Hello, As with many other institutions, we are planning to join our Windows 10 desktops to Azure AD and autoenroll into MS Intune. We have an on Prem AD and would like to Hybrid Join our Workstations. We have a VPN setup for remote access to the office. The only machines currently joined to AAD are the test devices I have been using. I have tested joining via "Accounts/Access Work or School" but I prefer the on Prem GPO method (with a group of machines in "Security Filtering") because its less user interaction. We have Azure AD Sync running on our DC. We also setup a user group that is associated to the "Device Restrictions Policy" and our "Compliance Policy" in MS Intune.
We have three types of machines as shown below:
1. Office Desktops that have been moved to employee's homes. These machines are joined to on Prem AD
2. Office Laptops that are being used in employee's homes. These machines are joined to on Prem AD and may also be AAD Registered because the user logged into OFfice365.
3. Brand new laptops that are sent directly to employee's homes. These laptops are being joined to on Prem AD. They may also be AAD Registered because the user logged into OFfice365 or entered thier work email during the initial setup of Windows.
My questions are:
Will Hybrid AAD Join work well for all three categories of machines listed above?
Once a machine is Hybrid Joined, will the user be able to login with their on Prem AD credentials (username@onprem.contoso.com)? For ex. If we enable always on VPN and the user logs in using on Prem AD credentials. Also will the user have the option to login with thier AAD credentials (username@contoso.com)? For ex. If a user tries to login while wifi is connected but the VPN is not connected.
Lets say an on Prem domain joined laptop/desktop is sent to a user's home. This user has never logged into this device but the device is Hybrid joined (Via the on Prem GPO settings). Will the user be able to login with AAD credentials being that there are no on prem cached credentials and VPN is not enabled?
Also will the local user profile be different for the AAD login vs on Prem AD login?
We use Google Apps and allow our users to enable email alias'. The email alias is stored in the on Prem "mail" attribute. A custom on Prem AD attribute is populated with the SAMAccountName@contoso.com by our Identity System (in order to have a record of the default email address). Of course, the userPricipalName contains the SAMAccountName@onprem.contoso.com. It seems that this may cause some issues because some users are entering thier default email address and others enter thier alias. Can AAD accept both mail attributes and associate them to the same AAD user? Any advice is appreciated.
We want to use MS Intune to enable Always on VPN. Any advice is appreciated.
I have been reading that AD credentials are cached for 30 days but can be adjusted. Should we be adjusting this value in the scenario I am describing?
Any advice is appreciated.