Cloud-only account on hybrid joined device?

Vexxer_5 21 Reputation points
2019-12-03T10:57:06.527+00:00

Hello everyone,
we are planning to use hybrid joined devices (AD & AAD) in future as one step (of many) to a cloud-only approach.

What we are currently wondering (because it's not working in the lab environment):
Can a cloud-only user logon to a hybrid joined computer? Currently in our test environment it's not working. The company want's to have the On-Premise AD User Accounts removed in near future and use cloud-only accounts.

Thanks in advance

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,119 questions
0 comments No comments
{count} votes

Accepted answer
  1. soumi-MSFT 11,786 Reputation points Microsoft Employee
    2019-12-03T12:10:03.53+00:00

    @Vexxer_5 , If the machine is Hybrid AAD joined, a cloud only user wont be able to join, as while you login to a Hybrid AAD join machine, usually the user is present in both the on-prem and the cloud and only that user can login, because while logging into a Domain joined machine, the user first has to get authenticated by the on-prem Domain Controller before AAD checks the credentials.

    Second option is to go ahead with Azure AD Joined machine.

    Ref: https://learn.microsoft.com/en-us/azure/active-directory/devices/azureadjoin-plan

    ---------------------------------------------------------------------------------------------------------------------------------------

    Please take a moment to "Mark as Answer" and/or "Vote as Helpful" wherever applicable. Thanks!

    3 people found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Caroline Sanchez 6 Reputation points
    2020-07-08T21:34:19.007+00:00

    Found this thread while stumbling upon the following cloud only documentation. Thought it might help someone who finds this thread first.

    1 person found this answer helpful.
    0 comments No comments

  2. Biju Thankappan 101 Reputation points
    2019-12-03T16:26:49.093+00:00

    If in the future the plan is to completely move from On-Prem to AAD, then refer this article. Then, gradually decommission On-Prem AD DC's.

    Please take a moment to "Mark as Answer" and/or "Vote as Helpful" wherever applicable. Thanks!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.