Hybrid Azure AD Join information not registered in SCCM

Vijayaguru M 21 Reputation points
2021-02-25T13:12:48.463+00:00

Hi,

We have recently configured CMG in our SCCM environment for internet based clients. We are running SCCM 2006 in our environment and managing both servers and workstations. All the VPN boundaries associated with CMG Management Point.

I am having couple of issues in Hybrid AD joined as described below.

  1. Many of our Laptops are hybrid AD joined and communicate with CMG for content download. There are few Windows 10 laptops (irrespective of OS Build version) which shows Hybrid Azure AD joined in Azure Portal but the information is not registered in SCCM database. ex. AAD TenentID shows NULL in CM database and Hybrid AD value set to 0. I tried clean reinstalling client and ran HW inventory and DDR cycle but nothing worked out. Could you please advise what could be the issue and how do i get those information updated in SCCM DB?
  2. There are some Windows 10 1607 or older build version having issue with joining Hybrid Azure AD. I tried the below commands which work for few laptops but not all. Please advice

dsregcmd /leave /debug
dsregcmd /debug /join

Error:

"AdalLog: Token response is not successfull. Status:400 ResponseText:{"error":"in
valid_grant","error_description":"AADSTS51004: The user account AFG9DKIeVkuS5Iln
cvHizw== does not exist in the 24df34ab-a358-4b62-ba14-e5dfb43b9d63 directory. T
o sign into this application, the account must be added to the directory.\r\nTra
ce ID: f0df8c14-a4af-4749-9728-8400ef163900\r\nCorrelation ID: 6f5531cc-cda4-4f7
a-9392-2836786cca46\r\nTimestamp: 2021-02-25 07:04:56Z","error_codes":[51004],"t
imestamp":"2021-02-25 07:04:56Z","trace_id":"f0df8c14-a4af-4749-9728-8400ef16390
0","correlation_id":"6f5531cc-cda4-4f7a-9392-2836786cca46","error_uri":"https://
login.microsoftonline.com/error?code=51004"} ; HRESULT: 0x0
AdalLog: Webrequest returns error code:invalid_grant and error description:AADST
S51004: The user account AFG9DKIeVkuS5IlncvHizw== does not exist in the 24df34ab
-a358-4b62-ba14-e5dfb43b9d63 directory. To sign into this application, the accou
nt must be added to the directory.
Trace ID: f0df8c14-a4af-4749-9728-8400ef163900
Correlation ID: 6f5531cc-cda4-4f7a-9392-2836786cca46
Timestamp: 2021-02-25 07:04:56Z ; HRESULT: 0x0
AdalLog: HRESULT: 0xcaa20003
AdalLog: HRESULT: 0xcaa90006
LogFatalAuthError: AdalMessage: GetStatus returned failure
AdalErrorCode: 0xcaa90006
AdalCorrelationId: 6f5531cc-cda4-4f7a-9392-2836786cca46
AdalLog: HRESULT: 0xcaa90006
AdalLog: HRESULT: 0xcaa20003
AdalLog: Webrequest returns error code:invalid_grant and error description:AADST
S51004: The user account AFG9DKIeVkuS5IlncvHizw== does not exist in the 24df34ab
-a358-4b62-ba14-e5dfb43b9d63 directory. To sign into this application, the accou
nt must be added to the directory.
Trace ID: f0df8c14-a4af-4749-9728-8400ef163900
Correlation ID: 6f5531cc-cda4-4f7a-9392-2836786cca46
Timestamp: 2021-02-25 07:04:56Z ; HRESULT: 0x0
AdalLog: Token response is not successfull. Status:400 ResponseText:{"error":"in
valid_grant","error_description":"AADSTS51004: The user account AFG9DKIeVkuS5Iln
cvHizw== does not exist in the 24df34ab-a358-4b62-ba14-e5dfb43b9d63 directory. T
o sign into this application, the account must be added to the directory.\r\nTra
ce ID: f0df8c14-a4af-4749-9728-8400ef163900\r\nCorrelation ID: 6f5531cc-cda4-4f7
a-9392-2836786cca46\r\nTimestamp: 2021-02-25 07:04:56Z","error_codes":[51004],"t
imestamp":"2021-02-25 07:04:56Z","trace_id":"f0df8c14-a4af-4749-9728-8400ef16390
0","correlation_id":"6f5531cc-cda4-4f7a-9392-2836786cca46","error_uri":"https://
login.microsoftonline.com/error?code=51004"} ; HRESULT: 0x0

Thanks,
VJ

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. AllenLiu-MSFT 40,551 Reputation points Microsoft Vendor
    2021-02-26T07:01:10.65+00:00

    Hi, @Vijayaguru M
    Thank you for posting in Microsoft Q&A forum.
    When you open cmd prompt and run the command: Dsregcmd /status, what is the device state info?
    And may we know what table or view have you checked in SCCM database?

    And for the issue about windows 10 1607 or older build version joining Hybrid Azure AD, I think we may get better support in Azure support.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Jason Sandys 31,161 Reputation points Microsoft Employee
    2021-02-26T16:05:11.973+00:00

    There are some Windows 10 1607 or older build version having issue with joining Hybrid Azure AD.

    These systems are completely unsupported (and have been for a couple of years now) and can't be co-managed. Until you upgrade them to a supported version of Win 10, there's nothing you can do to make them function properly in the above scenario.