Hybrid Azure AD joined status in pending

Vij 316 Reputation points
2023-07-31T18:06:23.43+00:00

There are few machines "Hybrid Azure AD joined" status is in the Pending stage.

Same machine in OU where configured Hybrid Azure Sync & Intune enrolment GPO. There are three entries in Azure , two entries for "Azure AD registered" with two user IDs & other entry is "Hybrid Azure AD joined" with user status is none with pending stage.

How to stop the automatic "Azure AD registered" from Azure level.?

The pending stage is how to remediate. Still, the machine is part of the correct OU.?

Screenshot 2023-07-31 at 11.16.08 PM

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,483 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,277 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Ajinkya Ghare 155 Reputation points
    2023-07-31T18:22:38.17+00:00

    This problem can occur in the following scenario:

    1. The device object is moved to another organizational unit (OU) that isn't in the sync scope in Azure AD Connect Sync.
    2. Azure AD Connect Sync recognizes this change as the device object being deleted in the on-premises Active Directory. Therefore, it deletes the device in Azure AD.
    3. The device object was moved back to the OU in the sync scope.
    4. Azure AD Connect Sync creates a pending device object for this device in Azure AD.
    5. The device fails to complete the device registration process because it was registered previously.

    To fix the problem, unregister the device by running dsregcmd /leave at an elevated command prompt, and restart the device. The device will reinitiate the device registration process through the scheduled task. For Windows 10-based devices, the scheduled task is under Task Scheduler Library > Microsoft > Windows > Workplace Join > Automatic-Device-Join Task.

    https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/pending-devices

    Thanks

    Ajinkya Ghare

    Follow me on LinkedIn

    If my reply helped, please mark it as helpful,

    If it fixed your problem, please mark it as the answer

    1 person found this answer helpful.
    0 comments No comments

  2. Crystal-MSFT 53,821 Reputation points Microsoft External Staff
    2023-08-01T01:23:23.58+00:00

    @Vij, Thanks for posting in Q&A. From the picture you provided, I find the device did Azure AD registered and enroll into Intune last year. And now it seems you want to do GPO enroll for this device. If there's any misunderstanding, feel free to let us know.

    For your situation, I suggest remove all the device records with this device in Intune firstly. Then remove the three records in Azure AD portal. After that do Hybrid Azure AD join again and see if it can work.

    Meanwhile, for this device, please ensure the device object and user you login this device has sync to Azure AD.

    However, if the issue still persists, please read the following link to do the troubleshooting:

    https://learn.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-hybrid-join-windows-current

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.