What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To hybrid join a Windows device and manage it with Intune, first synchronize the right on-premises Active Directory devices to Microsoft Entra ID, configure and pilot hybrid join, then set a deliberate Intune automatic-enrollment scope for licensed users. These are separate states: a device can be hybrid joined without being enrolled in Intune.
Decide whether hybrid join is the right target
Hybrid Microsoft Entra join connects a domain-joined Windows device to Microsoft Entra ID while retaining its on-premises Active Directory domain membership. It can suit organizations that still depend on domain controllers, AD-based resources, or existing domain management. Microsoft recommends cloud-native Microsoft Entra join for new devices; hybrid join remains a documented option when those on-premises dependencies persist. In particular, Autopilot hybrid provisioning adds dependencies rather than making hybrid join a simpler greenfield choice.
| Consideration | Cloud-native Microsoft Entra join | Hybrid Microsoft Entra join |
|---|---|---|
| Domain-controller access | Does not require joining the device to an on-premises AD domain. | Requires on-premises domain membership and domain-controller connectivity for relevant operations. |
| Directory and configuration dependencies | Does not rely on synchronizing the device’s AD computer object or configuring hybrid-join discovery for that object. | Depends on correctly scoped directory synchronization and hybrid-join configuration, including applicable computer OUs and discovery settings. |
| Legacy AD resources and policy | Check that required resources and policies work for cloud-joined devices before choosing this route. | Can preserve domain membership for environments that still require it. |
| Autopilot provisioning | Microsoft’s recommended direction for new devices. | Requires additional connector, domain-join profile, and network dependencies. |
| Migration direction | Aligns with a move away from on-premises domain dependencies. | Can maintain an existing hybrid environment, but preserves those dependencies. |
Assess domain-controller reliance, legacy application and resource requirements, synchronization and OU scope, provisioning complexity, and your migration direction before selecting a target.
Confirm prerequisites before changing configuration
Check synchronization and device scope
- Confirm Microsoft Entra Connect Sync is configured and that the intended computer-object OUs are included in synchronization scope.
- Ensure default device attributes have not been filtered from synchronization.
- The Microsoft setup guidance lists Microsoft Entra Connect version 1.1.819.0 or later. Treat that as a version floor stated by that guide, not as confirmation that this is the currently supported release; check Microsoft’s live requirements before implementing or upgrading.
Use Microsoft’s Microsoft Entra hybrid-join configuration guidance for current setup requirements.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Check permissions and user eligibility
Confirm that administrators have the required tenant and on-premises forest privileges, and that users are allowed to register devices. For Intune automatic enrollment, identify the intended user scope and verify that every in-scope user has the required licensing. The cited enrollment guidance lists Intune plus Microsoft Entra ID Premium P1 or P2, or a trial; confirm current licensing terms for your tenant before rollout.
Check network access in device context
Devices need line of sight to an on-premises domain controller and access to the Microsoft endpoints for their cloud. For commercial tenants, the cited setup guide names enterpriseregistration.windows.net, login.microsoftonline.com, and device.login.microsoftonline.com. Federated tenants also need access to the organization’s STS, and government clouds use different endpoint domains; use the relevant cloud-specific Microsoft guidance rather than assuming the commercial list applies.
Rank #2
Validate proxy behavior from the machine context, not only from an interactive browser session. Proxy authentication or TLS break-and-inspect can disrupt device registration and certificate authentication. Microsoft identifies device-registration endpoints that should be excluded from TLS inspection; follow the endpoint-specific instructions in its hybrid-join configuration guide and hybrid-join troubleshooting guide.
Configure and pilot hybrid join
- Review synchronization scope. Verify the intended computer OUs and default device attributes in Microsoft Entra Connect Sync before enabling registration.
- Configure hybrid join for the intended forest and domain. Use the Microsoft Entra Connect device-configuration workflow described in Microsoft’s setup guide. Confirm the relevant forest and hybrid-join settings rather than relying on old screenshots or remembered wizard labels.
- Start with targeted deployment. Use Microsoft’s targeted hybrid-join deployment approach to validate configuration on a limited group before broad rollout.
- Validate join and sign-in. Check that pilot devices register successfully and that users can sign in as expected. Resolve discovery, network, or synchronization problems before expanding the deployment group.
- Expand in stages. Once the pilot is healthy, broaden deployment deliberately and monitor join status as additional devices register.
Configure automatic Intune enrollment separately
Hybrid join alone does not enroll a device in Intune. Automatic enrollment is controlled by the MDM user scope: users set to None, Some, or All are treated differently, so select a scope that matches the rollout rather than assuming every hybrid-joined device will enroll.
Rank #3
- In the Intune admin center, go to Devices > Enrollment > Windows > Automatic enrollment.
- Set the MDM user scope to Some for a controlled rollout and choose the pilot group, or choose All only when all eligible users should be in scope. Choose None if automatic enrollment is not intended.
- Verify that pilot users have the required Intune and Microsoft Entra ID Premium licensing, and check that Windows enrollment restrictions and other enrollment policies permit their devices.
- Validate enrollment on pilot devices before increasing the scope.
Microsoft’s Windows automatic enrollment in Intune guide covers the enrollment settings and prerequisites. A join-state success does not prove MDM enrollment succeeded; check both independently.
Use Autopilot hybrid only when its dependencies are justified
Autopilot hybrid deployment is a distinct provisioning route for devices that must join an on-premises AD domain while using Autopilot. It needs more than hybrid-join configuration alone, and Microsoft recommends cloud-native Microsoft Entra join for new devices.
Rank #4
- Configure Intune automatic enrollment and confirm the intended users are licensed and in MDM scope.
- Install and validate the Intune Connector for Active Directory.
- Create and assign an Autopilot deployment profile configured for hybrid join.
- Create and assign a domain-join configuration profile with the AD domain and OU details.
- Ensure the deploying device can reach the Internet and an AD domain controller during the required stages.
Connector requirements can be version-specific. Check the current Autopilot hybrid deployment guidance for supported connector requirements and configuration details before deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Verify join and enrollment as separate outcomes
Check the device’s join state
Run dsregcmd /status in an appropriate elevated or user context and inspect Device State. A successfully hybrid-joined device should show both AzureAdJoined : YES and DomainJoined : YES. If either value is missing, troubleshoot the join path before treating the device as ready.
Best Value
Triage a join failure
- Check that the device’s computer object is in a synchronized OU and that the required attributes are not filtered.
- Check hybrid-join discovery and Service Connection Point (SCP) configuration.
- Confirm domain-controller line of sight and machine-context access to the relevant registration endpoints.
- Review proxy authentication and TLS inspection behavior for device registration.
Use Microsoft’s hybrid-join troubleshooting guidance to match symptoms to the current diagnostic steps.
Triage an enrollment failure
If the device is joined but not managed in Intune, investigate enrollment rather than repeating join configuration. Check the user’s license and MDM scope, Windows support status, applicable enrollment restrictions, MDM discovery URL, and any enrollment Group Policy configuration. Microsoft’s MDM enrollment diagnostics explains how to diagnose client enrollment failures.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

