Update cahced domain creds on device with AAD/InTune/AADConnect

Aaron 21 Reputation points
2020-09-18T13:32:06.923+00:00

So we are currently set up in a hybrid AAD join enviroment. And we have recently got InTune as well. We are talking about going full Azure AD join in the coming few months, but for the mean time, I do know that you can enable pass through authentication to send the users password out from the on-prem DC to their device and enable them to be prompted to change their password with o365/Azure, but the domain creds on the device that are cached, aren't able to be changed so they will still have to use their new password with any o365 apps, azure apps, etc... but still have to use their old password that is cached on their machine to login to their laptop daily. I want to fix that, preferrably without using a DirectConnect or VPN, until we go full Azure AD Join cause I know it's possible that way since there won't be an on-prem DC anymore.

Can anyone suggest any kind of insights or ideas on how to get that to work successfully without a DirectConnect or VPN? Azure enviroment is fairly new to me and I am still learning it. Any help is appreciated.

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,410 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,683 questions
0 comments No comments
{count} votes

Accepted answer
  1. Jason Sandys 31,171 Reputation points Microsoft Employee
    2020-09-18T16:39:35.54+00:00

    This is a fundamental design limitation of Windows and on-prem domain join. Line of sight to a domain controller is 100% required for inital logins and password changes. Anything else is not possible.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful