Windows Autopilot user-driven mode for hybrid Azure Active Directory join

Applies to: Windows 10

Windows Autopilot requires that devices be Azure Active Directory joined. If you have an on-premises Active Directory environment and want to also join devices to your on-premises domain, you can accomplish this by configuring Autopilot devices to be hybrid Azure Active Directory (AAD) joined.

Requirements

To perform a user-driven hybrid AAD joined deployment using Windows Autopilot:

  • A Windows Autopilot profile for user-driven mode must be created and
    • Hybrid Azure AD joined must be specified as the selected option under Join to Azure AD as in the Autopilot profile.
  • If using Intune, a device group in Azure Active Directory must exist with the Windows Autopilot profile assigned to that group.
  • The device must be running Windows 10, version 1809 or later.
  • The device must be connected to the Internet and have access to an Active Directory domain controller.
  • The Intune Connector for Active Directory must be installed.
    • Note: The Intune Connector will perform an on-prem AD join, therefore users do not need on-prem AD-join permission, assuming the Connector is configured to perform this action on the user's behalf.

AAD device join: The hybrid AAD join process uses the system context to perform device AAD join, therefore it is not affected by user based AAD join permission settings. In addition, all users are enabled to join devices to AAD by default.

Step by step instructions

See Deploy hybrid Azure AD joined devices using Intune and Windows Autopilot.

Also see the Validation section in the Windows Autopilot user-driven mode topic.