Greetings: I have a scenario that I believe should be possible, but I was hoping if someone could confirm. Environment is an on-prem forest, thousands of machines. We have a footprint in azure with AD Connect synchronizing. Machines are Hybrid AD Joined.
+----------------------------------------------------------------------+
| Device State |
+----------------------------------------------------------------------+
AzureAdJoined : YES
EnterpriseJoined : NO
DomainJoined : YES
DomainName : <netbios domain name>
Device Name : <machine.fqdn>
I'm looking to find a way to get a user into a new device once they receive it. They will not have visibility to a domain controller, but they should have internet access with an azure ad account sync'd from AD Connect.
To be clear, I'm not looking to gain access to any specific resources on prem - I just need to get the user logged into the machine.