Configure Device Registration with Azure AD Connect

Azure AD Connect is a great tool to On-board your On-Premise Identities to the Azure Cloud. If you like to use a Hybrid Join of your Windows 10 Devices – Local Domain join & Azure AD join – you can configure Device Registration. What is the benefit if you enable this option?

PREPARE

Since a few version back of Azure AD Connect it allows you to use the wizard to configure the necessary options for you. First of all, make sure you use the latest version of Azure AD Connect. You can also check the Auto-Upgrade Option of the engine by using the PowerShell command on the server where AAD Connect is installed:

Get-ADSyncAutoUpgrade
Further information can found here.

CONFIGURE AZURE AD CONNECT

Run Azure AD Connect – Configure – and select “Configure device options”

2018-08-15 19_29_00-Window

On the “Overview” page click Next.
On the “Connect to Azure” page enter your Global Admin credentials and click Next.
On the “Device options” page select “Configure Hybrid Azure AD Join” and click Next.

2018-08-16 12_57_27-192.168.1.4 - Remote Desktop Connection

On the next step you will configure the Service Connection Point (SCP) to help your Windows 10 devices to find the necessary Azure Tenant information’s. To configure the SCP you need to provide Enterprise Admin Credentials. If you cannot provide this credentials during the wizard, you will be able to download the script to set the SCP in a later phase or offline.

2018-08-16 13_01_08-192.168.1.4 - Remote Desktop Connection

This step helps you also to verify your current configuration. AAD Connect is checking the configured configuration on your AD. You can manually to that by browsing your ADSI Editor. Connect to the configuration naming context and then load the CN:   “CN=ms-DS-Device-Registration-Service,CN=Schema,CN=Configuration,DC=xy,DC=xy”

2018-08-16 13_16_52-192.168.1.4 - Remote Desktop Connection

Back to the wizard, provide the Enterprise Admin credentials and click “Next”.

2018-08-16 13_09_18-192.168.1.4 - Remote Desktop Connection

Device Registration is also supported for Windows Downlevel Devices, like Windows 10 prior 1607 build, Windows 8.1, 8 & 7. For further information regarding downlevel devices visit the docs.microsoft.com page.

2018-08-16 13_10_51-192.168.1.4 - Remote Desktop Connection

This will configure the Device Registration for a Hybrid Join. Click configure.

2018-08-16 13_14_01-192.168.1.4 - Remote Desktop Connection

This will complete your On-Prem configuration for Device Registration.

2018-08-16 13_43_25-192.168.1.4 - Remote Desktop Connection

POST CONFIGURATION TASKS

https://docs.microsoft.com/de-ch/azure/active-directory/connect/active-directory-azure-ad-connect-hybrid-azure-ad-join-post-config-tasks

Check out point 10 on the post tasks. You should create a GPO to make sure your devices getting Hybrid joined in Azure:

  • Create a new GPO and Name it
  • Computer Configuration > Policies > Administrative Templates > Windows Components > Device Registration
  • Select : Register domain-joined computers as devices
  • OK
  • Link the policy to your Windows 10 Devices

 

7 thoughts on “Configure Device Registration with Azure AD Connect”

  1. Question: What will happen to the clients after the azure ad hybtid join configuration is set? What will the clients that are scoped within the OU we specified to sync out to AAD? And what will happen to the rest of the clients not scoped if they find the SCP?

    Liked by 1 person

    1. As long your not setting an Intune policy to Azure Hybrid joined devices, nothing will happen. They will appear in your Azure Portal as Hybrid Joined devices. If no GPO is scoped to a specific group or OU of devices, they will not apear in the portal and not been hybrid joiend. You can find details in this article:
      https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-control

      Let me know if you have more questions.
      Regards,
      Al

      Like

  2. Hi Al,
    First of all , i like to thank you for the article. it has helps me understand device registration and how windows 10 is getting registered in Azure Ad (manage and federated)
    I have question on backout plan for device registration – After implementation of device registration (it is updated in schema). If i decide to back out (i.e no more device registration). What steps do i follow or you have an article on it.

    Like

    1. Hi,
      You can remove the SCP (Service Connection Pont) in the local Forest or / and remove the ADFS configuration for device registration. Also disable the Automatic MDM enrollment in Intune and remove the local GPO to register and ernroll in MDM. This will stop devices to appear in Azure AD.
      Hope this helps.
      Cheers,
      Al

      Like

Leave a Reply to Al Schneiter Cancel reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: