<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Entra-Id-Connect-(Aad-Connect) on Ru Campbell MVP</title>
    <link>https://campbell.scot/tags/entra-id-connect-aad-connect/</link>
    <description>Recent content in Entra-Id-Connect-(Aad-Connect) on Ru Campbell MVP</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Mon, 19 Apr 2021 20:02:44 +0000</lastBuildDate>
    <atom:link href="https://campbell.scot/tags/entra-id-connect-aad-connect/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Troubleshooting Hybrid Azure AD Intune Automatic Enrollment</title>
      <link>https://campbell.scot/troubleshooting-hybrid-azure-ad-intune-automatic-enrollment/</link>
      <pubDate>Mon, 19 Apr 2021 20:02:44 +0000</pubDate>
      <guid>https://campbell.scot/troubleshooting-hybrid-azure-ad-intune-automatic-enrollment/</guid>
      <description>&lt;p&gt;As I have blogged about &lt;a href=&#34;https://campbell.scot/hybrid-azure-ad-join-intune-enrollment-prerequisites-checklist-and-process-flow/&#34;&gt;a&lt;/a&gt;&lt;a href=&#34;https://petri.com/how-to-automatically-hybrid-azure-ad-join-and-intune-enroll-pcs&#34;&gt;lot&lt;/a&gt;, there are a bunch of hoops to be jumped through and prerequisites to be met for a successful hybrid Azure AD join and automatic, GPO-invoked Intune enrollment. But sometimes, you have to go back to the basics when you&amp;rsquo;re banging your head off the table, and laugh off the embarrassment of not checking the fundamentals.&lt;/p&gt;
&lt;p&gt;I was recently setting up hybrid Azure AD join and Intune enrollment, as I&amp;rsquo;ve done hundreds of times before, but this time I was hitting a strange problem.  Hybrid Azure AD join went fine, but for the Intune MDM enrollment, I was getting nowhere.  Devices showed in the Azure AD admin centre, but never showed an MDM, and therefore never showed in Endpoint Manager.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Understanding Modern vs. Legacy Authentication in Microsoft 365</title>
      <link>https://campbell.scot/understanding-modern-vs-legacy-authentication-in-microsoft-365/</link>
      <pubDate>Sun, 24 Jan 2021 13:46:35 +0000</pubDate>
      <guid>https://campbell.scot/understanding-modern-vs-legacy-authentication-in-microsoft-365/</guid>
      <description>&lt;p&gt;Since October 2019, Microsoft has enabled Security Defaults by default in new Microsoft 365 tenants.  Security Defaults are a group of best-practice security settings, and one of note is the disablement of all &lt;strong&gt;legacy authentication&lt;/strong&gt;, which itself has been off in Exchange Online and SharePoint Online, by default, since August 2017.&lt;/p&gt;
&lt;p&gt;The term legacy authentication doesn&amp;rsquo;t refer to one particular protocol, but rather any that do not support Multi-Factor Authentication (MFA).  Protocols that support MFA are described as &lt;strong&gt;modern authentication&lt;/strong&gt;.  In the context of Microsoft 365 and Azure Active Directory, which handles Microsoft 365&amp;rsquo;s authentication, these are protocols such as ADAL and OAuth.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hybrid Azure AD Join &#43; Intune Enrollment - Prerequisites Checklist and Process Flow</title>
      <link>https://campbell.scot/hybrid-azure-ad-join-intune-enrollment-prerequisites-checklist-and-process-flow/</link>
      <pubDate>Mon, 25 May 2020 17:22:04 +0000</pubDate>
      <guid>https://campbell.scot/hybrid-azure-ad-join-intune-enrollment-prerequisites-checklist-and-process-flow/</guid>
      <description>&lt;p&gt;I&amp;rsquo;m a simple person, and sometimes it just helps to have a checklist to refer to when you&amp;rsquo;re troubleshooting rather than navigating the sparse pages of docs.microsoft.com.  In this blog, I  explain the prerequisites for the Hybrid Azure AD Join (HAADJ) + automatic (GPO controlled) Intune MDM enrollment scenario and the process from start to end, as simply and concisely as I can (not easy!)  There are no screenshots and it&amp;rsquo;s not a click-by-click: this is a quick reference for when you&amp;rsquo;re pulling your hair out wondering what could be stopping you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Register Domain-Joined Computers as Devices - The Redundant and Broken Hybrid Azure AD Join GPO</title>
      <link>https://campbell.scot/register-domain-joined-computers-as-devices-the-redundant-and-broken-hybrid-azure-ad-join-gpo/</link>
      <pubDate>Tue, 19 May 2020 19:11:46 +0000</pubDate>
      <guid>https://campbell.scot/register-domain-joined-computers-as-devices-the-redundant-and-broken-hybrid-azure-ad-join-gpo/</guid>
      <description>&lt;p&gt;The group policy object &lt;strong&gt;Register domain-joined computers as devices&lt;/strong&gt;, or &lt;strong&gt;Automatically workplace join client computers&lt;/strong&gt; in older templates, was previously a requirement for enabling Hybrid Azure AD Join.  After configuring Azure AD Connect and your Seamless SSO GPOs, this had to be enabled.&lt;/p&gt;
&lt;p&gt;Since Windows 10 1607 (&amp;ldquo;Anniversary Update&amp;rdquo;), in Azure AD Connect environments, on-premises Active Directory joined computers become Azure Active Directory registered when a synchronised user signs in to a synchronised computer; regardless of the GPO existing.  Prior to this, on Windows 10 1511 (&amp;ldquo;November Update&amp;rdquo;) and before, only if this GPO, or other configuration to create this registry value, was used.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
