User-driven Microsoft Entra hybrid join: Install the Intune Connector

Autopilot user-driven Microsoft Entra hybrid join steps:

  • Step 2: Install the Intune Connector

For an overview of the Windows Autopilot user-driven Microsoft Entra hybrid join workflow, see Windows Autopilot user-driven Microsoft Entra hybrid join overview.

Note

If the Intune Connector is already installed and configured, skip this step and move on to Step 3: Increase the computer account limit in the Organizational Unit (OU).

Install the Intune Connector

Turn off Internet Explorer Enhanced Security Configuration

  1. Sign into the server where the Intune Connector is being installed with an account that has local administrator rights.

  2. Turn off Internet Explorer Enhanced Security Configuration on the server. By default Windows Server has Internet Explorer Enhanced Security Configuration turned on. To turn off Internet Explorer Enhanced Security Configuration:

    1. On the server where the Intune Connector is being installed, open Server Manager.

    2. In the left pane of Server Manager, select Local Server.

    3. In the right PROPERTIES pane of Server Manager, select the On or Off link next to IE Enhanced Security Configuration.

    4. In the Internet Explorer Enhanced Security Configuration window, select Off under Administrators:, and then select OK.

Download the Intune Connector

  1. On the server where the Intune Connector is being installed, Sign into the Microsoft Intune admin center.

  2. In the Home screen, select Devices in the left hand pane.

  3. In the Devices | Overview screen, under By platform, select Windows.

  4. In the Windows | Windows devices screen, under Device onboarding, select Enrollment.

  5. In the Windows | Windows enrollment screen, under Windows Autopilot, select Intune Connector for Active Directory.

  6. In the Intune Connector for Active Directory page, select Add.

  7. In the Add connector window that opens, select Download the on-premises Intune Connector for Active Directory under step 2 of Configuring the Intune connector for Active Directory. The link downloads a file called ODJConnectorBootstrapper.exe.

Install the Intune Connector on the server

  1. Open the ODJConnectorBootstrapper.exe file that downloaded to launch the Intune Connector install.

  2. In the Intune Connector for Active Directory Setup installer window, select I agree to the license terms and conditions, and then select Install.

    Note

    If an install location other than the default of C:\Program Files\Microsoft Intune\ODJConnector is desired, select Options and specify the desired install location.

  3. When the install completes, select Configure Now in the Intune Connector for Active Directory Setup installer window.

    Note

    If Close is accidentally selected or the Intune Connector for Active Directory Setup installer window is accidentally closed, the Intune Connector for Active Directory configuration can be accessed by selecting Intune connector for Active Directory > Intune connector for Active Directory from the Start menu.

  4. In the Intune connector for Active Directory window:

    1. Under the Enrollment tab, select Sign In.

    2. Under the Sign In tab, sign in with the credentials of an Intune administrator role. The user account must have an assigned Intune license. The sign in process might take a few minutes to complete.

    3. Once the sign in process is complete, a The Intune connector for Active Directory successfully enrolled confirmation window appears. Select OK to close the window. The Enrollment tab shows Intune connector for Active Directory is enrolled and the Sign In button is greyed out.

    4. Close the Intune connector for Active Directory window.

  5. In the Microsoft Intune admin center, close the Add connector window if it's still displayed.

  6. In the Intune Connector for Active Directory page, confirm that the server is displayed under Connector name and shows as Active under Status. If the server isn't displayed, select Refresh or navigate away from the page, and then navigate back to the Intune Connector for Active Directory page.

Note

  • The account used to enroll the Intune connector is only a temporary requirement at the time of installation. The account isn't used going forward after the server is enrolled.

  • It can take several minutes for the newly enrolled server to appear in the Intune Connector for Active Directory page of the Microsoft Intune admin center. The enrolled server only appears if it can successfully communicate with the Intune service.

After the Intune Connector is installed, it will start logging in the Event Viewer under the path Applications and Services Logs > Microsoft > Intune > ODJConnectorService. Under this path, the Admin and Operational logs are found.

Next step: Increase the computer account limit in the Organizational Unit (OU)

For more information on the Intune connector, see the following article: