Hybrid Azure AD Join - Missing GPO regkey - Key Path: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CDJ\AAD

Tombstone2004 11 Reputation points
2020-06-02T12:23:35.56+00:00

Hi

We are currently following the below article:

https://learn.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-control

Specifically the section titled - https://learn.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-control#configure-client-side-registry-setting-for-scp

On our server 2016 box, when trying to create the new reg key under GPOs advised in the article we are unable to do so. Furthest it gets to in the key path is

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion/

There is no option of CDJ etc.....

Perhaps were missing something obvious here, any guidance on this would be appreciated.

Cheers

G

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,473 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Tombstone2004 11 Reputation points
    2020-06-03T08:14:10.563+00:00

    Believe this to be resolved, just needed to manually type complete the key ourselves in the key path field.

    Think that should do the trick!

    2 people found this answer helpful.
    0 comments No comments

  2. Jai Verma 461 Reputation points
    2020-06-02T12:31:00.197+00:00

    What is the version of OS from where you are trying to modify this registry? Did you try from the box where you want to block using GPMC?

    0 comments No comments

  3. Tombstone2004 11 Reputation points
    2020-06-02T13:02:47.383+00:00

    We are unable to modify any registry at the moment. The issue is the keypath does not exist in the gpo editor. The box we are trying from is a DC running server 2016 DataCenter edition, in gpo editor we go to

    Computer Configuration > Preferences > Windows Settings > Registry > Right-click on the Registry and select New > Registry Item

    Once in here when looking through the hives for the key path under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ there is no option for CDJ. The only C's we have are 'Casting' then next 'CEIP', no CDJ in sight.

    Hope this helps

    0 comments No comments