Windows 10: Hybrid AD join using ON PREM ADFS settings

Discus and support Hybrid AD join using ON PREM ADFS settings in Windows 10 Customization to solve the problem; Hey guys,We are currently testing with Hybrid AD joined devices. The joining works correct and the systems get the AD hybrid joined status. However the... Discussion in 'Windows 10 Customization' started by Frank van den Bogaard, May 31, 2021.

  1. Hybrid AD join using ON PREM ADFS settings


    Hey guys,We are currently testing with Hybrid AD joined devices. The joining works correct and the systems get the AD hybrid joined status. However the hybrid joined systems ignore the settings that are in our on prem ADFS server.We have a rule that for intranet zone based on IP the user doesn't have to use SSO. Machines that are just local domain joined work fine but the hybrid ones seem to ignore the on prem adfs server. We are using a third party Relying Trust name surfconext.nl.Is there logging i can check somewhere ?

    :)
     
    Frank van den Bogaard, May 31, 2021
    #1
  2. Dino-M Win User

    Disconnecting on prem AD and then joining Azure AD creates new Windows profile?

    Hello everyone,

    I have a question about joining computers in my firm from on prem AD to Azure AD. When someone new arrives at our firm (new employee), there is a fresh installation of Windows 10. It is easy to join Azure AD
    because it is a fresh start, but now we have to migrate all Windows 10 users that are on prem AD to Azure AD. When I disconnect those users from our local on prem AD and join them to Azure AD, whole new Windows 10 profile is created, without any of settings,
    data or anything else on that profile (clean profile with few applications that are installed computer-wide). So my question is, is there any solution to keep their profile settings from before they joined Azure AD? Or I will have to simply tell them to backup
    everything (essential data).

    What I tried so far:

    • Tried tools for migration like ForensiT (User Profile Wizard, User Profile Manager and Transwiz, just to see if it is going to work) - not successful
    • Tried changing profile path from registry - not successful
    • Tried log in with the old credentials example: CONTOSO\user (because after I joined that computer to Azure AD user should log in as *** Email address is removed for privacy ***) - not successful
    Is there anything else I can try? Thanks for your answers.
     
    Dino-M, May 31, 2021
    #2
  3. WojtekSzk Win User
    Azure AD Banned Password List without On-Prem Agent

    Hi All,

    I am considering enabling banned password list for our Azure AD in our hybrid environment and want to ask, how doing that will affect our environment if we do not install the on-prem DC agent, as our on-prem does not meet minimum requirements.

    Which password resets and changes will be validated through banned password list and which will not?

    Will 'noncompliant' passwords synced from on-prem to Azure AD be causing issues?

    TIA,

    W
     
    WojtekSzk, May 31, 2021
    #3
  4. Hybrid AD join using ON PREM ADFS settings

    To join a box to on premise or azure ad?

    Right now I am working for a small shop, about 50 folks and like most folks half of them are remote at any give time plus a few permanent remote folks...most of the services that people use are cloud based through other vendors tied back to SAML/ADFS for
    SSO...one of the services is 365, which gives us Azure AD and also a foot in the door with EMS, AD Prem, Write management, etc...

    as one of the first things I did at this gig was stand up few servers for ADFS (inside and proxy) plus Azure Connect...then I did all the AD building and joining of endpoints. but 365 is not Federated yet

    Beginning in windows 10-1511 we can start joining our boxes to the Azure AD...but seems like options are limited, endpoints are managed via intune vice GPOs, not to mention LAPS isnt out there for azure joins let alone bitlocker management

    so I guess its a trade off...would love to here some stories and other folks thoughts...I had a hair brain idea of ditch the adfs boxes (since I basically rent them) and get EMS...but having a hard time getting data and testing
     
    RussellMeyer8516, May 31, 2021
    #4
Thema:

Hybrid AD join using ON PREM ADFS settings

Loading...
  1. Hybrid AD join using ON PREM ADFS settings - Similar Threads - Hybrid join using

  2. Azure and on-prem hybrid and NTP best practices

    in Windows 10 Gaming
    Azure and on-prem hybrid and NTP best practices: Hello allFor those of you in an Azure hybrid environment i.e. on-prem and Azure with DCs in each did you make any changes to NTP on Azure machines or are you using the out of box configuration when using NTP? I assume people are leaving the default for all machines in Azure...
  3. Azure and on-prem hybrid and NTP best practices

    in Windows 10 Software and Apps
    Azure and on-prem hybrid and NTP best practices: Hello allFor those of you in an Azure hybrid environment i.e. on-prem and Azure with DCs in each did you make any changes to NTP on Azure machines or are you using the out of box configuration when using NTP? I assume people are leaving the default for all machines in Azure...
  4. Conditional access in on-prem/ADFS enviroment for windows login

    in Windows Hello & Lockscreen
    Conditional access in on-prem/ADFS enviroment for windows login: Hi!I've been searching for conditional access for the windows login. Could not find anything relevant to my case so far.AD FS relying party trust/access controll policies seems to be controlling access to applications, but I need to control windows logins.GPO require smart...
  5. Conditional access in on-prem/ADFS enviroment for windows login

    in Windows 10 Gaming
    Conditional access in on-prem/ADFS enviroment for windows login: Hi!I've been searching for conditional access for the windows login. Could not find anything relevant to my case so far.AD FS relying party trust/access controll policies seems to be controlling access to applications, but I need to control windows logins.GPO require smart...
  6. Conditional access in on-prem/ADFS enviroment for windows login

    in Windows 10 Software and Apps
    Conditional access in on-prem/ADFS enviroment for windows login: Hi!I've been searching for conditional access for the windows login. Could not find anything relevant to my case so far.AD FS relying party trust/access controll policies seems to be controlling access to applications, but I need to control windows logins.GPO require smart...
  7. Azure AD Hybrid environment with on prem

    in Windows 10 Gaming
    Azure AD Hybrid environment with on prem: I have an existing domain in PA but I want to avoid purchasing a lot of equipment to start a domain in MIA. If I were to choose Azure AD instead on purchasing an On-prem and a server license; purchase all the equipment needs for a on-prem setup isn't neccessary, I can create...
  8. Azure AD Hybrid environment with on prem

    in Windows 10 Software and Apps
    Azure AD Hybrid environment with on prem: I have an existing domain in PA but I want to avoid purchasing a lot of equipment to start a domain in MIA. If I were to choose Azure AD instead on purchasing an On-prem and a server license; purchase all the equipment needs for a on-prem setup isn't neccessary, I can create...
  9. On-prem to azure ad

    in Windows 10 Drivers and Hardware
    On-prem to azure ad: Hi, We have some customers that wants to take all services to azure. We have sett up ad sync so users are loaded up and computers are azurr ad registered. We are trying to find the best way to automate the transfer for the computers. What is the best approach. The...
  10. Windows Autopilot for existing devices supports Hybrid Azure AD Join

    in Windows 10 News
    Windows Autopilot for existing devices supports Hybrid Azure AD Join: First, a quick refresher on Windows Autopilot for existing devices: For customers looking for a path to migrate from Windows 7 (or 8.1) to Windows 10 using Windows Autopilot, the challenge was always that you had to register the existing machines with Windows Autopilot in...