Hybrid Entra ID Join & Intune Enrollment

A troubleshooting walkthrough of the path from Active Directory through Entra Connect and Hybrid Entra ID Join to Intune enrollment: where it breaks and how to check each step.

  • Status: In progress
  • Based on work experience
  • Example

Overview

  1. Active DirectoryComputer object in synced OU
  2. Entra ConnectDevice object synchronised
  3. Hybrid Entra ID JoinDevice registers, gets PRT
  4. Intune EnrollmentGPO triggers auto-enrollment
The chain every hybrid-joined device goes through

Problem

Example scenario: a domain-joined Windows device doesn't appear in Intune. In Entra ID it is either missing or shows as “Pending”.

Analysis

Checking the chain from the start, one link at a time:

  1. Is the computer object in an OU included in Entra Connect synchronisation scope?
  2. Is the Service Connection Point (SCP) configured, or is client-side registry targeting in place?
  3. What does dsregcmd /status report for AzureAdJoined, DomainJoined and AzureAdPrt?
  4. Does the device reach the required Microsoft endpoints (proxy, TLS inspection)?
  5. Is the auto-enrollment GPO applied, and is the user in the MDM user scope with an Intune licence?
powershell
dsregcmd /status | Select-String "AzureAdJoined|DomainJoined|AzureAdPrt|TenantName"

# Did the auto-enrollment policy apply?
gpresult /r /scope computer

# Registration and enrollment events
Get-WinEvent -LogName "Microsoft-Windows-User Device Registration/Admin" -MaxEvents 20
Get-WinEvent -LogName "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" -MaxEvents 20
Example — first checks on the device

Solution

The fix depends on which link failed. Typical examples: adding the OU to sync scope, correcting the SCP, allowing device registration endpoints through the proxy, or fixing the GPO scope (Computer Configuration → Administrative Templates → Windows Components → MDM → Enable automatic MDM enrollment using default Azure AD credentials).

Result

Outcome to be added from a real, anonymised case.

Back to all projects