Moving from ADFS, hybrid with device write back to just hybrid joined AAD Connect

Tori Alfeld 0 Reputation points
2023-11-30T20:20:26.2833333+00:00

Hi we are currently migrating our AAD Connect server.
We used to use ADFS (server has been terminated) with device write back, as well has having Hybrid Azure AD Join enabled in "Configure Device Options". The options for ADFS are still in the old connector.

New AAD Connect setup has Hybrid Azure AD joined only enabled, pre being brought out of staging I can see it wants to sync/add a huge number of disconnectors devices and appears to change the attributes on the added devices versus what was in device write back.

Will this break anything switching to just Hybrid Azure AD join instead of write back seeing as we don't have ADFS anymore? Will adding all these devices break anything, as they already existed via write back but with different attributes used?

User's image

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,490 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 145K Reputation points MVP
    2023-11-30T20:40:04.9633333+00:00

    I suspect as long as that SCP exists in AD, you will see those disconnections, otherwise I dont think it hurts to not enable it.

    Take a look at this thread as well:

    https://learn.microsoft.com/en-us/answers/questions/1320600/cant-disable-hybrid-azure-ad-join-in-azure-ad-conn