, generally we called do Hybrid Azure AD join, based on my research, there's no direct method to convert it. I think we need unenroll the device from Intune and remove the device from Azure AD. Then configure Hybrid Azure AD join. After the device is Hybrid Azure AD joined, then we can choose GPO enrollment to do the enrollment.

    https://learn.microsoft.com/en-us/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy

    Or you can choose the Autopilot Hybrid Azure AD join method in above link.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.