Can't disable Hybrid Azure AD Join in Azure AD Connect

Robert Panick 156 Reputation points
2023-06-28T15:40:49.5666667+00:00

We enabled Hybrid AAD Join using AAD Connect, we've since discovered it is writing computer objects to AAD without an associated user, or the wrong user. The issue is all of our computers join the domain with SCCM OSD task sequences, but no user has logged in. AAD Connect picks up the computer account and does the Hybrid AAD join, without the user, and at times using a service account used for the AD domain join operation.

We have decided to address this problem we will turn off Hybrid AAD Join in AAD Connector, and use SCCM to establish the Hybrid AAD Join since we can delay the operation until the user has had a chance to log in.

The problem comes is that we go into the AAD Connect > Device Options and select Configure Hybrid Azure AD Join, then under Device Systems turn OFF the "Windows 10 or later domain-joined devices" checkbox. Note the downlevel checkbox is also turned off. The problem is the "Next" button is not enabled so there is no way to continue.

At this point the only other option would be to tear down the AAD Connect and rebuild it, but we really don't want to do that because of issues that likely would occur.

Unfortunately, fixing the user record association with the computer would be a lot of work. Without the user association makes using Intune problematic in many ways.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-06-28T16:14:17.33+00:00

  2. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-06-28T17:14:56.45+00:00

    Well, I'm sure you have seen this:

    https://albandrodsmemory.wordpress.com/2021/04/15/how-to-disable-hybrid-azure-ad-join/

    But I cant vouch for it or if its supported


  3. Robert Panick 156 Reputation points
    2023-06-28T22:06:51.31+00:00

    It appears that the need may be moot. We ran some tests today and discovered that a computer created using SCCM OSD would register without a user as expected. When a user logged in the record in AAD updated quickly. Intune created a second record, but at least the user to computer association was there.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.