Hybrid AD Join Pending

Alfred 1 Reputation point
2022-07-06T20:22:03.643+00:00

We are beginning to sync our devices to AAD in preparation for intune co-management. On a percentage of devices, we get them getting stuck in a 'pending state'. As per https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/pending-devices it would seem these have been synced previously, and then removed (this makes sense as apparently this was performed in our environment a few years back accidentally, where a OU was selected by accident).

  1. Is it possible to predict which of our devices will enter this state? I understand the devices are effectively hidden in AAD until they get re-synced. Can we see these dormant devices somehow?
  2. We have experience an issue when the device gets synced that our users lose their Windows hello settings and need to re-enroll. Additionally SSO breaks and they need to re-login - is this an expected behaviour?

Many thanks

Microsoft Configuration Manager
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,889 questions
{count} votes

1 answer

Sort by: Most helpful
  1. JimmySalian-2011 41,936 Reputation points
    2022-07-06T20:32:54.713+00:00

    Hi Alfred,

    AFAIK, this is a expected behaviour and did you tried the command mentioned in the article to export the existing devices that are in AAD?

    Also I will suggest to refer to this article and use the troubleshooting steps to export the existing device state, so you can extract the pending and registered devices for analysis.

    howto-hybrid-join-verify

    Hope this helps.

    Regards,
    Jimmy