Jump to content

Recommended Posts

Posted

We had intune working fine using hybrid joined for approx 10 laptops until recently where devices would failed when users sign in for the first time to set them up etc.

 

After a dig around, turns out it is an issue with the profile we are currently using and line of site to network, so the devices are unable join AD etc

 

I can spend some time fixing the issue or I can create a new profile and have new devices as Entra Joined only.

 

If all goes well for September we will be going laptops for staff, so ideally I’d like to get this right now and not struggle and run into issues later on like I am now!

 

What join type are other people using? And why?

 

I’m happy to say I don’t know enough about intune and if it warrants paying someone to give it a once over and configure it correctly then great - one less area for me worry about being secure.

 

Cheers

Posted
We are currently in a split, of shared devices being hybrid joined but Configuration Manager managed, 1:1 devices (currently only for staff) are Intune managed and Azure AD joined. With the recent Cloud Trust you can still seamlessly sign on to on-prem resources with a user logged in using Windows Hello (assuming the user is synced from on-prem rather than cloud only), one of the previous sticking points for us (there were ways round this - key trust/certificate trust - but they were not very reliable)
Posted
We are currently in a split, of shared devices being hybrid joined but Configuration Manager managed, 1:1 devices (currently only for staff) are Intune managed and Azure AD joined. With the recent Cloud Trust you can still seamlessly sign on to on-prem resources with a user logged in using Windows Hello (assuming the user is synced from on-prem rather than cloud only), one of the previous sticking points for us (there were ways round this - key trust/certificate trust - but they were not very reliable)

 

Hi,

 

Our hybrid joined works well as well. But we want to move intune only manage devices but same time need to configure on prem resource access.

 

How did you setup your environment?

Posted
Hi,

 

Our hybrid joined works well as well. But we want to move intune only manage devices but same time need to configure on prem resource access.

 

How did you setup your environment?

 

Assuming your users are all synced from on-prem AD, then logging on using username/password to an Azure AD joined device they will automatically be able to access on-prem domain file shares, printers etc. To have this work if they log in with Windows Hello you need to set up (preferably, as it's the easiest) Cloud Kerberos Trust - as per https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust?tabs=intune - basically creates an object in AD and sets a couple of settings in Intune policy. You also need ms-KeyCredentialLink attribute to be writing back from Azure AD to on-prem AD (I think this is configured by default in Azure AD Connect, unless it's a very old configuration). This attribute is where the public key for the Windows Hello lives for the user (the private key being on the specific device).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...