{"id":4144,"date":"2018-01-12T14:03:42","date_gmt":"2018-01-12T14:03:42","guid":{"rendered":"http:\/\/www.tsls.co.uk\/?p=4144"},"modified":"2024-04-22T08:57:07","modified_gmt":"2024-04-22T08:57:07","slug":"azure-ad-ds-hybrid-azure-ad-intune-mdm-qa","status":"publish","type":"post","link":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/","title":{"rendered":"Azure AD DS Hybrid with Azure AD and Intune MDM Q&#038;A"},"content":{"rendered":"<p>Q1: Why can\u2019t I \u201cfactory reset\u201d my Windows 10 device even though it\u2019s listed in Intune under \u201cAzure AD Devices\u201d, however the device is not listed in All Devices<br \/>\nA1: Azure AD Join devices don\u2019t allow you to factory reset. Your device needs to be enrolled with Intune MDM before the device can be \u201cfactor reset\u201d. To enable Intune MDM run though the following<br \/>\n1.\tEnable Intune MDM integration with Azure AD: https:\/\/docs.microsoft.com\/en-us\/intune\/windows-enroll<br \/>\n2.\tLicense user for EMS (AD Premium and Intune required): https:\/\/docs.microsoft.com\/en-us\/intune\/licenses-assign<br \/>\n3.\tDevice Enrolment:  https:\/\/docs.microsoft.com\/en-us\/intune-user-help\/enroll-your-w10-phone-or-w10-pc-windows<br \/>\n4.\tTo force intune MDM enrolment you can install the company portal app from the Microsoft Store: https:\/\/www.microsoft.com\/en-gb\/store\/p\/company-portal\/9wzdncrfj3pz<br \/>\nNB: if joining windows AD DS and Azure AD see Q3:<\/p>\n<p>Q2: Can I factory reset a Windows 10 device which is Windows AD DS Joined, Azure AD Joined and Intune MDM Managed<br \/>\nA2: Yes, to configure please see Q3<\/p>\n<p>Q3: can I automatically enrol a windows 10 windows AD DS joined device into MDM and Azure AD<br \/>\nA3; Yes, however you need to be using build 1709 or above, for more information please see : https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/device-management-hybrid-azuread-joined-devices-setup and<br \/>\nhttps:\/\/docs.microsoft.com\/en-us\/windows\/client-management\/mdm\/enroll-a-windows-10-device-automatically-using-group-policy <\/p>\n<p>Q4: Is it possible to add the BitLocker Protector key to AzureAD? even if you enabled BitLocker before the device was Azure AD Join?<br \/>\nA4: Yes, the following PowerShell will need to be executed:<\/p>\n<p>Add-BitLockerKeyProtector -MountPoint &#8220;C:&#8221; -RecoveryPasswordProtector<br \/>\n$BLV = Get-BitLockerVolume -MountPoint &#8220;C:&#8221;<br \/>\nBackupToAAD-BitLockerKeyProtector -MountPoint &#8220;C:&#8221; -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId<\/p>\n<p>Further information:<\/p>\n<p>Intune make sure the DNS CNAMEs are created: https:\/\/docs.microsoft.com\/en-us\/intune\/windows-enroll#simplify-windows-enrollment-without-azure-ad-premium<br \/>\nIntune Factory reset\\Remove company data descriptions: https:\/\/docs.microsoft.com\/en-us\/intune\/devices-wipe<br \/>\nIntune Non-windows updates: https:\/\/docs.microsoft.com\/en-us\/intune\/whats-new<br \/>\nIntune device compliance policies: https:\/\/docs.microsoft.com\/en-us\/intune\/device-compliance-get-started<br \/>\nBitLocker Management: https:\/\/docs.microsoft.com\/en-us\/windows\/device-security\/bitlocker\/bitlocker-management-for-enterprises <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Q1: Why can\u2019t I \u201cfactory reset\u201d my Windows 10 device even though it\u2019s listed in Intune under \u201cAzure AD Devices\u201d, however the device is not listed in All Devices A1: Azure AD Join devices don\u2019t<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_newsletter_tier_id":0,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[21],"tags":[2491,2694,1011,2714,2704],"class_list":["post-4144","post","type-post","status-publish","format-standard","hentry","category-microsoft","tag-ad-ds","tag-azure-ad","tag-intune","tag-mdm","tag-sccm"],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.9.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\r\n<title>Azure AD DS Hybrid with Azure AD and Intune MDM Q&amp;A - TSLS - Luke Smith<\/title>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_GB\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"Azure AD DS Hybrid with Azure AD and Intune MDM Q&amp;A - TSLS - Luke Smith\" \/>\r\n<meta property=\"og:description\" content=\"Q1: Why can\u2019t I \u201cfactory reset\u201d my Windows 10 device even though it\u2019s listed in Intune under \u201cAzure AD Devices\u201d, however the device is not listed in All Devices A1: Azure AD Join devices don\u2019t\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/\" \/>\r\n<meta property=\"og:site_name\" content=\"TSLS - Luke Smith\" \/>\r\n<meta property=\"article:published_time\" content=\"2018-01-12T14:03:42+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2024-04-22T08:57:07+00:00\" \/>\r\n<meta name=\"author\" content=\"Luke Smith\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Luke Smith\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/\",\"url\":\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/\",\"name\":\"Azure AD DS Hybrid with Azure AD and Intune MDM Q&A - TSLS - Luke Smith\",\"isPartOf\":{\"@id\":\"https:\/\/www.tsls.co.uk\/#website\"},\"datePublished\":\"2018-01-12T14:03:42+00:00\",\"dateModified\":\"2024-04-22T08:57:07+00:00\",\"author\":{\"@id\":\"https:\/\/www.tsls.co.uk\/#\/schema\/person\/e4d7dac4fe1b3f8df31f3857bb3ebda7\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.tsls.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Azure AD DS Hybrid with Azure AD and Intune MDM Q&#038;A\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.tsls.co.uk\/#website\",\"url\":\"https:\/\/www.tsls.co.uk\/\",\"name\":\"TSLS - Luke Smith\",\"description\":\"- Knowledge - Thoughts - Microsoft -\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.tsls.co.uk\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.tsls.co.uk\/#\/schema\/person\/e4d7dac4fe1b3f8df31f3857bb3ebda7\",\"name\":\"Luke Smith\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.tsls.co.uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/29abc50f07a4ebe68cb4f31981884f89b2157d7e4ed63b09631d40c0717faa94?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/29abc50f07a4ebe68cb4f31981884f89b2157d7e4ed63b09631d40c0717faa94?s=96&d=mm&r=g\",\"caption\":\"Luke Smith\"},\"description\":\"I\u2019ve been working with Microsoft Technologies for over 20 years, my main focus now being Microsoft Online Services. I manage the Cloud Services at ElysianIT Limited and as a P-SELLER at Microsoft. I have worked with many organisations from SMC to Enterprise. I\u2019ve been working with Microsoft Technologies since DOS 5.0, to date I have been working on Microsoft\u2019s latest cloud technology Windows Azure, Windows 10 Office 365 and Microsoft SharePoint\",\"sameAs\":[\"http:\/\/www.tsls.co.uk\"],\"url\":\"https:\/\/www.tsls.co.uk\/index.php\/author\/luke\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Azure AD DS Hybrid with Azure AD and Intune MDM Q&A - TSLS - Luke Smith","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/","og_locale":"en_GB","og_type":"article","og_title":"Azure AD DS Hybrid with Azure AD and Intune MDM Q&A - TSLS - Luke Smith","og_description":"Q1: Why can\u2019t I \u201cfactory reset\u201d my Windows 10 device even though it\u2019s listed in Intune under \u201cAzure AD Devices\u201d, however the device is not listed in All Devices A1: Azure AD Join devices don\u2019t","og_url":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/","og_site_name":"TSLS - Luke Smith","article_published_time":"2018-01-12T14:03:42+00:00","article_modified_time":"2024-04-22T08:57:07+00:00","author":"Luke Smith","twitter_misc":{"Written by":"Luke Smith","Estimated reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/","url":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/","name":"Azure AD DS Hybrid with Azure AD and Intune MDM Q&A - TSLS - Luke Smith","isPartOf":{"@id":"https:\/\/www.tsls.co.uk\/#website"},"datePublished":"2018-01-12T14:03:42+00:00","dateModified":"2024-04-22T08:57:07+00:00","author":{"@id":"https:\/\/www.tsls.co.uk\/#\/schema\/person\/e4d7dac4fe1b3f8df31f3857bb3ebda7"},"breadcrumb":{"@id":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.tsls.co.uk\/index.php\/2018\/01\/12\/azure-ad-ds-hybrid-azure-ad-intune-mdm-qa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.tsls.co.uk\/"},{"@type":"ListItem","position":2,"name":"Azure AD DS Hybrid with Azure AD and Intune MDM Q&#038;A"}]},{"@type":"WebSite","@id":"https:\/\/www.tsls.co.uk\/#website","url":"https:\/\/www.tsls.co.uk\/","name":"TSLS - Luke Smith","description":"- Knowledge - Thoughts - Microsoft -","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.tsls.co.uk\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.tsls.co.uk\/#\/schema\/person\/e4d7dac4fe1b3f8df31f3857bb3ebda7","name":"Luke Smith","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.tsls.co.uk\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/29abc50f07a4ebe68cb4f31981884f89b2157d7e4ed63b09631d40c0717faa94?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/29abc50f07a4ebe68cb4f31981884f89b2157d7e4ed63b09631d40c0717faa94?s=96&d=mm&r=g","caption":"Luke Smith"},"description":"I\u2019ve been working with Microsoft Technologies for over 20 years, my main focus now being Microsoft Online Services. I manage the Cloud Services at ElysianIT Limited and as a P-SELLER at Microsoft. I have worked with many organisations from SMC to Enterprise. I\u2019ve been working with Microsoft Technologies since DOS 5.0, to date I have been working on Microsoft\u2019s latest cloud technology Windows Azure, Windows 10 Office 365 and Microsoft SharePoint","sameAs":["http:\/\/www.tsls.co.uk"],"url":"https:\/\/www.tsls.co.uk\/index.php\/author\/luke\/"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p2gf1k-14Q","_links":{"self":[{"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/4144","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=4144"}],"version-history":[{"count":1,"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/4144\/revisions"}],"predecessor-version":[{"id":4154,"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/4144\/revisions\/4154"}],"wp:attachment":[{"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=4144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/categories?post=4144"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tsls.co.uk\/index.php\/wp-json\/wp\/v2\/tags?post=4144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}