We are performing a targeted deployment (formerly controlled validation) to Hybrid Azure AD Join our Windows 10 workstations. We have a federated environment. We're using MECM (formerly SCCM), so the machines will be co-managed once they are Hybrid Joined. The first batch of machines that we successfully hybrid joined (according to 'dsregcmd /status' and a 'Hybrid Join' join type in Azure Active Directory), do not show the Azure AD domain in the 'Access Work or School' settings. However, the on-prem Active Directory domain is there. In MECM, we're using the pilot option for Cloud Attach, so we can gradually switch the workloads over from MECM/Group Policy to Intune. Present, the only workload transferred is Endpoint Security, which should include cloud policy settings directly related to Defender.
I discovered the AAD domain was missing from 'Access work or school' when I attempted to perform a policy sync. The procedure is to go into the 'Access work or school' settings and trigger a policy sync from the AAD domain connection item. Obviously I can't do that if the only connection item is the on-prem domain. Perhaps it won't appear until I switch over one of the other workloads to Intune?