Essential Steps for Seamless Microsoft Entra Hybrid Device Management: Unenroll from MDM First

Posted by

When unjoining and rejoining Microsoft Entra hybrid devices, it’s crucial to first unenroll from mobile device management (MDM). Failing to do so can lead to misalignment of device properties, removal of policies, and potential access issues to corporate resources. To ensure a seamless experience, always follow the best practice of unenrolling before rejoining.2. **:**

Important Support Tip for Microsoft Entra Hybrid Devices

In the ever-evolving landscape of cloud technology, managing hybrid devices efficiently is crucial. Recently, a significant support tip emerged regarding Microsoft Entra hybrid devices. This advice can enhance device management and user experience.

What’s New?

Microsoft has identified a critical issue affecting hybrid devices during the unjoin and rejoin process. Specifically, this problem arises when devices are not unenrolled from mobile device management (MDM) before being rejoined. This oversight can lead to misalignment of essential device properties.

“Failing to properly manage the unjoin-rejoin process can result in device targeting issues where policies and configurations don’t apply correctly.”

Major Updates and Impacts

When hybrid devices are rejoined without prior unenrollment from MDM, Microsoft Entra generates a new device object. This new object comes with a new object ID while retaining the original device ID. Consequently, this can create significant management challenges.

  • Policy Removal: Policies assigned to static groups will be removed, disrupting device functionality.
  • Dynamic Group Delays: Policies from dynamic groups may take up to two weeks to reapply, causing potential downtime.
  • Conditional Access Issues: Newly created device objects are treated as non-compliant, blocking access to corporate resources.
“Newly created Microsoft Entra device objects are treated as non-compliant by default, meaning users may be blocked from accessing corporate resources.”

Best Practices to Follow

To mitigate these issues, it is advisable to avoid the unjoin and rejoin process altogether. However, if it is necessary, ensure that you unenroll hybrid devices from MDM before proceeding. This practice preserves the integrity of device policies, applications, and settings.

By following this guidance, IT administrators can maintain a smoother re-enrollment process. Ultimately, this will lead to a more stable and reliable user experience.

Conclusion

In conclusion, managing Microsoft Entra hybrid devices requires careful attention to detail. Always remember to unenroll from MDM before unjoining and rejoining devices. This simple step can save time and prevent complications down the road.

  • Windows Autopilot with Microsoft Entra hybrid join connects devices to the cloud from on-premises Active Directory.
  • Unenrolling from MDM before rejoining prevents critical device properties from becoming misaligned.
  • Improper management during the unjoin-rejoin process can disrupt Windows Autopilot configurations.
  • New device objects created during rejoining are treated as non-compliant, potentially blocking access to resources.
  • Best practice recommends avoiding unjoining and rejoining hybrid devices to maintain policy integrity.
  • From the Intune Customer Success articles



    Related Posts
    Unlock New Possibilities with Windows Server Devices in Intune!

      Windows Server Devices Now Recognized as a New OS in Intune Microsoft has announced that Windows Server devices are Read more

    Unlock the Power of the Platform: Your Guide to Power Platform at Microsoft Ignite 2022

    Microsoft Power Platform is leading the way in AI-generated low-code app development. With the help of AI, users can quickly Read more

    Unlock the Power of Microsoft Intune with the 2210 October Edition!

    Microsoft Intune is an enterprise mobility management platform that helps organizations manage mobile devices, applications, and data. The October edition Read more

    Unlock the Power of Intune 2.211: What’s New for November!

    Microsoft Intune has released its November edition, featuring new updates to help IT admins better manage their organization’s mobile devices. Read more