{"id":5629,"date":"2022-03-15T22:25:26","date_gmt":"2022-03-15T22:25:26","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=5629"},"modified":"2022-03-15T22:25:26","modified_gmt":"2022-03-15T22:25:26","slug":"hybrid-join-computer-to-azure-active-directory-intune-without-access-line-of-sight-to-domain-controller","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/hybrid-join-computer-to-azure-active-directory-intune-without-access-line-of-sight-to-domain-controller","title":{"rendered":"Hybrid Join computer to Azure Active Directory \\ Intune without access (line of sight) to domain controller"},"content":{"rendered":"<p>Machines <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/client-management\/mdm\/enroll-a-windows-10-device-automatically-using-group-policy\">usually need a GPO to join them to Intune<\/a> and Line of Sight access to the Domain Controller to join to Azure AD. You can actually build and deploy a Package\u00a0 to help with this for computers that don&#8217;t access the Domain but still need to by Hybrid Joined<\/p><p>&nbsp;<\/p><p>reate a provisioning package, using Windows Configuration Designer (which you can download from the Microsoft Store app):<\/p><div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1291 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-3.png\" sizes=\"auto, (max-width: 543px) 100vw, 543px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-3.png 1595w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-3-300x238.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-3-1024x813.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-3-768x610.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-3-1536x1219.png 1536w\" alt=\"\" width=\"543\" height=\"430\" \/><figcaption>Windows Configuration Designer app<\/figcaption><\/figure><\/div><p>Once that\u2019s downloaded, we\u2019ll create a new project:<\/p><div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1292 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4.png\" sizes=\"auto, (max-width: 2056px) 100vw, 2056px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4.png 2056w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4-300x212.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4-1024x724.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4-768x543.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4-1536x1086.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-4-2048x1448.png 2048w\" alt=\"\" width=\"2056\" height=\"1454\" \/><\/figure><\/div><p>The most important step will be going to\u00a0<strong>Account Management<\/strong>, selecting\u00a0<strong>Enroll in Azure AD<\/strong>, and getting a\u00a0<strong>Bulk Token<\/strong>:<\/p><figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1293 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-5-1024x724.png\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-5-1024x724.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-5-300x212.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-5-768x543.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-5-1536x1086.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-5.png 2045w\" alt=\"\" width=\"960\" height=\"678\" \/><figcaption>Bulk Token<\/figcaption><\/figure><p>Once you have a bulk token, select\u00a0<strong>Finish<\/strong>\u00a0and then click\u00a0<strong>Switch to advanced editor<\/strong>\u00a0in the bottom left. We need to switch to the advanced editor to remove any extra settings other than the bulk token.<\/p><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1296 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-8-1024x723.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-8-1024x723.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-8-300x212.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-8-768x542.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-8-1536x1084.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-8-2048x1446.png 2048w\" alt=\"\" width=\"1024\" height=\"723\" \/><figcaption>Select Switch to advanced editor<\/figcaption><\/figure><p>Here I\u2019ll delete the\u00a0<strong>DNSComputerName<\/strong>:<\/p><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1301 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-13-1024x521.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-13-1024x521.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-13-300x153.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-13-768x391.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-13-1536x781.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-13.png 1557w\" alt=\"\" width=\"1024\" height=\"521\" \/><\/figure><p>And then the\u00a0<strong>HideOobe\u00a0<\/strong>setting:<\/p><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1302 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-14-1024x603.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-14-1024x603.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-14-300x177.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-14-768x452.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-14-1536x904.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-14.png 1576w\" alt=\"\" width=\"1024\" height=\"603\" \/><\/figure><p>Once we only see\u00a0<strong>Authority\u00a0<\/strong>and\u00a0<strong>BPRT<\/strong>\u00a0under Azure, we\u2019re ready to\u00a0<strong>export the package:<\/strong><\/p><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1303 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-15-1024x729.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-15-1024x729.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-15-300x214.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-15-768x547.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-15-1536x1094.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-15.png 2044w\" alt=\"\" width=\"1024\" height=\"729\" \/><figcaption>Export package<\/figcaption><\/figure><p>Then we just need to copy the\u00a0<strong>RunTime Provisioning Package\u00a0<\/strong>(.ppkg) file in the exported directory to our device:<\/p><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1298 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-10-1024x582.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-10-1024x582.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-10-300x170.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-10-768x436.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-10-1536x873.png 1536w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-10.png 1575w\" alt=\"\" width=\"1024\" height=\"582\" \/><figcaption>Exported directory for PPKGs<\/figcaption><\/figure><p>Once the PPKG is on the device, double click it to kick off the process:<\/p><div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1299 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-11-1024x766.png\" sizes=\"auto, (max-width: 488px) 100vw, 488px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-11-1024x766.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-11-300x224.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-11-768x574.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-11.png 1245w\" alt=\"\" width=\"488\" height=\"365\" \/><figcaption>PPKG UAC Prompt<\/figcaption><\/figure><\/div><div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1304 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-16-1024x420.png\" sizes=\"auto, (max-width: 772px) 100vw, 772px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-16-1024x420.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-16-300x123.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-16-768x315.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-16.png 1415w\" alt=\"\" width=\"772\" height=\"316\" \/><figcaption>Apply PPKG<\/figcaption><\/figure><\/div><p>Unfortunately PPKGs don\u2019t really report any progress, but you can check under\u00a0<strong>Settings &gt; Accounts &gt; Access work or school &gt; Add or remove a provisioning package<\/strong>\u00a0to see if it applied:<\/p><div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1318 img-responsive\" src=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-26-1024x710.png\" sizes=\"auto, (max-width: 418px) 100vw, 418px\" srcset=\"https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-26-1024x710.png 1024w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-26-300x208.png 300w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-26-768x533.png 768w, https:\/\/deviceadvice.io\/wp-content\/uploads\/2021\/04\/image-26.png 1153w\" alt=\"\" width=\"418\" height=\"289\" \/><\/figure><\/div>","protected":false},"excerpt":{"rendered":"<p>Machines usually need a GPO to join them to Intune and Line of Sight access to the Domain Controller to join to Azure AD. You can actually [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5629","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/5629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=5629"}],"version-history":[{"count":1,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/5629\/revisions"}],"predecessor-version":[{"id":5630,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/5629\/revisions\/5630"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=5629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=5629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=5629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}