Remote laptop domain login

Derek Benak 20 Reputation points
2023-10-23T18:56:37.42+00:00

I have laptops Hybrid joined to an Azure/AD domain. I want remote users to have the ability to login that have never logged into their laptop before. The laptops are joined to our AD domain.

I am told users could do this in the past by logging in with the full e-mail address (ex. jdoe@cov.org) but this has stopped working. The user has been walked through connecting to their home network, but they get the domain is not available message.

  1. Is this even possible for Hybrid joined devices?
  2. What settings are needed to enable this functionality in 365 and/or on the laptop?

Thanks

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,759 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,769 questions
0 comments No comments
{count} votes

Accepted answer
  1. Akshay-MSFT 16,436 Reputation points Microsoft Employee
    2023-10-30T09:10:02.5+00:00

    @Derek Benak

    Thank you for posting your query on Microsoft Q&A, as per above description it seems like your end users are not able to login with there on prem UPN on Hybrid AD join devices with personal network.

    Please do correct me if this is not the case by responding in the comments section.

    Yes, this is true you could login with your on-prem creds when devices become hybrid AD join. However, you need to review on-premises AD users UPN support for Microsoft Entra hybrid join.

    • If on-premises AD users UPNs are different from your Microsoft Entra UPNs. In these cases, Windows 10 or newer Microsoft Entra hybrid join provides limited support for on-premises AD UPNs based on the authentication method, domain type, and Windows version. There are two types of on-premises AD UPNs that can exist in your environment.
    • You may also verify Microsoft Entra hybrid join state of 2 or 3 impacted devices.
    • Also if the devices haven't been in the domain network for considerable time then you need to bring them in as:

    Microsoft Entra hybrid joined devices require network line of sight to your on-premises domain controllers periodically. Without this connection, devices become unusable. If this requirement is a concern, consider Microsoft Entra joining your devices.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful