Thank you for posting this in Microsoft Q&A.
If you are looking to join any VM to Entra ID domain services, then you have to perform below steps,
- Connect the Windows Server VM to an Azure virtual network
- Join the VM to the managed domain
Main concept of getting using Entra ID domain services is Microsoft Entra Domain Services provides managed domain services such as domain join, group policy, lightweight directory access protocol (LDAP), and Kerberos/NTLM authentication. You use these domain services without the need to deploy, manage, and patch domain controllers (DCs) in the cloud.
When you create a Domain Services managed domain, you define a unique namespace. This namespace is the domain name, such as aaddscontoso.com. Two Windows Server domain controllers (DCs) are then deployed into your selected Azure region. This deployment of DCs is known as a replica set.
Note: There is no option to add additional domain controllers to this managed domain
You can only add Azure VM's to this managed domain.
If your scenario is something like, you have a DC in on-premises environment, and a domain controller in Azure, then you can follow below article,
https://learn.microsoft.com/en-us/azure/architecture/reference-architectures/identity/
Let us know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.