How to overcome from issue after migrating from one forest to another for Hybrid Azure AD joined devices scenario?

Prabhjot Singh 145 Reputation points
2024-04-10T16:10:14.9433333+00:00

I'm trying to migrate a Hybrid Azure AD joined workstation from one domain to another in a different forest. I used PowerShell to unregister the device from Azure AD and signed out of all Microsoft 365 applications. I also deployed an application package in SCCM to restart the device and join it to the new domain. After joining the new domain, everything seemed fine, but some applications are still asking for old credentials instead of new ones. Additionally, I'm getting an error in Settings>Account>Access Work or School, saying 'sync wasn't fully successful because we weren't able to verify your credentials.' How can I fix this?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,876 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,251 questions
Microsoft Configuration Manager
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,506 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,146 Reputation points MVP
    2024-04-10T21:28:52.76+00:00

    Is the hybrid join successful in the new domain? Are the user identities synced in the new domain?


  2. Akhilesh 4,775 Reputation points Microsoft Vendor
    2024-04-16T13:12:56.7633333+00:00

    Hi @Prabhjot Singh

    Thank you for reaching out to the community forum!

    I understand that you are facing issues with some applications asking for old credentials after migrating a Hybrid Azure AD joined workstation from one domain to another in a different forest. Additionally, they are getting an error 'sync wasn't fully successful because we weren't able to verify your credentials.
    After migrating some applications to continue prompting for old credentials due to cached information. could you try to remove any stored credentials related to the old domain from Credential Manager.

    Also, please ensure that the device was completely unregistered from the old Azure AD before joining the new domain.

    The other side about the error 'sync wasn't fully successful because we weren't able to verify your credentials' This issue occurs when MFA is Enabled or Enforced, or Microsoft Entra Conditional Access policies that require MFA are applied to all cloud apps. It prevents user association with the device in the portal. To fix the issue Set MFA to Disabled or modify the Conditional Access policies are used.

    Reference: https://learn.microsoft.com/en-us/troubleshoot/mem/intune/comanage-configmgr/troubleshoot-co-management-auto-enrolling#devices-fail-to-sync-after-auto-enrollment

    https://techcommunity.microsoft.com/t5/microsoft-intune-blog/understanding-hybrid-azure-ad-join-and-co-management/ba-p/2221201

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.