Microsoft Entra ID | Hybrid Azure AD Join Devices | Managed Domains

Поділитися
Вставка
  • Опубліковано 2 жов 2024

КОМЕНТАРІ • 188

  • @emirmoneer3090
    @emirmoneer3090 3 роки тому +5

    Better than most PAID teachers honestly

  • @lostray117
    @lostray117 2 роки тому +1

    Thank you very much!
    Your Video and explanation ist brilliant!
    Your are the only one who explain the issues when the hybrid ad join is not working because of the connectivity to the urls / internet.

  • @fisheridle6886
    @fisheridle6886 4 роки тому +23

    Great work! Really appreciate this! It's crystal clear, and looks like an anatomy against the things behind. It saves me tons of hours reading those MS poor organized documentation. Thanks, man!

  • @gabrielalicea4803
    @gabrielalicea4803 3 роки тому +1

    Watching this for the third time and it’s great quality work. Thank you again.

  • @niranmanandhar8517
    @niranmanandhar8517 4 роки тому +2

    very impressed and happy with the level of explanation you have provided in this video. Getting to learn quite a few things

  • @abhimanyusinghshekhawat6871
    @abhimanyusinghshekhawat6871 4 роки тому +1

    Love hearing you.. crisp and clear.

  • @widodoboedijono9374
    @widodoboedijono9374 4 роки тому

    Simple, Brief, and Very Clear

  • @charliemelga7445
    @charliemelga7445 2 роки тому +1

    Great video, with some good tips, thanks very much for taking the time to create and post :)

  • @rizomarshal7483
    @rizomarshal7483 5 років тому +7

    thanks a LOT!!!! for this great tutorial - deep explained of the overall hybrid process and component.
    learned a lot :)

  • @sandeep909b
    @sandeep909b 3 роки тому +1

    Quality Stuff.. very nice deep dive👍

  • @abulaith4485
    @abulaith4485 5 років тому +6

    Another great technical video.
    Do you work for Microsoft?

  • @Productivity365
    @Productivity365 4 роки тому

    Thanks for sharing such informative videos

  • @Sanddancer75
    @Sanddancer75 2 роки тому +4

    Possibly the most concise but informative video I've ever seen on UA-cam. Very very well done.

  • @Henry1973
    @Henry1973 4 роки тому +6

    I love how you showed the ways we can troubleshoot the process, the detail you explain of how the process works and the concept of it. This was a great video and has set the standard for concepts work in my mind, i subscribed!

  • @arifshaikh213
    @arifshaikh213 3 роки тому

    Awesome explanation 👏🏼👏🏼

  • @navneetsingh9592
    @navneetsingh9592 2 роки тому +1

    Excellent video, Thanks for explaining the concept. Just one question, your machine is in workgroup , so how come it gets the task ? Is it there for all windows 10 machines by default and gets enabled only when it joins the domain and if hybrid AAD is enabled?

  • @du1vbs
    @du1vbs 4 роки тому +2

    Beautifully explained. Thank you so much for sharing your knowledge.

  • @cryptoguru7630
    @cryptoguru7630 4 роки тому +2

    Nice explanation 👌👍

  • @thedavid1174
    @thedavid1174 4 роки тому +3

    This is an amazing video, I love how you go into detail about what is happening in the background. Certainly subscribing :)
    Quick question. I managed to get this far, but do you have any video on how to get them managed and into InTune after this step and after they are Hybrid joined?

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      Hi David, thanks for the kind words.
      Just wanted to understand your requirement related to intune.
      The device which are hybrid azure ad joined are already managed through on-prem, can you please share some more details in terms of how you want to manage the from intune.

    • @thedavid1174
      @thedavid1174 4 роки тому +1

      ​@@ConceptsWork We are in the process of purchasing 150 laptops for staff that will be used both onsite and offsite. If they are onsite, they will be either connected via cable to our main network, or on our corporate wifi for direct access to the DCs and managed via traditional on-prem group policies etc.
      I am pretty new to InTune, but we want to basically make sure all of our devices are registred to InTune so that we can retain some sort of control when they are off-network too.
      I managed to get this working though. Initially, for those devices that are Hybrid Joined, the MDM was showing as "None". However, after making some GPO changes, my devices now are showing as Hybrid Joined with InTune as their MDM. We are not really going to configure much on InTune, but it will be nice to have the option to in the future. I hope this make sense, and I hope this is a correct use-case for InTune.
      BYOD devices, at the moment, we're not really expecting to get onto InTune or Azure Joined.

  • @anniesrivastava2276
    @anniesrivastava2276 2 роки тому +1

    Sir you are great.. is there any way we can ever see you or meet you..it would be a great pleasure.. you have an exceptional skills to explain such difficult topics so easily

  • @cool2685
    @cool2685 2 роки тому

    First of all, i Really appreciate your efforts!! I have one question, how we manage device which joined the already domain joined, Do we need to reconfigure it in domain? and second thing will it work for those devices which is on VPN?

  • @chetansharma6595
    @chetansharma6595 2 роки тому

    Please make a detailed video on how a device get PRT.

  • @sumeetkumar6900
    @sumeetkumar6900 4 роки тому +2

    Instantly subscribed :) beautifully explained Sir. Do you also have ADFS tutorials ?

    • @ConceptsWork
      @ConceptsWork  4 роки тому +1

      ua-cam.com/play/PL8wOlV8Hv3o9uHl0XFfI6_katp6BXNVjb.html

  • @yousefbableh5611
    @yousefbableh5611 4 роки тому +4

    The is great presentation, I subscripted, I have one question!! why you have disjoin and rejoin the devise to on prem AD, it will not work if you just enable internet to populate the certificate?

    • @Southpaw07
      @Southpaw07 3 роки тому

      yes, i have the same question. seems a little confusing and hoping don't have disjoin machines to get ADHybrid join to work.

  • @ramyogeshwaran
    @ramyogeshwaran 3 роки тому +1

    I hope before post the each video. I could see your hard work. Keep post the new videos.

  • @gabrielalicea4803
    @gabrielalicea4803 4 роки тому +1

    Outstanding presentation and attention to detail. This video made me subscribe to your channel. Well done.

  • @kanikagambhir2592
    @kanikagambhir2592 2 роки тому +1

    The content is really good and the way you explain the concepts is commendable. Also the settle tone of explaining the concepts helps in understanding them easily...Keep continue the good work.....Only thing that I found missing is that "content ppt" is not available anywhere for the revision purpose....If it's available somewhere please share the location.
    ..... Thank u.

    • @ConceptsWork
      @ConceptsWork  2 роки тому

      Hi Kanika, though there is a membership, for this, but if it is only this PPT that you need, please send us an email at learnconceptswork@gmail.com

  • @robinraju4321
    @robinraju4321 4 роки тому +2

    Wonderful video. well explained

  • @PavanKumargurijala
    @PavanKumargurijala 3 роки тому +1

    excellent explanation

  • @phucmac5312
    @phucmac5312 3 роки тому

    question for you. I'm running into this issue where I keep getting this error
    auto MDM ENroll Get ADD Token: Device Credential (0x0) Resource url (Null)( UNknown win32 error code 0x801800b.
    everything work great on my lab, but in productions I can't get past that on the event viewer.

  • @williamkass9057
    @williamkass9057 4 місяці тому

    If I have a user that isnt located within the Office(DOmain LAN) but has a company laptop that was joined to the on-prem domain when the laptop was setup in the past. If I migrate my infrastructure to Azure AD how am i able to get the aformentioned user endpoint to join the new AZURE AD domain with out making the user go to an office lan.

  • @nithyanadhamsingaravadivel8547

    Hi, Your vidoes are really informative, lets say if my domain. Joined devices are already synced to Azure AD as the device type "Azure AD registered", In this case, does this method would help us to delete the device type "Azure AD registered" and pefform the new device registration as "Hybrid AD joined" ? If this is posisble ? What will be impacts when the device is removed and registered again in azure as hybrid joined devices ?
    With the SCP created in Active Directory, how can we perform the phased roll out for hybrid device registration in Azure AD? Does selecting the appropriate OU's would help us with the phased roll out ?
    Also how can we avoid the automatic device enrollment of hybrid joined devices to microsoft intune ? Is adjusting MDM scope the only option ? Or we can keep MDM scope set to all users and adjust somewhere else in the Microsoft intune portal to avoid the auto enrollment of windows hybrid joined devices to Microsoft intune ?

  • @alfonsorodriguez5449
    @alfonsorodriguez5449 3 роки тому +1

    Best technical deep dive in Azure AD Hybrid Join

  • @belzebubas
    @belzebubas Рік тому

    Ok. This is great. How about machines that are already on the OnPrem domain? What if I have 100 machines. Does this mean I'll have to disconnect and rejoin the domain in order for these machines to get Azure AD hybrid Joined?

  • @ameerthoughts848
    @ameerthoughts848 3 роки тому +1

    very nice class

  • @harrichavan789
    @harrichavan789 4 роки тому +1

    This is deep dive about behind the scene of Azure Hybrid Join thanks for such video

  • @silerauk366
    @silerauk366 2 роки тому

    Great work..indeed..Could you pls explain on how to go AD configuration partition using adsi edit ? Appreciated...

  • @manjitbhatia9909
    @manjitbhatia9909 4 роки тому +1

    Great Contribution and very well explained ... awesome tutorial ..

  • @vin21711487
    @vin21711487 3 роки тому +1

    Will this method of joining sync my on prem domain joined devices to Azure AD and Intune Endpoint Manager for managing the devices from there? If not could you suggest a solution which will enable me to enroll domain joined local existing computer devices to sync to intune devices for management ?

    • @ConceptsWork
      @ConceptsWork  3 роки тому +1

      Make sure you have enabled automatic enrollment in Endpoint manager portal and MDM scope is also set for all the users. In this case when the user will join the device to Azure AD, it will be automatically enrolled to MDM, also if you deployed the onboarding to Microsoft defender for endpoints that will also happen seamlessly.

  • @lyfrocks5554
    @lyfrocks5554 4 роки тому +1

    Brilliant. Thanks for sharing this. Subscribed.

  • @mask3809
    @mask3809 3 роки тому +1

    perfect

  • @flymoracer
    @flymoracer 4 роки тому +1

    Thanks. If I query AAD using get-msoldevice poweshell command, it returns a DeviceTrustType of 'Domain Joined' for a device that is listed in the portal as Hybrid AD Joined. Is this correct?

  • @ashoksan14
    @ashoksan14 2 роки тому

    Can we join windows server to Azure AD without Azure ADDS and OnpremADDS infra.

  • @TITOMIKEE89
    @TITOMIKEE89 3 роки тому

    Hello,
    its me again, what if i have a domain joined devices that i want to hybri joined. will i need to take them out of the domain and rejoined to get the Usercertificate populated?

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      No, once the hybrid process is completed, I mean the machine is able to contact the respective endpoints, user certificate attribute will be populated.

  • @ravisuj
    @ravisuj Рік тому

    Thanks for creating and sharing such excellent content. If there are two AD connect servers (one in staged mode) is it needed to run the wizard for hybrid Azure AD join on the staged server also?

    • @ConceptsWork
      @ConceptsWork  Рік тому

      Yes, this will keep the configuration file, identitical on all the servers.

  • @StephenKunstmann
    @StephenKunstmann 4 роки тому +1

    Hi, very good video! Exactly what I needed to know :) Quick question - ist it possible to use my UPN/Azure AD account to login to such a hybrid joined device?

    • @ConceptsWork
      @ConceptsWork  4 роки тому +1

      Unfortunately not, as the authentication authority for users is still on-prem AD.

  • @ThePaulSIN
    @ThePaulSIN 4 роки тому +2

    Great video! What happens to a PC that is already a member of the local AD when you enable the hybrid sync and you set the policy as you suggested. Will they automatically be hybrid joined with no action from the local PC side (accept maybe a reboot)?

    • @ConceptsWork
      @ConceptsWork  4 роки тому +4

      This applies to Windows 10 1709 or above:-
      "If a machine is already joined to Active Directory, the moment you enable device registration from AAD connect, the SCP of the tenant gets registered in AD, now from the next time when device registration will be triggered the machine will create the cert and save it in the machine object.
      When this object is synced to azure AD in next sync cycle, the user will start receiving PRT.

    • @taksiobs
      @taksiobs 4 роки тому

      @@ConceptsWork okay, so i don't have to disjoin the machine and rejoin it just like what you did right?

    • @riyazqureshi8906
      @riyazqureshi8906 2 роки тому

      @@ConceptsWork when will the next time device registration trigger if the machine is already domain joined, does it happen when synchronisation cycle happen next time?

  • @marctemplin366
    @marctemplin366 3 роки тому

    Thanks for this video. It's very helpful. If a hybrid joined device is active on the internet, is that activity registered in on-prem AD? We have a policy to disable devices that haven't been active on the domain for 3 months so I wondered if a device is hybrid joined and active on the internet, would that activity prevent the on-prem object from being disabled?

  • @devraj_thezeus
    @devraj_thezeus 2 роки тому

    If i create AD and a client vm in hyper v and use default switch for network will this whole thing work

  • @riswanthnsai7144
    @riswanthnsai7144 4 роки тому +1

    Great contribution to the learners and videos are really useful

  • @WoTpro
    @WoTpro 3 роки тому +1

    great video thanks for your efforts

  • @SanjeevKumar-hs6gp
    @SanjeevKumar-hs6gp 3 роки тому +1

    Nice Informative Video !

  • @nareshkumarshetti6073
    @nareshkumarshetti6073 2 роки тому

    Join type information is blank on azure portal, may I know the reason.

  • @brunomarcelo880
    @brunomarcelo880 3 роки тому +1

    U nailed thank you so muchhhhhhh

  • @TahaTaha-sz3zk
    @TahaTaha-sz3zk 3 роки тому

    Can you view the certificate in certificate store ? I don’t see it in machine private

  • @BindasBadshah
    @BindasBadshah 3 роки тому +1

    This was so amazing. Very well thought of and covered every aspect of HADDJ. Thanks,

  • @robinraju4321
    @robinraju4321 4 роки тому +1

    Clear Explanation ...thanks a lot

  • @NitinKumar-pd9nt
    @NitinKumar-pd9nt 5 років тому +1

    Hi, It was a nice explanation. My Question - In an environment where win10 and win7 machines are already joined to local domain, how to initiate Hybrid setup?

    • @ConceptsWork
      @ConceptsWork  5 років тому +5

      Start from enabling Hybrid Azure AD join from AAD connect, make sure all the network configuration is in place.
      When the SCP and the network endpoints are enabled win 10 will get automatically joined.
      For windows 7 check this article - docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains#enable-windows-downlevel-devices

  • @techmaster6166
    @techmaster6166 4 роки тому +1

    Great video and brilliant explanation, i have been watching few videos of different series, just one comment, in my opinion when you make series if you could number your videos then it will easier to watch all of them in order, let say intune part 1 or lecture 1, great work please keep it up

  • @prabaselvam
    @prabaselvam 4 роки тому +1

    can we do hybrid AD JOIN for windows server 2019(Instead of windows 10)?

  • @taksiobs
    @taksiobs 3 роки тому +1

    My device is showing hybrid ad join but i can't manage it from intune still.

    • @ConceptsWork
      @ConceptsWork  3 роки тому +1

      There must be PRT on the device and verify is the GPO has reached the device.

    • @taksiobs
      @taksiobs 3 роки тому

      @@ConceptsWork thanks for your reply but what's a PRT?

    • @ConceptsWork
      @ConceptsWork  3 роки тому +1

      PRT is token that is device specific - docs.microsoft.com/en-us/azure/active-directory/devices/concept-primary-refresh-token#:~:text=A%20Primary%20Refresh%20Token%20(PRT,applications%20used%20on%20those%20devices.

    • @taksiobs
      @taksiobs 3 роки тому

      @@ConceptsWork thanks much! let me read this. i'm scratching my head since.

  • @pg4694
    @pg4694 2 роки тому

    Nice

  • @phucmac5312
    @phucmac5312 3 роки тому

    Great Video, assuming since this manual enrolled, but if I want to autopilot i would need to install the intune connector?

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      Yes with auto pilot you need connector and line of site of DC.

    • @phucmac5312
      @phucmac5312 3 роки тому

      @@ConceptsWork my current environment is a hybrid, I haven’t setup intune connector yet. will you still be able to do the manual enrollment and join machine to hybrid AD join even though you have autopilot set up? Currently my environment is small everything has been setup manually and manual AD join.

    • @phucmac5312
      @phucmac5312 3 роки тому

      I see that the machine is azure AD join. but MDMurl and MDMtouurl are empty, how do you fix that? cause it to register with as hybrid ad join, but can't push application nor policy to it.

  • @WelcomeWithinMyDream
    @WelcomeWithinMyDream 4 роки тому +1

    Awesome video! Quick question from me since I want to be sure I understood correctly the information. For the 4 urls, for Win10 the laptop needs to have internet access to said urls (an entry in Site to zone) is not required, while for lower OS, it is mandatory to provide the entry. Is this correct? Ty for your time, content and knowledge share!

    • @ConceptsWork
      @ConceptsWork  4 роки тому +1

      Yes, for windows down level devices, all these links should be added as seamless sso is one of the pre-reqs.

    • @taksiobs
      @taksiobs 4 роки тому

      @@ConceptsWork oh! so if all my devices are windows 10, then no need to add these URLs?

  • @lakergreat1
    @lakergreat1 3 роки тому

    What steps would have I have to setup if I WASN'T seeing AzureADPRT:YES, and instead it said NO?

  • @macro8681
    @macro8681 4 роки тому +1

    Great video. Well done!
    Do you know if there is a method for migrating systems from hybrid Azure AD joined to fully Azure AD joined and doesn't involve manually touching every system?

    • @ConceptsWork
      @ConceptsWork  4 роки тому +1

      As of now there is no method to Migrate machines from on-prem to Azure AD.

    • @taksiobs
      @taksiobs 4 роки тому

      @@ConceptsWork unless you want everything fresh or user 3rd party tools to migrate user profiles. am i right?

  • @joshandres4964
    @joshandres4964 Рік тому

    If I want to have my device listed on AAD but use a different IDP like Okta, will I have to rejoin those machines if I switch from AAD IDP to Okta?

  • @Ambedkarites_Indian
    @Ambedkarites_Indian Рік тому

    Great sir, thank you very much.

  • @qamarqureshi2874
    @qamarqureshi2874 3 роки тому

    I can see you joined one machine in Hybrid Azure AD but what if i have 100 or 500 client machines in my organization to join Hybrid Azure AD. do i need to go and join them manually to Azure Ad domain ? also process will be same for client machine and windows servers ?

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      No, you don't have to do it manually, if all the config is in place as well as machines get line of site to DC, it will work as expected.

  • @shahzadansari9728
    @shahzadansari9728 Рік тому

    Can we expect more Azure Security videos AZ 50

  • @ytho7618
    @ytho7618 Рік тому

    thanks for making these great videos

  • @vivek.padale
    @vivek.padale 4 роки тому

    Hi,
    Thanks for sharing this awesome content. I will appreciate if you help with my query.
    If my on-prem ADDS and Azure ADDS are sync with AAD connect, can i use Azure ADDS to authenticate and authorize on-prem users for internal or intranet resources.
    And also can i use Azure ADDS as a DR solution for On-prem ADDS.
    Regards,
    Best of Luck!!!

  • @priyankareddy3587
    @priyankareddy3587 3 роки тому

    We have done configuration in azure ad connect with all prerequisites met.Will the device registration be pending in portal until user login to client machine to complete hybrid join?? Or automatically the device registration gets completed after certian period of time in Azure portal and the client machine will be hybrid join??

    • @ConceptsWork
      @ConceptsWork  3 роки тому +1

      The activity timestamp will only be populated when there is a valid PRT on the device.
      As soon as the device is synced from on-prem, portal shows that device as hybrid, but the activity time stamp also has to be populated.

  • @sayedhasanalalawi749
    @sayedhasanalalawi749 2 роки тому

    Good job, but I have one question. To join a device as a hybrid AD join, is it a must to connect it to the work network? Or it can be joined remotely from home for example?

    • @ConceptsWork
      @ConceptsWork  2 роки тому

      The machine must have line of site to DC, which in turns fall back to connectivity to on-prem network.

  • @michaelpietrzak2067
    @michaelpietrzak2067 3 роки тому +1

    Great video!

  • @HOKING-ef8dj
    @HOKING-ef8dj 4 роки тому +1

    Fantastic videos !

  • @paolodifrancesco4319
    @paolodifrancesco4319 4 роки тому

    Tahnks for stunniung video tutorial! I'm concerned abou if my laptop goes out of enterprise network...domain authentication will work even local domain controller is not accessible? Again...if i change my password out of enterprise network it will be write back do on prem AD? thanks

  • @kpanagos
    @kpanagos 4 роки тому +1

    Great guide !!! Thank you very much.

  • @phanihishi
    @phanihishi 2 роки тому

    Great video! Can't dive deeper!

  • @kosalyeang2101
    @kosalyeang2101 2 роки тому

    It's a great guide video.

  • @tranghienkhoa
    @tranghienkhoa Рік тому

    WOW YOU ARE THE BEST!!!! ❤

  • @CaptDarksoul
    @CaptDarksoul 4 роки тому

    How do you remove old management objects before you add the new HAAD joined process?

  • @babrdwod7464
    @babrdwod7464 2 роки тому

    Outstanding explanation. Please keep publishing these videos!

  • @007Joelsky
    @007Joelsky 3 роки тому

    Awesome!! What you explained from 13:14 is exactly what I needed to know! Thanks

  • @Wiseparentsclub
    @Wiseparentsclub 2 роки тому

    Thank you for such as in depth explanation.

  • @bartoszjelen326
    @bartoszjelen326 3 роки тому

    Great Video ! 2 questions :
    1. When I get to configuration Part I don't have a option to configure SCP why ?
    2. I have about 5-6 Domain Controllers in single forest. It looks like users are synchronize properly as hybrid azure joined only if there are connected to DC02. Why is that ? Is it possible to initiate hybrid joined connection even if users connect to different domain controllers ? Where do I troubleshoot this?

    • @ConceptsWork
      @ConceptsWork  3 роки тому +1

      For the first question, which version of AAD connect you have, also make sure that you are selecting hybrid option.
      For 2nd question - Its not about user, its about machine object which has to be synced to Azure AD for Hybrid Azure AD join to work.
      If the changes are made on a dc which is not directly contacted by AAD connect, and these changes are not reflecting in Azure AD, it can be a replication issue between DC's.

  • @sraju999
    @sraju999 2 роки тому

    Outstanding presentation and attention to detail. Thank you

  • @baranisam
    @baranisam 4 роки тому +1

    Great stuff thanks a lot. My question is "Is it possible to register domain joint PC as hybrid azure ad joined from vpn access or internet?"

    • @ConceptsWork
      @ConceptsWork  4 роки тому +1

      Even with Intune Connector, the machines must be able to contact your domain controller.
      Please check this article - docs.microsoft.com/en-us/mem/intune/enrollment/windows-autopilot-hybrid

    • @ashtonashton4529
      @ashtonashton4529 3 роки тому

      @@ConceptsWork Does it means that for WFH scenario, It's not possible for on prem join domain PC and has SCCM agent to setup hybrid azure ad join without VPN?
      What's the best way to migrate from AD and SCCM managed to Azure AD and Intune managed for WFH scenario, PC are already join to onprem AD and installed with SCCM agent but have no VPN

  • @cooksiecooks
    @cooksiecooks 4 роки тому

    Hello, is this possoble for Windows E3 Subcription despite joined to local domain?

  • @italonofi216
    @italonofi216 2 роки тому

    hi,
    great video congratulations, you have been very clear in the explanation in fact I am following the whole series of azure ad on your channel.
    Can I ask you just one question since a detail is not clear to me? Why can you get a PRT by accessing the machine with an on-prem domain user?
    When the machine from on-prem is joined also to azure ad to get a PRT shouldn't you access it using an azure active directory account? You can get a PRT because your on-prem users are also synchronized with azure ad right?

    • @ConceptsWork
      @ConceptsWork  2 роки тому

      PRT is per user and device specific.
      Regarding more details on how PRT works, please check this article - docs.microsoft.com/en-us/azure/active-directory/devices/concept-primary-refresh-token

  • @asithahttp
    @asithahttp 4 роки тому

    One of the greatest explanation i have ever seen, have two questions, how to trigger the scheduled task on already domain joined device, and how it will act on device is connecting from VPN ? WFH scenario

    • @ConceptsWork
      @ConceptsWork  4 роки тому +1

      You have to ask users to use VPN, as the task to renew PRT is initiated in every unlock of the machine, also you can create a scheduled task which should trigger device registration at least 3 or 4 times a day, once the device is successfully, PRT should work as expected, but just FYI, renewal of PRT requires line of site for DC in federated environments.

  • @jadhav44
    @jadhav44 5 років тому

    Hi, appreciate the efforts taken to create this awesome video giving guidance around Hybrid AAD join. Is there a possibility that an device has been Hybrid AAD joined but failed to get the PRT? I have a set of devices where Hello provisioning is getting failed and the device state for those devices is Hybrid AAD joined but has failed to get the PRT. Any thoughts?

    • @jadhav44
      @jadhav44 5 років тому +1

      Infact, I just did an repro in my personal tenant and it is exactly the same. I set the GPO to trust all the sites specified in the documentation as well as your video, my AAD Connect is configured for the Hybrid AAD Join with Passthrough Authentication and SSO Enabled. Also, I can see my Computer Object being synced to the Cloud and when I join my machine to the domain, I can see the User device registration logs confirming that the device has been joined but while checking the dsregcmd status it shows that it has not obtained any PRT but the device is joined to AAD. Your technical insights would help me solve issue in my personal tenant as well as Production. The only difference in my prod is we are using Federated Domain and in personal I am using Managed.
      Thanks a lot in advance!!

    • @ConceptsWork
      @ConceptsWork  5 років тому +1

      Hello Ganesh,
      Thanks for being so responsive on all our videos, please reach us on learnconceptswork@gmail.com, and we will resolve this issue.
      Regards,
      Conceptswork.

    • @lyfrocks5554
      @lyfrocks5554 4 роки тому

      Hello Ganesh, what are your findings after checking with concept team. I had a similar issue. Any inputs from your end is highly appreciated.

    • @lyfrocks5554
      @lyfrocks5554 4 роки тому

      @@jadhav44 any inputs from concept team regarding your issue, as I have seen a similar situation at my end.

  • @anujsheth1732
    @anujsheth1732 4 роки тому

    Great Video. My question is if a device is already Azure Joined but is also part of the domain. Do I need to remove the Azure Joined Device first then follow the hybrid join process?

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      A device which is domain joined cannot be manually Azure AD joined from settings pane.

  • @priyankareddy3587
    @priyankareddy3587 4 роки тому +1

    great..please do continue azure and adfs..u look like an expert..great content

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      Thanks for your kind words.

    • @priyankareddy3587
      @priyankareddy3587 4 роки тому +1

      @@ConceptsWork for hybrid join ..enterpriseprt should be yes, but in your video I see as NO , Could you please explain

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      ADFS also offers device registration, and enterprise PRT is related to ADFS, please check this article for more details.
      docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-faq

    • @priyankareddy3587
      @priyankareddy3587 4 роки тому

      I did not find info about enterprisePRT.
      I know abt session cookie ...acess token...
      My question was why enterprisePrt was set to No if it is a hydrid join...
      If the machine is hybrid Join, azureadprt and enterprisePRT should be YES.
      Please let me if my understanding is wrong

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      Enterprise PRT will be available, if you have implemented Device Registration of ADFS.
      Enterprise PRT is not required for Hybrid Azure AD join Devices.

  • @TITOMIKEE89
    @TITOMIKEE89 3 роки тому

    Hello,
    I have a question, will adding the 4 url endpoints into gpo will let them access the urls?

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      No, adding these url's to GPO will add them to local intranet zone. The access to these URL's should be whitelisted at the network.

    • @TITOMIKEE89
      @TITOMIKEE89 3 роки тому

      @@ConceptsWork Meaning so they can be contacted by Down level devices? but for devices that are Windows 10 and updated those 4 URL's must be whitelisted in the network? My device can contact the 2 out for 4 URL"S . For enterpriseregistration.windows.net/ i get error endpoint not availble. I appreciate your help.

    • @TITOMIKEE89
      @TITOMIKEE89 3 роки тому

      One more thing, will the SCP be installed after the AD sync configuration? or it should be there by default?

  • @fredericcuzon5194
    @fredericcuzon5194 3 роки тому

    Thank you so much for taking the time to make the video. Got a question tough, My devices are hybrid joined & can see them OK in Azure AD. Issue is that I cannot login with a user on the machine if not connected to the local domain. My understanding would be that if the domain is not available, then users should be able to authenticate via Azure AD?

    • @ConceptsWork
      @ConceptsWork  3 роки тому

      No, the first authentication will be sent to Local AD itself.

    • @fredericcuzon5194
      @fredericcuzon5194 3 роки тому

      ​@@ConceptsWork, so it is not possible.. I would have thought otherwise being Hybrid!

  • @ronald0122
    @ronald0122 4 роки тому

    so no gpo to device join to azure?

  • @CaptDarksoul
    @CaptDarksoul 4 роки тому

    How do you make the Is it possible to register domain joint PC as hybrid azure ad joined from vpn access or internet run the join after a device is on VPN automaticlly?

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      You can ask users to remain connect on VPN for some days and get a gpo created which should trigger dsregcmd task at least 3-4 times a day.

  • @Sunny-zj6wt
    @Sunny-zj6wt 4 роки тому

    Thanks a lot for the videos. Just wanted to know what happens to the machines that are already domain joined before implementing thh Hybrid Azure AD Join? Do they need to be on-prem to register or these devices can be registered over the Internet to Azure AD?

    • @ConceptsWork
      @ConceptsWork  4 роки тому

      The machines must contact AD, as there is a cert which is written to the user certificate attribute of computer object.
      This applies to Windows 10 1709 or above:-
      "If a machine is already joined to Active Directory, the moment you enable device registration from AAD connect, the SCP of the tenant gets registered in AD, now from the next time when device registration will be triggered the machine will create the cert and save it in the machine object.
      When this object is synced to azure AD in next sync cycle, the user will start receiving PRT.

    • @Sunny-zj6wt
      @Sunny-zj6wt 4 роки тому

      @@ConceptsWork Thank you for the information. So, once I enable the device registration from AAD connect, in order to get the Certificate the Machine must contact the on Prem Domain Controller for first time? Once thats done it can be offsite? How about service password reset? Is that the same case well?
      Thank you again

  • @exchameed
    @exchameed 4 роки тому

    Excellent video... The way he explain things is awesome