A cloud-based identity and access management service for securing user authentication and resource access
Hi @Nawal Almuajel,
Based on your query, here is my understanding: Devices are getting hybrid AD join without in sync scope.
In order to identify the devices are not in sync scope by any means, please make sure to search the device with device name in metaverse search of sync service manager. Here is the Microsoft document which might help you on the same: Sync Service Manager Metaverse Search.
As you have also configured SCCM for your devices, I believe this might also have some impact since the device has their own SCP configured from your end. Kindly re check whether SCP is running for the devices at any given time due to any policies.
If this does not help you and if there is no requirement of the device on Azure, you can swiftly remove the device from Azure and keep it as domain join in your on-premises. Once removed make sure there are no policies or the device object available in Entra AD connect or SCCM policies applied to the device. If there is any appear of the device again Entra ID, you can check the latest logs of Entra AD connect or SCCM policies then we might know exact cause of it and remove it accordingly.
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly "upvote it". If you have extra questions about this answer, please click "Comment".