A cloud-based identity and access management service for securing user authentication and resource access
Hello Chris,
Adding to Saravana´s Comment, in a Microsoft Entra Domain Services-only environment, hybrid join isn´t possible at all.
Answering your Questions:
- Missing SCP, expected?
- Yes. The SCP is only used for Microsoft Entra hybrid Join, and Hybrid Join requier the computer object to be synced from a On-Premises AD to Entra / azure via the Entra Connect. Microsoft says that installing the Entra Connect in a managed domain to sync back isn´t supported. So the SCP is absend by design here.
- Create it Manually?
- No, the device still couldn´t Hybrid Join, because the Computer Object never reaches Entra so the error would just come in a later phase again.
- Related to the CA failure?
- No. windows attempts the hybrid join automatically on every domain joined machine, so the error "0x801c001d" is a expected noise and can be ignored in your setup. The 53000 comes only from Require compliant device - a registered device only gets device-based Conditional Acccess when its enrolled in Intune the "AAD joined: Yes" from Windows Hello events are most likely reflects per-user work account registrations every user who adds a work account on the server creates their own registered deivce oject with the same name and multiplies the devices like this.
What i would do in your scenario is to treat the host a never-compliant and protect is differently what i mean by that:
- Use the "Compliant OR MFA" pattern for the RDS Sessions: its a Microsoft Conditinal Access Template Require compliant or hybrid joined device or MFA for all users lets the RDS host pass with MFA while managed clients pass with compliance. Scope your strict "Requiere compliant device" policy so it doesn´t cover the RDS user/sessions (what i mean: by group, or by named location for the hosts outbound IP if its a fixed IP) keep in mind test the Policy first in Report only and with the "What if" tool.
- Optionall: Block registration on the Server so users can´t create new registered device onjects via "Add work or School account" the Registry Key can be found here:
Existing registrations are per user profile and need to be discnnected under Settings - Accounts - Access work or schoolHKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin --> BlockAADWorkplaceJoin with the Value 1 (DWORD) - if device compliance is a hard requirement, the Micrsofot supported way is a Azure Virtual Desktop or Windows 365 with Entra Joined, intune managed hosts
- Optionall: Block registration on the Server so users can´t create new registered device onjects via "Add work or School account" the Registry Key can be found here:
Important: please check what your interim fix is currently using if it is using a Device filter it won´t apply to a unregistered device, so if you block and remove the registrations, the 53000 loop comes back - so Please set up the new scoping before you unregister the host.
References for you to read it:
- Domain Services synchronization (one-way)
- Domain Services scenarios (Entra Connect in managed domain not supported)
- Hybrid join troubleshooting (0x801c001d)
- Microsoft Entra registered devices
- CA template: compliant or hybrid joined or MFA
- Device FAQ (BlockAADWorkplaceJoin, duplicate entries per user)
- Filter for devices (unregistered device behavior)
Best regards Alex