Hybrid Azure AD join computer procedure

roy lee 51 Reputation points
2021-01-25T09:35:01.303+00:00

Hi All,

We have configured AADC to sync on-prem AD object / password hash to O365 with ADFS for federation and access control.

We are planning to change our O365 from federated domain to managed domain, so we can dismiss the ADFS.
It will involve Hybrid Azure AD join our domain computers, setup Azure AD conditional access and then dismiss the ADFS, while keeping AADC to sync on-prem AD object / password hash to O365.

Original plan:

  1. Setup AAD hybrid join with federation domain.
  2. Windows 10 computer will auto AAD hybrid join.
  3. Setup Conditional Access rules.
  4. Change federation domain to managed domain.
  5. Change AAD hybrid join to managed domain.
  6. Dismiss ADFS.

According to Microsoft documents: "Beginning with Windows 10 1803, if the instantaneous hybrid Azure AD join for a federated environment by using AD FS fails, we rely on Azure AD Connect to sync the computer object in Azure AD that's subsequently used to complete the device registration for hybrid Azure AD join."

So I am thinking a new plan to simplify the steps:

  1. AADC sync WIndows 10 computer to AAD
  2. Setup SCP GPO to publish SCP to Windows 10 computers.
  3. Windows 10 auto do the AAD hybrid join.
  4. Setup Conditional Access rule.
  5. Change federation domain to managed domain.
  6. Dismiss ADFS.

Will this migration step work?

Thanks,
Roy

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} vote

8 answers

Sort by: Most helpful
  1. roy lee 51 Reputation points
    2021-02-11T01:57:43.39+00:00

    Hi @Abhijeet-MSFT ,

    dsregcmd show EnterprisePrt: No. Also no EnterprisePrtExpiryTime and no EnterprisePrtUpdateTime. How you know it is issued by ADFS?

    Attached the output of Get-AdfsRelyingPartyTrust -name "Microsoft office 365 identity platform worldwide" | FL *

    This is the only one Rely party in my ADFS.

    66688-get-adfsrelyingpartytrust.txt

    0 comments No comments

  2. roy lee 51 Reputation points
    2021-02-18T06:56:15.617+00:00

    Hi @Abhijeet-MSFT ,

    Any update?

    0 comments No comments

  3. roy lee 51 Reputation points
    2021-03-01T09:02:14.74+00:00

    Hi @Abhijeet-MSFT ,

    Waiting your reply.

    Or let it be?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.