Quick Tip: Hybrid Domain Join with Intune

Although the future is to move to Azure Active Directory (Azure AD) for lots of organizations still have the need to Domain Join (Local AD domain join) devices still because of legacy issues.

6/10/2023: Update: Azure Active Directory is now called Entra ID

You can Azure Domain Join, enroll and provision devices enroll with Microsoft Intune tenant. However, the ability to join to local domain needs is delegated to when the device sees the Local AD. This means a VPN (along with certificates) needs to be deployed using an silent package (app) with Intune. Once deployed, you can enable the VPN to connect to the internal local directory and domain join the device automatically.

Two Articles by MICHAEL NIEHAUS back in 2019 follow:

Microsoft Documentation:

Palo Alto GlobalProtect specific info:

Additional Resources:

How Azure AD device registration works – Microsoft Entra | Microsoft Learn

Autopilot Hybrid Azure AD Join Breakpoints – MDM Tech Space (joymalya.com)

Microsoft Exchange Server 2013 to Office 365: Hybrid Migration Step-by-Step | CBT Nuggets

Similar Posts