Hybrid Join with Entra Domain Services

FoHe 5 Reputation points
2024-02-22T07:10:04.3666667+00:00

Hi all, do you know if it is possible to do a hybrid join with entra domain services? There is no local AD DS and no Entra connect. (We want to stay with the Entra Domain Services, but also want to use intune to manage the clients) thanks Andreas

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
{count} vote

2 answers

Sort by: Most helpful
  1. Akhilesh Vallamkonda 15,320 Reputation points Microsoft External Staff Moderator
    2024-02-22T09:34:19.1033333+00:00

    Hi @FoHe

    Thank you for posting your query on Q&A.

    For your query, I understand that you would like to know is it possible to do a hybrid join with Entra Domain Services without a local AD DS and Entra Connect.

    Hybrid join is a feature in Azure AD that allows you to have devices that are both joined to your on-premises Active Directory Domain Services (AD DS) and registered in Azure AD. This way, you can use both the on-premises and cloud-based tools and services to manage and secure your devices.

    Entra Domain Services is a cloud-based domain service that provides domain join, group policy, and LDAP access to Azure VMs. It does not require a local AD DS or Azure AD Connect.

    Intune is a cloud-based service that provides mobile device management, mobile application management, and PC management capabilities. It can manage devices that are joined to Azure AD or hybrid-joined to on-premises AD.

    For hybrid join you need to have a local AD DS and Entra Connect to configure Microsoft Entra hybrid join. Without these components, you cannot sync your devices to Microsoft Entra ID and leverage the benefits of hybrid join. So, it is not possible to do a hybrid join with Entra Domain Services without a local AD DS and Entra Connect.
    However, if you do not have the AD DS you can join the device to Microsoft Entra ID

    I hope this information helps! please Feel free to ask any questions you may have.

    Reference: https://learn.microsoft.com/en-us/entra/identity/domain-services/scenarios

    https://learn.microsoft.com/en-us/entra/identity/devices/concept-hybrid-join

    Thanks,

    Akhilesh.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

  2. Thameur-BOURBITA 36,261 Reputation points Moderator
    2024-02-22T07:35:43.6333333+00:00

    Hi @FoHe

    If you don’t have a onpremise domain, you can join Windows computer to AZure AD via Azure AD feature to be managed by intune :

    User's image

    Fore more details you can refer to :

    https://support.microsoft.com/en-us/account-billing/join-your-work-device-to-your-work-or-school-network-ef4d6adb-5095-4e51-829e-5457430f3973

    The hybride join configuration is used when you have a hybrid envirement that means an on-premise domain synced to Entra ID through Entra Connect. You don’t need to use this configuration to join computer to Azure because you don’t have a onpremise domain.


    Please don’t forget to accept helpful answer


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.