Skip to content

Migrating Devices from Entra Hybrid Join to Entra Join: A Cloud-First Approach

Migrating Devices from Entra Hybrid Join to Entra Join: A Cloud-First Approach

Section titled “Migrating Devices from Entra Hybrid Join to Entra Join: A Cloud-First Approach”

Migrating devices from Entra Hybrid Join to Entra Join is an important step for organizations embracing a modern, cloud-first IT infrastructure. Starting with this configuration sets a strong foundation for security, scalability, and simplified management.

Since our initial engagement with Microsoft around Zero Trust security, we have decided to start with Entra Join instead of Hybrid Join, aligning with Microsoft’s recently adjusted recommendations. Here’s why it’s beneficial to start with Entra Join for both new deployments and device refreshes, and how group policies should be managed during the transition.


Entra Join represents Microsoft’s cloud-first approach to device management, eliminating the complexities of hybrid environments while providing enhanced security and simplified administration.


BenefitCapabilityBusiness Value
Simplified ManagementCloud-only device management through Microsoft IntuneEliminates hybrid complexity and reduces administrative overhead
Enhanced ScalabilityStandardized cloud-native device managementSupports organizational growth without infrastructure changes
Improved SecurityModern security baselines and policiesEnsures devices meet current security standards
Future-ReadyAligned with Microsoft’s cloud ecosystemPrepares for ongoing cloud innovations and features

While Hybrid Join adds the PC to Azure AD and enables the use of conditional access and other controls, it introduces several challenges, particularly for devices that do not consistently connect to a VPN or corporate network.

IssueImpactRoot Cause
Machine Account Password ChangesDomain trust issues requiring manual interventionInfrequent VPN connections prevent password rotation
User Password Changes and CachingAuthentication failures for remote usersNew AD passwords not cached without VPN connectivity
TPM ResetsSecurity module synchronization problemsLack of secure on-premises network connection
Group Policy UpdatesOutdated security and compliance policiesDevices not receiving updated GPOs without VPN
AD Security Group MembershipRestricted access to resources and applicationsGroup membership changes not synchronized
Certificate IssuesAuthentication failures and service disruptionsDelayed certificate issuance and renewal
Policy ConflictsInconsistent device configurationsDual management by Group Policy and Intune

Ideal for: Fresh deployments and new device provisioning

Approach: Adopt Entra Join from the start for all new devices and users.

Key Benefits:

  • Consistent Deployment: Automatic enrollment in Microsoft Intune with uniform configuration profiles
  • Future-Proofing: Alignment with Microsoft’s cloud-first management direction
  • Simplified Onboarding: Streamlined device provisioning and user setup

Ideal for: Hardware replacement cycles and device reassignment

Approach: Migrate refreshed devices from Entra Hybrid Join to Entra Join.

Implementation Steps:

  • Reset and Re-enrollment: Use Microsoft Autopilot to provision devices under Entra Join
  • Latest Security Baselines: Ensure devices receive current security configurations
  • Consistent Policies: Apply uniform cloud-managed policies across all devices

Before migrating from Entra Hybrid Join to Entra Join, ensure:

  • No On-Premises Dependencies: Verify no applications rely on machine authentication
  • Certificate Configuration: Address Wi-Fi access point certificates, especially with RADIUS authentication
  • Alternative Authentication: Implement Intune-pushed certificates or user credentials for Wi-Fi access

Challenge: Users will receive a new user profile during migration.

Solution: Use tools like ProfWiz to migrate user profiles:

  • Preserve user settings, files, and configurations
  • Minimize disruption during the transition
  • Maintain continuity of user experience

A key part of transitioning from hybrid join to Entra Join is managing group policies effectively.

Policy TypeMigration ApproachRecommended Solution
Security PoliciesReplace, don’t migrateMicrosoft Security Baselines in Intune
Configuration SettingsMigrate to cloud-native formatIntune Configuration Profiles
Unsupported SettingsCustom implementationPowerShell or custom scripts via Intune
Policy AnalysisEvaluate before migrationGroup Policy Analytics in Intune
  1. Policy Analysis: Use Group Policy Analytics to import and analyze existing GPOs
  2. Security Baseline Adoption: Implement Microsoft Security Baselines for modern security
  3. Configuration Migration: Convert Group Policy settings to Intune Configuration Profiles
  4. Gap Filling: Deploy custom scripts for unsupported settings
  5. Validation: Test policies to ensure consistent configuration

Key Takeaway: Migrating devices from Entra Hybrid Join to Entra Join is the optimal path for modern, cloud-first organizations seeking enhanced security and simplified management.

Benefits of Migration:

  • Streamlined Management: Centralized control through Intune
  • Enhanced Security: Modern security baselines and policies
  • Improved Scalability: Support for organizational growth
  • Reduced Complexity: Elimination of hybrid environment challenges

Migration Outcomes:

  • Resolved Common Issues: Eliminates password rotation, policy update, and connectivity problems
  • Cloud-First Operations: Devices fully equipped for modern management environments
  • Zero Trust Foundation: Strong security posture aligned with Microsoft recommendations

By transitioning to Entra Join, organizations can phase out legacy infrastructure while maintaining robust security and operational consistency across their device fleet, positioning themselves for a more secure and manageable future.