Entra hybrid join

2024-05-21T07:01:56.8566667+00:00

All devices in my tenant are Azure ad registered + on premises ad joined when i enable entra hybrid join in entra connect it will automatically convert to entra hybrid join or I have to manually unenroll this devices from azure ad registered and then enable entra hybrid join to convert into entra hybrid join devices.Note: all devices are above windows 1903. we are using adfs.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Akhilesh Vallamkonda 15,320 Reputation points Microsoft External Staff Moderator
    2024-05-29T14:00:00.9633333+00:00

    Hi @Srinivas Pasupuleti - CyberSecurity

    Thank you for post!

    When you enable Hybrid Azure AD join in Microsoft Entra, devices that are already Azure AD registered and on-premises AD joined will not automatically convert to Hybrid Azure AD join you will need to manually unenroll these devices from Azure AD registered and then enable Entra hybrid join to convert them into Entra hybrid join devices.
    Any existing Microsoft Entra registered state for a user would be automatically removed after the device is Microsoft Entra hybrid joined and the same user logs in.
    For more readings https://learn.microsoft.com/en-us/entra/identity/devices/hybrid-join-plan#handling-devices-with-microsoft-entra-registered-state
    https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join
    https://learn.microsoft.com/en-us/entra/identity/devices/hybrid-join-control
    Hope this helps. Do let us know if you any further queries.

    Thanks,
    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


2 additional answers

Sort by: Most helpful
  1. Abiola Akinbade 29,490 Reputation points Volunteer Moderator
    2024-05-21T08:40:09.6866667+00:00

    Hello Srinivas Pasupuleti - CyberSecurity,

    Thanks for your question.

    You can convert to Hybrid join and it will work fine when you enable.

    However, you do have to note that there will be a duplicate entry at first, which will be cleaned up eventually. This was experienced by other users in the community. See links here:

    https://techcommunity.microsoft.com/t5/microsoft-entra/from-azure-ad-registered-devices-to-hybrid-azure-ad-joined/m-p/290775

    https://techcommunity.microsoft.com/t5/microsoft-intune/converting-azure-registered-device-into-hybrid-azure-ad-joined/m-p/3891097

    Please let me know if you have further questions

    You can mark it 'Accept Answer' if this helped.


  2. Srinivas Pasupuleti - CyberSecurity 40 Reputation points
    2024-06-13T14:25:40.68+00:00

    In my organization devices are azure ad registered(intune enrolled)+ domain joined .when i enable entra hybrid join it shows dual state like entra registered(intune) and entra hybrid joined in entra id.How can i make entra hybrid joined to Intune enrolled and removed the entra registered state.Around 1000 devices are their it is difficult form me to manually unenroll intune& entra registered device and enroll to hybrid join and intune enroll.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.