question

ShijinMohammed-5429 avatar image
0 Votes"
ShijinMohammed-5429 asked ·

Enrol SCCM managed hybrid AD Win 10 devices to Intune

Hi,

We have hybrid AD Win 10 devices that are managed by SCCM. Now we need to enrol those hybrid AD devices to Intune and we are able to do it by pushing the MDM GPO. We haven't done anything in SCCM co-management settings so far like enablement of Co-management

Are there any changes we need to do for achieving our target? We are after patching (Quality / Feature / Office Updates) those devices via Intune instead of SCCM.


TIA
Shijin M73876-1.png


mem-intune-enrollmentmem-cm-co-management
1.png (74.7 KiB)
· 1
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Need more information. Are you saying,

1) Machines managed by SCCM
2) They are Hybrid Azure AD joined
3) MDM GPO deployed to this PC
4) No co-management setting turned ON

Still a machine managed by SCCM enrolled in Intune? Ideally this is not possible.

0 Votes 0 ·
YashGarg-6451 avatar image
2 Votes"
YashGarg-6451 answered ·

Hi,

there are 2 things here which we need to see ,

Firstly if you are enrolling the devices Via GPO, and the sccm is already there in the machine , the state of the machine will be a co-managed state once the sccm client is detected . Now since you are opting to go for the intune enrollment via sccm client ,you can also utilize it but first you need to make sure the autoenrollment collection it should a Pilot collection (You can take it as a test collection) , the devices in this group will be enrolled via sccm client for a reference the flow is too large you can check the basic things in the task scheduler the task name "Enterprise management" will be created and the you can check the comanagementhandler.log.


You mentioned that you need to enable the patching on the machines for this you need to configure the workloads which are defined , the 2 workloads which you need to move to the Intune pilot / Intune (based on the environment) is the office click to run apps and the windows update policy . The office click to run apps will make sure the apps are deployed via intune There's a new global condition, Are Office 365 applications managed by Intune on the device. This condition is added by default as a requirement to new Microsoft 365 applications. You can then enable the updates to them via ADMX in intune https://docs.microsoft.com/en-us/mem/intune/configuration/administrative-templates-update-office
For the quality updates and the feature updates , you have the windows update rings which you can target accordingly from MEM console.

Just for FYI : If the workload remains on SCCM and you target policy via Intune /MEM it will be shown as not applicable as the machine will not be able to determine the policy is coming from MEM since workload is still on sccm

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Jason-MSFT avatar image
1 Vote"
Jason-MSFT answered ·

You definitely need to enable co-management otherwise the ConfigMgr client will prevent nearly all Intune management of the devices. There's also no need to enroll the devices in MDM using a GPO as that's part of the functionality included in co-management.

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Crystal-MSFT avatar image
1 Vote"
Crystal-MSFT answered ·

@ShijinMohammed-5429. For the Hybrid Azure AD joined device which are not managed by SCCM, we can put these devises into one OU and assign the GPO for the enrollment. For the Hybrid Azure AD joined device which are manged by SCCM, we can consider co-management.

Here is an article describe the prerequisites and steps to enable co-management for existing configuration Manager Clients. We can read it as a reference:
https://docs.microsoft.com/en-us/mem/configmgr/comanage/tutorial-co-manage-clients

Hope it can help.


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.