Hybrid Entra ID Join & Intune Enrollment
A troubleshooting walkthrough of the path from Active Directory through Entra Connect and Hybrid Entra ID Join to Intune enrollment: where it breaks and how to check each step.
- Status: In progress
- Based on work experience
- Example
Overview
- Active DirectoryComputer object in synced OU
- Entra ConnectDevice object synchronised
- Hybrid Entra ID JoinDevice registers, gets PRT
- Intune EnrollmentGPO triggers auto-enrollment
Problem
Example scenario: a domain-joined Windows device doesn't appear in Intune. In Entra ID it is either missing or shows as “Pending”.
Analysis
Checking the chain from the start, one link at a time:
- Is the computer object in an OU included in Entra Connect synchronisation scope?
- Is the Service Connection Point (SCP) configured, or is client-side registry targeting in place?
- What does dsregcmd /status report for AzureAdJoined, DomainJoined and AzureAdPrt?
- Does the device reach the required Microsoft endpoints (proxy, TLS inspection)?
- Is the auto-enrollment GPO applied, and is the user in the MDM user scope with an Intune licence?
dsregcmd /status | Select-String "AzureAdJoined|DomainJoined|AzureAdPrt|TenantName"
# Did the auto-enrollment policy apply?
gpresult /r /scope computer
# Registration and enrollment events
Get-WinEvent -LogName "Microsoft-Windows-User Device Registration/Admin" -MaxEvents 20
Get-WinEvent -LogName "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" -MaxEvents 20Solution
The fix depends on which link failed. Typical examples: adding the OU to sync scope, correcting the SCP, allowing device registration endpoints through the proxy, or fixing the GPO scope (Computer Configuration → Administrative Templates → Windows Components → MDM → Enable automatic MDM enrollment using default Azure AD credentials).
Result
Outcome to be added from a real, anonymised case.