Microsoft Entra ID | Hybrid Azure AD Join Devices | Managed Domains

แชร์
ฝัง
  • เผยแพร่เมื่อ 3 ธ.ค. 2024

ความคิดเห็น • 188

  • @emirmoneer3090
    @emirmoneer3090 4 ปีที่แล้ว +5

    Better than most PAID teachers honestly

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      Thanks for your acknowledgement.

  • @Sanddancer75
    @Sanddancer75 2 ปีที่แล้ว +4

    Possibly the most concise but informative video I've ever seen on TH-cam. Very very well done.

  • @fisheridle6886
    @fisheridle6886 5 ปีที่แล้ว +23

    Great work! Really appreciate this! It's crystal clear, and looks like an anatomy against the things behind. It saves me tons of hours reading those MS poor organized documentation. Thanks, man!

    • @ConceptsWork
      @ConceptsWork  5 ปีที่แล้ว +4

      Thank you for your kind words.

  • @lostray117
    @lostray117 2 ปีที่แล้ว +1

    Thank you very much!
    Your Video and explanation ist brilliant!
    Your are the only one who explain the issues when the hybrid ad join is not working because of the connectivity to the urls / internet.

  • @Henry1973
    @Henry1973 4 ปีที่แล้ว +6

    I love how you showed the ways we can troubleshoot the process, the detail you explain of how the process works and the concept of it. This was a great video and has set the standard for concepts work in my mind, i subscribed!

  • @gabrielalicea4803
    @gabrielalicea4803 3 ปีที่แล้ว +1

    Watching this for the third time and it’s great quality work. Thank you again.

  • @rizomarshal7483
    @rizomarshal7483 5 ปีที่แล้ว +7

    thanks a LOT!!!! for this great tutorial - deep explained of the overall hybrid process and component.
    learned a lot :)

  • @niranmanandhar8517
    @niranmanandhar8517 4 ปีที่แล้ว +2

    very impressed and happy with the level of explanation you have provided in this video. Getting to learn quite a few things

  • @harrichavan789
    @harrichavan789 4 ปีที่แล้ว +1

    This is deep dive about behind the scene of Azure Hybrid Join thanks for such video

  • @du1vbs
    @du1vbs 5 ปีที่แล้ว +2

    Beautifully explained. Thank you so much for sharing your knowledge.

  • @alfonsorodriguez5449
    @alfonsorodriguez5449 3 ปีที่แล้ว +1

    Best technical deep dive in Azure AD Hybrid Join

  • @babrdwod7464
    @babrdwod7464 2 ปีที่แล้ว

    Outstanding explanation. Please keep publishing these videos!

  • @manjitbhatia9909
    @manjitbhatia9909 5 ปีที่แล้ว +1

    Great Contribution and very well explained ... awesome tutorial ..

  • @cryptoguru7630
    @cryptoguru7630 4 ปีที่แล้ว +2

    Nice explanation 👌👍

  • @BindasBadshah
    @BindasBadshah 3 ปีที่แล้ว +1

    This was so amazing. Very well thought of and covered every aspect of HADDJ. Thanks,

  • @riswanthnsai7144
    @riswanthnsai7144 5 ปีที่แล้ว +1

    Great contribution to the learners and videos are really useful

  • @abhimanyusinghshekhawat6871
    @abhimanyusinghshekhawat6871 4 ปีที่แล้ว +1

    Love hearing you.. crisp and clear.

  • @robinraju4321
    @robinraju4321 4 ปีที่แล้ว +2

    Wonderful video. well explained

  • @007Joelsky
    @007Joelsky 3 ปีที่แล้ว

    Awesome!! What you explained from 13:14 is exactly what I needed to know! Thanks

  • @sraju999
    @sraju999 2 ปีที่แล้ว

    Outstanding presentation and attention to detail. Thank you

  • @gabrielalicea4803
    @gabrielalicea4803 4 ปีที่แล้ว +1

    Outstanding presentation and attention to detail. This video made me subscribe to your channel. Well done.

  • @priyankareddy3587
    @priyankareddy3587 4 ปีที่แล้ว +1

    great..please do continue azure and adfs..u look like an expert..great content

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      Thanks for your kind words.

    • @priyankareddy3587
      @priyankareddy3587 4 ปีที่แล้ว +1

      @@ConceptsWork for hybrid join ..enterpriseprt should be yes, but in your video I see as NO , Could you please explain

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      ADFS also offers device registration, and enterprise PRT is related to ADFS, please check this article for more details.
      docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-faq

    • @priyankareddy3587
      @priyankareddy3587 4 ปีที่แล้ว

      I did not find info about enterprisePRT.
      I know abt session cookie ...acess token...
      My question was why enterprisePrt was set to No if it is a hydrid join...
      If the machine is hybrid Join, azureadprt and enterprisePRT should be YES.
      Please let me if my understanding is wrong

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      Enterprise PRT will be available, if you have implemented Device Registration of ADFS.
      Enterprise PRT is not required for Hybrid Azure AD join Devices.

  • @sandeep909b
    @sandeep909b 3 ปีที่แล้ว +1

    Quality Stuff.. very nice deep dive👍

  • @PavanKumargurijala
    @PavanKumargurijala 3 ปีที่แล้ว +1

    excellent explanation

  • @navneetsingh9592
    @navneetsingh9592 2 ปีที่แล้ว +1

    Excellent video, Thanks for explaining the concept. Just one question, your machine is in workgroup , so how come it gets the task ? Is it there for all windows 10 machines by default and gets enabled only when it joins the domain and if hybrid AAD is enabled?

  • @widodoboedijono9374
    @widodoboedijono9374 4 ปีที่แล้ว

    Simple, Brief, and Very Clear

  • @Productivity365
    @Productivity365 4 ปีที่แล้ว

    Thanks for sharing such informative videos

  • @abulaith4485
    @abulaith4485 5 ปีที่แล้ว +6

    Another great technical video.
    Do you work for Microsoft?

  • @charliemelga7445
    @charliemelga7445 2 ปีที่แล้ว +1

    Great video, with some good tips, thanks very much for taking the time to create and post :)

  • @ramyogeshwaran
    @ramyogeshwaran 3 ปีที่แล้ว +1

    I hope before post the each video. I could see your hard work. Keep post the new videos.

  • @ameerthoughts848
    @ameerthoughts848 3 ปีที่แล้ว +1

    very nice class

  • @exchameed
    @exchameed 4 ปีที่แล้ว

    Excellent video... The way he explain things is awesome

  • @anniesrivastava2276
    @anniesrivastava2276 2 ปีที่แล้ว +1

    Sir you are great.. is there any way we can ever see you or meet you..it would be a great pleasure.. you have an exceptional skills to explain such difficult topics so easily

  • @kanikagambhir2592
    @kanikagambhir2592 2 ปีที่แล้ว +1

    The content is really good and the way you explain the concepts is commendable. Also the settle tone of explaining the concepts helps in understanding them easily...Keep continue the good work.....Only thing that I found missing is that "content ppt" is not available anywhere for the revision purpose....If it's available somewhere please share the location.
    ..... Thank u.

    • @ConceptsWork
      @ConceptsWork  2 ปีที่แล้ว

      Hi Kanika, though there is a membership, for this, but if it is only this PPT that you need, please send us an email at learnconceptswork@gmail.com

  • @kpanagos
    @kpanagos 4 ปีที่แล้ว +1

    Great guide !!! Thank you very much.

  • @thedavid1174
    @thedavid1174 4 ปีที่แล้ว +3

    This is an amazing video, I love how you go into detail about what is happening in the background. Certainly subscribing :)
    Quick question. I managed to get this far, but do you have any video on how to get them managed and into InTune after this step and after they are Hybrid joined?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      Hi David, thanks for the kind words.
      Just wanted to understand your requirement related to intune.
      The device which are hybrid azure ad joined are already managed through on-prem, can you please share some more details in terms of how you want to manage the from intune.

    • @thedavid1174
      @thedavid1174 4 ปีที่แล้ว +1

      ​@@ConceptsWork We are in the process of purchasing 150 laptops for staff that will be used both onsite and offsite. If they are onsite, they will be either connected via cable to our main network, or on our corporate wifi for direct access to the DCs and managed via traditional on-prem group policies etc.
      I am pretty new to InTune, but we want to basically make sure all of our devices are registred to InTune so that we can retain some sort of control when they are off-network too.
      I managed to get this working though. Initially, for those devices that are Hybrid Joined, the MDM was showing as "None". However, after making some GPO changes, my devices now are showing as Hybrid Joined with InTune as their MDM. We are not really going to configure much on InTune, but it will be nice to have the option to in the future. I hope this make sense, and I hope this is a correct use-case for InTune.
      BYOD devices, at the moment, we're not really expecting to get onto InTune or Azure Joined.

  • @Wiseparentsclub
    @Wiseparentsclub 2 ปีที่แล้ว

    Thank you for such as in depth explanation.

  • @techmaster6166
    @techmaster6166 4 ปีที่แล้ว +1

    Great video and brilliant explanation, i have been watching few videos of different series, just one comment, in my opinion when you make series if you could number your videos then it will easier to watch all of them in order, let say intune part 1 or lecture 1, great work please keep it up

  • @robinraju4321
    @robinraju4321 4 ปีที่แล้ว +1

    Clear Explanation ...thanks a lot

  • @arifshaikh213
    @arifshaikh213 3 ปีที่แล้ว

    Awesome explanation 👏🏼👏🏼

  • @SanjeevKumar-hs6gp
    @SanjeevKumar-hs6gp 3 ปีที่แล้ว +1

    Nice Informative Video !

  • @lyfrocks5554
    @lyfrocks5554 5 ปีที่แล้ว +1

    Brilliant. Thanks for sharing this. Subscribed.

  • @silerauk366
    @silerauk366 2 ปีที่แล้ว

    Great work..indeed..Could you pls explain on how to go AD configuration partition using adsi edit ? Appreciated...

  • @Ambedkarites_Indian
    @Ambedkarites_Indian ปีที่แล้ว

    Great sir, thank you very much.

  • @WoTpro
    @WoTpro 3 ปีที่แล้ว +1

    great video thanks for your efforts

  • @asithahttp
    @asithahttp 4 ปีที่แล้ว

    One of the greatest explanation i have ever seen, have two questions, how to trigger the scheduled task on already domain joined device, and how it will act on device is connecting from VPN ? WFH scenario

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      You have to ask users to use VPN, as the task to renew PRT is initiated in every unlock of the machine, also you can create a scheduled task which should trigger device registration at least 3 or 4 times a day, once the device is successfully, PRT should work as expected, but just FYI, renewal of PRT requires line of site for DC in federated environments.

  • @sumeetkumar6900
    @sumeetkumar6900 4 ปีที่แล้ว +2

    Instantly subscribed :) beautifully explained Sir. Do you also have ADFS tutorials ?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      th-cam.com/play/PL8wOlV8Hv3o9uHl0XFfI6_katp6BXNVjb.html

  • @yousefbableh5611
    @yousefbableh5611 4 ปีที่แล้ว +4

    The is great presentation, I subscripted, I have one question!! why you have disjoin and rejoin the devise to on prem AD, it will not work if you just enable internet to populate the certificate?

    • @Southpaw07
      @Southpaw07 4 ปีที่แล้ว

      yes, i have the same question. seems a little confusing and hoping don't have disjoin machines to get ADHybrid join to work.

  • @HOKING-ef8dj
    @HOKING-ef8dj 4 ปีที่แล้ว +1

    Fantastic videos !

  • @phanihishi
    @phanihishi 2 ปีที่แล้ว

    Great video! Can't dive deeper!

  • @ytho7618
    @ytho7618 2 ปีที่แล้ว

    thanks for making these great videos

  • @marctemplin366
    @marctemplin366 3 ปีที่แล้ว

    Thanks for this video. It's very helpful. If a hybrid joined device is active on the internet, is that activity registered in on-prem AD? We have a policy to disable devices that haven't been active on the domain for 3 months so I wondered if a device is hybrid joined and active on the internet, would that activity prevent the on-prem object from being disabled?

  • @belzebubas
    @belzebubas ปีที่แล้ว

    Ok. This is great. How about machines that are already on the OnPrem domain? What if I have 100 machines. Does this mean I'll have to disconnect and rejoin the domain in order for these machines to get Azure AD hybrid Joined?

  • @brunomarcelo880
    @brunomarcelo880 3 ปีที่แล้ว +1

    U nailed thank you so muchhhhhhh

  • @nithyanadhamsingaravadivel8547
    @nithyanadhamsingaravadivel8547 ปีที่แล้ว

    Hi, Your vidoes are really informative, lets say if my domain. Joined devices are already synced to Azure AD as the device type "Azure AD registered", In this case, does this method would help us to delete the device type "Azure AD registered" and pefform the new device registration as "Hybrid AD joined" ? If this is posisble ? What will be impacts when the device is removed and registered again in azure as hybrid joined devices ?
    With the SCP created in Active Directory, how can we perform the phased roll out for hybrid device registration in Azure AD? Does selecting the appropriate OU's would help us with the phased roll out ?
    Also how can we avoid the automatic device enrollment of hybrid joined devices to microsoft intune ? Is adjusting MDM scope the only option ? Or we can keep MDM scope set to all users and adjust somewhere else in the Microsoft intune portal to avoid the auto enrollment of windows hybrid joined devices to Microsoft intune ?

  • @ThePaulSIN
    @ThePaulSIN 4 ปีที่แล้ว +2

    Great video! What happens to a PC that is already a member of the local AD when you enable the hybrid sync and you set the policy as you suggested. Will they automatically be hybrid joined with no action from the local PC side (accept maybe a reboot)?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +4

      This applies to Windows 10 1709 or above:-
      "If a machine is already joined to Active Directory, the moment you enable device registration from AAD connect, the SCP of the tenant gets registered in AD, now from the next time when device registration will be triggered the machine will create the cert and save it in the machine object.
      When this object is synced to azure AD in next sync cycle, the user will start receiving PRT.

    • @taksiobs
      @taksiobs 4 ปีที่แล้ว

      @@ConceptsWork okay, so i don't have to disjoin the machine and rejoin it just like what you did right?

    • @riyazqureshi8906
      @riyazqureshi8906 2 ปีที่แล้ว

      @@ConceptsWork when will the next time device registration trigger if the machine is already domain joined, does it happen when synchronisation cycle happen next time?

  • @tranghienkhoa
    @tranghienkhoa ปีที่แล้ว

    WOW YOU ARE THE BEST!!!! ❤

  • @WelcomeWithinMyDream
    @WelcomeWithinMyDream 4 ปีที่แล้ว +1

    Awesome video! Quick question from me since I want to be sure I understood correctly the information. For the 4 urls, for Win10 the laptop needs to have internet access to said urls (an entry in Site to zone) is not required, while for lower OS, it is mandatory to provide the entry. Is this correct? Ty for your time, content and knowledge share!

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      Yes, for windows down level devices, all these links should be added as seamless sso is one of the pre-reqs.

    • @taksiobs
      @taksiobs 4 ปีที่แล้ว

      @@ConceptsWork oh! so if all my devices are windows 10, then no need to add these URLs?

  • @NitinKumar-pd9nt
    @NitinKumar-pd9nt 5 ปีที่แล้ว +1

    Hi, It was a nice explanation. My Question - In an environment where win10 and win7 machines are already joined to local domain, how to initiate Hybrid setup?

    • @ConceptsWork
      @ConceptsWork  5 ปีที่แล้ว +5

      Start from enabling Hybrid Azure AD join from AAD connect, make sure all the network configuration is in place.
      When the SCP and the network endpoints are enabled win 10 will get automatically joined.
      For windows 7 check this article - docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains#enable-windows-downlevel-devices

  • @lakergreat1
    @lakergreat1 3 ปีที่แล้ว

    What steps would have I have to setup if I WASN'T seeing AzureADPRT:YES, and instead it said NO?

  • @kosalyeang2101
    @kosalyeang2101 3 ปีที่แล้ว

    It's a great guide video.

  • @michaelpietrzak2067
    @michaelpietrzak2067 3 ปีที่แล้ว +1

    Great video!

  • @macro8681
    @macro8681 4 ปีที่แล้ว +1

    Great video. Well done!
    Do you know if there is a method for migrating systems from hybrid Azure AD joined to fully Azure AD joined and doesn't involve manually touching every system?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      As of now there is no method to Migrate machines from on-prem to Azure AD.

    • @taksiobs
      @taksiobs 4 ปีที่แล้ว

      @@ConceptsWork unless you want everything fresh or user 3rd party tools to migrate user profiles. am i right?

  • @ravisuj
    @ravisuj 2 ปีที่แล้ว

    Thanks for creating and sharing such excellent content. If there are two AD connect servers (one in staged mode) is it needed to run the wizard for hybrid Azure AD join on the staged server also?

    • @ConceptsWork
      @ConceptsWork  2 ปีที่แล้ว

      Yes, this will keep the configuration file, identitical on all the servers.

  • @CaptDarksoul
    @CaptDarksoul 4 ปีที่แล้ว

    How do you remove old management objects before you add the new HAAD joined process?

  • @williamkass9057
    @williamkass9057 6 หลายเดือนก่อน

    If I have a user that isnt located within the Office(DOmain LAN) but has a company laptop that was joined to the on-prem domain when the laptop was setup in the past. If I migrate my infrastructure to Azure AD how am i able to get the aformentioned user endpoint to join the new AZURE AD domain with out making the user go to an office lan.

  • @joshandres4964
    @joshandres4964 2 ปีที่แล้ว

    If I want to have my device listed on AAD but use a different IDP like Okta, will I have to rejoin those machines if I switch from AAD IDP to Okta?

  • @phucmac5312
    @phucmac5312 3 ปีที่แล้ว

    question for you. I'm running into this issue where I keep getting this error
    auto MDM ENroll Get ADD Token: Device Credential (0x0) Resource url (Null)( UNknown win32 error code 0x801800b.
    everything work great on my lab, but in productions I can't get past that on the event viewer.

  • @cool2685
    @cool2685 2 ปีที่แล้ว

    First of all, i Really appreciate your efforts!! I have one question, how we manage device which joined the already domain joined, Do we need to reconfigure it in domain? and second thing will it work for those devices which is on VPN?

  • @flymoracer
    @flymoracer 4 ปีที่แล้ว +1

    Thanks. If I query AAD using get-msoldevice poweshell command, it returns a DeviceTrustType of 'Domain Joined' for a device that is listed in the portal as Hybrid AD Joined. Is this correct?

  • @StephenKunstmann
    @StephenKunstmann 4 ปีที่แล้ว +1

    Hi, very good video! Exactly what I needed to know :) Quick question - ist it possible to use my UPN/Azure AD account to login to such a hybrid joined device?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      Unfortunately not, as the authentication authority for users is still on-prem AD.

  • @phucmac5312
    @phucmac5312 3 ปีที่แล้ว

    Great Video, assuming since this manual enrolled, but if I want to autopilot i would need to install the intune connector?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว

      Yes with auto pilot you need connector and line of site of DC.

    • @phucmac5312
      @phucmac5312 3 ปีที่แล้ว

      @@ConceptsWork my current environment is a hybrid, I haven’t setup intune connector yet. will you still be able to do the manual enrollment and join machine to hybrid AD join even though you have autopilot set up? Currently my environment is small everything has been setup manually and manual AD join.

    • @phucmac5312
      @phucmac5312 3 ปีที่แล้ว

      I see that the machine is azure AD join. but MDMurl and MDMtouurl are empty, how do you fix that? cause it to register with as hybrid ad join, but can't push application nor policy to it.

  • @paolodifrancesco4319
    @paolodifrancesco4319 4 ปีที่แล้ว

    Tahnks for stunniung video tutorial! I'm concerned abou if my laptop goes out of enterprise network...domain authentication will work even local domain controller is not accessible? Again...if i change my password out of enterprise network it will be write back do on prem AD? thanks

  • @italonofi216
    @italonofi216 3 ปีที่แล้ว

    hi,
    great video congratulations, you have been very clear in the explanation in fact I am following the whole series of azure ad on your channel.
    Can I ask you just one question since a detail is not clear to me? Why can you get a PRT by accessing the machine with an on-prem domain user?
    When the machine from on-prem is joined also to azure ad to get a PRT shouldn't you access it using an azure active directory account? You can get a PRT because your on-prem users are also synchronized with azure ad right?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว

      PRT is per user and device specific.
      Regarding more details on how PRT works, please check this article - docs.microsoft.com/en-us/azure/active-directory/devices/concept-primary-refresh-token

  • @ashoksan14
    @ashoksan14 2 ปีที่แล้ว

    Can we join windows server to Azure AD without Azure ADDS and OnpremADDS infra.

  • @nareshkumarshetti6073
    @nareshkumarshetti6073 2 ปีที่แล้ว

    Join type information is blank on azure portal, may I know the reason.

  • @cooksiecooks
    @cooksiecooks 5 ปีที่แล้ว

    Hello, is this possoble for Windows E3 Subcription despite joined to local domain?

  • @sayedhasanalalawi749
    @sayedhasanalalawi749 2 ปีที่แล้ว

    Good job, but I have one question. To join a device as a hybrid AD join, is it a must to connect it to the work network? Or it can be joined remotely from home for example?

    • @ConceptsWork
      @ConceptsWork  2 ปีที่แล้ว

      The machine must have line of site to DC, which in turns fall back to connectivity to on-prem network.

  • @TahaTaha-sz3zk
    @TahaTaha-sz3zk 3 ปีที่แล้ว

    Can you view the certificate in certificate store ? I don’t see it in machine private

  • @vin21711487
    @vin21711487 3 ปีที่แล้ว +1

    Will this method of joining sync my on prem domain joined devices to Azure AD and Intune Endpoint Manager for managing the devices from there? If not could you suggest a solution which will enable me to enroll domain joined local existing computer devices to sync to intune devices for management ?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว +1

      Make sure you have enabled automatic enrollment in Endpoint manager portal and MDM scope is also set for all the users. In this case when the user will join the device to Azure AD, it will be automatically enrolled to MDM, also if you deployed the onboarding to Microsoft defender for endpoints that will also happen seamlessly.

  • @anujsheth1732
    @anujsheth1732 4 ปีที่แล้ว

    Great Video. My question is if a device is already Azure Joined but is also part of the domain. Do I need to remove the Azure Joined Device first then follow the hybrid join process?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      A device which is domain joined cannot be manually Azure AD joined from settings pane.

  • @chetansharma6595
    @chetansharma6595 3 ปีที่แล้ว

    Please make a detailed video on how a device get PRT.

  • @baranisam
    @baranisam 4 ปีที่แล้ว +1

    Great stuff thanks a lot. My question is "Is it possible to register domain joint PC as hybrid azure ad joined from vpn access or internet?"

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      Even with Intune Connector, the machines must be able to contact your domain controller.
      Please check this article - docs.microsoft.com/en-us/mem/intune/enrollment/windows-autopilot-hybrid

    • @ashtonashton4529
      @ashtonashton4529 3 ปีที่แล้ว

      @@ConceptsWork Does it means that for WFH scenario, It's not possible for on prem join domain PC and has SCCM agent to setup hybrid azure ad join without VPN?
      What's the best way to migrate from AD and SCCM managed to Azure AD and Intune managed for WFH scenario, PC are already join to onprem AD and installed with SCCM agent but have no VPN

  • @vivek.padale
    @vivek.padale 4 ปีที่แล้ว

    Hi,
    Thanks for sharing this awesome content. I will appreciate if you help with my query.
    If my on-prem ADDS and Azure ADDS are sync with AAD connect, can i use Azure ADDS to authenticate and authorize on-prem users for internal or intranet resources.
    And also can i use Azure ADDS as a DR solution for On-prem ADDS.
    Regards,
    Best of Luck!!!

  • @bartoszjelen326
    @bartoszjelen326 3 ปีที่แล้ว

    Great Video ! 2 questions :
    1. When I get to configuration Part I don't have a option to configure SCP why ?
    2. I have about 5-6 Domain Controllers in single forest. It looks like users are synchronize properly as hybrid azure joined only if there are connected to DC02. Why is that ? Is it possible to initiate hybrid joined connection even if users connect to different domain controllers ? Where do I troubleshoot this?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว +1

      For the first question, which version of AAD connect you have, also make sure that you are selecting hybrid option.
      For 2nd question - Its not about user, its about machine object which has to be synced to Azure AD for Hybrid Azure AD join to work.
      If the changes are made on a dc which is not directly contacted by AAD connect, and these changes are not reflecting in Azure AD, it can be a replication issue between DC's.

  • @devraj_thezeus
    @devraj_thezeus 2 ปีที่แล้ว

    If i create AD and a client vm in hyper v and use default switch for network will this whole thing work

  • @prabaselvam
    @prabaselvam 4 ปีที่แล้ว +1

    can we do hybrid AD JOIN for windows server 2019(Instead of windows 10)?

  • @Sunny-zj6wt
    @Sunny-zj6wt 4 ปีที่แล้ว

    Thanks a lot for the videos. Just wanted to know what happens to the machines that are already domain joined before implementing thh Hybrid Azure AD Join? Do they need to be on-prem to register or these devices can be registered over the Internet to Azure AD?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      The machines must contact AD, as there is a cert which is written to the user certificate attribute of computer object.
      This applies to Windows 10 1709 or above:-
      "If a machine is already joined to Active Directory, the moment you enable device registration from AAD connect, the SCP of the tenant gets registered in AD, now from the next time when device registration will be triggered the machine will create the cert and save it in the machine object.
      When this object is synced to azure AD in next sync cycle, the user will start receiving PRT.

    • @Sunny-zj6wt
      @Sunny-zj6wt 4 ปีที่แล้ว

      @@ConceptsWork Thank you for the information. So, once I enable the device registration from AAD connect, in order to get the Certificate the Machine must contact the on Prem Domain Controller for first time? Once thats done it can be offsite? How about service password reset? Is that the same case well?
      Thank you again

  • @mask3809
    @mask3809 3 ปีที่แล้ว +1

    perfect

  • @fredericcuzon5194
    @fredericcuzon5194 3 ปีที่แล้ว

    Thank you so much for taking the time to make the video. Got a question tough, My devices are hybrid joined & can see them OK in Azure AD. Issue is that I cannot login with a user on the machine if not connected to the local domain. My understanding would be that if the domain is not available, then users should be able to authenticate via Azure AD?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว

      No, the first authentication will be sent to Local AD itself.

    • @fredericcuzon5194
      @fredericcuzon5194 3 ปีที่แล้ว

      ​@@ConceptsWork, so it is not possible.. I would have thought otherwise being Hybrid!

  • @taksiobs
    @taksiobs 4 ปีที่แล้ว +1

    My device is showing hybrid ad join but i can't manage it from intune still.

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      There must be PRT on the device and verify is the GPO has reached the device.

    • @taksiobs
      @taksiobs 4 ปีที่แล้ว

      @@ConceptsWork thanks for your reply but what's a PRT?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +1

      PRT is token that is device specific - docs.microsoft.com/en-us/azure/active-directory/devices/concept-primary-refresh-token#:~:text=A%20Primary%20Refresh%20Token%20(PRT,applications%20used%20on%20those%20devices.

    • @taksiobs
      @taksiobs 4 ปีที่แล้ว

      @@ConceptsWork thanks much! let me read this. i'm scratching my head since.

  • @ronald0122
    @ronald0122 4 ปีที่แล้ว

    so no gpo to device join to azure?

  • @TITOMIKEE89
    @TITOMIKEE89 3 ปีที่แล้ว

    Hello,
    its me again, what if i have a domain joined devices that i want to hybri joined. will i need to take them out of the domain and rejoined to get the Usercertificate populated?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว

      No, once the hybrid process is completed, I mean the machine is able to contact the respective endpoints, user certificate attribute will be populated.

  • @TITOMIKEE89
    @TITOMIKEE89 3 ปีที่แล้ว

    Hello,
    I have a question, will adding the 4 url endpoints into gpo will let them access the urls?

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว

      No, adding these url's to GPO will add them to local intranet zone. The access to these URL's should be whitelisted at the network.

    • @TITOMIKEE89
      @TITOMIKEE89 3 ปีที่แล้ว

      @@ConceptsWork Meaning so they can be contacted by Down level devices? but for devices that are Windows 10 and updated those 4 URL's must be whitelisted in the network? My device can contact the 2 out for 4 URL"S . For enterpriseregistration.windows.net/ i get error endpoint not availble. I appreciate your help.

    • @TITOMIKEE89
      @TITOMIKEE89 3 ปีที่แล้ว

      One more thing, will the SCP be installed after the AD sync configuration? or it should be there by default?

  • @shahzadansari9728
    @shahzadansari9728 ปีที่แล้ว

    Can we expect more Azure Security videos AZ 50

  • @priyankareddy3587
    @priyankareddy3587 3 ปีที่แล้ว

    We have done configuration in azure ad connect with all prerequisites met.Will the device registration be pending in portal until user login to client machine to complete hybrid join?? Or automatically the device registration gets completed after certian period of time in Azure portal and the client machine will be hybrid join??

    • @ConceptsWork
      @ConceptsWork  3 ปีที่แล้ว +1

      The activity timestamp will only be populated when there is a valid PRT on the device.
      As soon as the device is synced from on-prem, portal shows that device as hybrid, but the activity time stamp also has to be populated.

  • @qamarqureshi2874
    @qamarqureshi2874 4 ปีที่แล้ว

    I can see you joined one machine in Hybrid Azure AD but what if i have 100 or 500 client machines in my organization to join Hybrid Azure AD. do i need to go and join them manually to Azure Ad domain ? also process will be same for client machine and windows servers ?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      No, you don't have to do it manually, if all the config is in place as well as machines get line of site to DC, it will work as expected.

  • @flymoracer
    @flymoracer 4 ปีที่แล้ว

    You mention that Seamless SSO is a requirement. I've not found that listed as a pre-req in the Microsoft documentation. Could you please help me understand why this is needed?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +2

      Enable Windows down-level devices
      If some of your domain-joined devices are Windows down-level devices, you must:
      Configure the local intranet settings for device registration
      Configure seamless SSO
      Install Microsoft Workplace Join for Windows down-level computers
      -docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains

    • @flymoracer
      @flymoracer 4 ปีที่แล้ว

      @@ConceptsWork ah ok, so if there's no requirement to support down-level devices then we wont need seamless SSO?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว +2

      Yes from windows 1803, it is not required that's what I have experienced.

    • @flymoracer
      @flymoracer 4 ปีที่แล้ว +1

      @@ConceptsWork that's great. Thank you for answering my questions, you've been a great help. Your video's are really useful, thanks for putting them up.

  • @CaptDarksoul
    @CaptDarksoul 4 ปีที่แล้ว

    How do you make the Is it possible to register domain joint PC as hybrid azure ad joined from vpn access or internet run the join after a device is on VPN automaticlly?

    • @ConceptsWork
      @ConceptsWork  4 ปีที่แล้ว

      You can ask users to remain connect on VPN for some days and get a gpo created which should trigger dsregcmd task at least 3-4 times a day.

  • @jadhav44
    @jadhav44 5 ปีที่แล้ว

    Hi, appreciate the efforts taken to create this awesome video giving guidance around Hybrid AAD join. Is there a possibility that an device has been Hybrid AAD joined but failed to get the PRT? I have a set of devices where Hello provisioning is getting failed and the device state for those devices is Hybrid AAD joined but has failed to get the PRT. Any thoughts?

    • @jadhav44
      @jadhav44 5 ปีที่แล้ว +1

      Infact, I just did an repro in my personal tenant and it is exactly the same. I set the GPO to trust all the sites specified in the documentation as well as your video, my AAD Connect is configured for the Hybrid AAD Join with Passthrough Authentication and SSO Enabled. Also, I can see my Computer Object being synced to the Cloud and when I join my machine to the domain, I can see the User device registration logs confirming that the device has been joined but while checking the dsregcmd status it shows that it has not obtained any PRT but the device is joined to AAD. Your technical insights would help me solve issue in my personal tenant as well as Production. The only difference in my prod is we are using Federated Domain and in personal I am using Managed.
      Thanks a lot in advance!!

    • @ConceptsWork
      @ConceptsWork  5 ปีที่แล้ว +1

      Hello Ganesh,
      Thanks for being so responsive on all our videos, please reach us on learnconceptswork@gmail.com, and we will resolve this issue.
      Regards,
      Conceptswork.

    • @lyfrocks5554
      @lyfrocks5554 5 ปีที่แล้ว

      Hello Ganesh, what are your findings after checking with concept team. I had a similar issue. Any inputs from your end is highly appreciated.

    • @lyfrocks5554
      @lyfrocks5554 5 ปีที่แล้ว

      @@jadhav44 any inputs from concept team regarding your issue, as I have seen a similar situation at my end.