The end result is to be able to use Hello for Business. Not doing anything with FS.
Have a DC, that is linked to AAD through Connect using HASH.
All devices currently show Azure AD registered.
Have gone in the AAD Connect configuration and done this process to enable SCP - https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains.
It has been left to percolate for a couple hours, and nothing has changed for the device status, and not changing to Hybrid AAD Joined.
If I run dsregcmd /status, it shows it is just domain joined. There is an error listed in the discover step.
Error Phase: discover
Client ErrorCode: 0x801c001d
https://enterpriseregistration.windows.net - If I go through my browser, it fails to connect saying endpoint not found. There is though nothing blocking outbound traffic.
https://login.microsoftonline.com - Works fine
https://device.login.microsoftonline.com - Error about not being able to sign in. If I open in private mode, it wants a certificate, which I only have one, and it fails on it.
I am kind of stuck, and having to jump around through 20 different Microsoft Doc's is not helping.

