O365 Admin

How to Configure Hybrid Entra ID Join

Published 27 October 2025 · 8 min read

Hybrid Entra ID join allows Windows devices to be joined to both on-premises Active Directory and Entra ID simultaneously. The device receives Group Policy from AD and MDM policies from Intune. This is the standard approach for organisations migrating gradually from on-premises to cloud.

What hybrid join is

A hybrid Entra ID joined device appears in both AD (as a computer account, receives GPO) and Entra ID (as a device in your tenant, receives Intune policies). Different from pure Entra ID join (cloud-only) and pure domain join (on-prem only).

💡
When to use hybrid vs Entra ID join
Use hybrid join when you have existing domain-joined devices and on-premises dependencies. Use pure Entra ID join for new devices in cloud-first organisations.

Prerequisites

Configure hybrid join

Entra Connect → Configure → Configure device options → Configure Hybrid Azure AD join
  1. Select Configure Hybrid Azure AD join
  2. Select your AD forest
  3. Choose Windows 10 or later domain-joined devices
  4. Select your Azure AD domain
  5. Complete the wizard

Verify devices are joined

# On the device
dsregcmd /status

# Look for:
# AzureAdJoined : YES
# DomainJoined  : YES
# Both YES = hybrid join successful
Entra ID → Devices → All devices → filter Join Type = Hybrid Entra ID joined

Frequently Asked Questions

Q: Can I enrol hybrid joined devices in Intune?

Yes. Configure automatic MDM enrolment in Entra ID under Mobility (MDM and MAM) > Microsoft Intune.

Q: Can hybrid joined devices use Windows Hello for Business?

Yes. WHfB works on hybrid joined devices.

Q: What is the difference between hybrid join and co-management?

Hybrid join is the device registration state. Co-management means both SCCM and Intune managing the device simultaneously.

Related Guides
-> Entra ID vs Active Directory-> Intune vs Group Policy-> Enrol Entra ID Devices
// need intune set up properly?
Fixed-price Intune setup for UK businesses

App deployment, compliance policies, Conditional Access, and full documentation at a fixed price.

View Packages