Score:0

Looking for experienced advice for switching from Azure AD Registered Devices to Hybrid in Azure AD Connect

br flag

I'm looking for hints, tips, and information on what the end-user may noticed during the change from Azure Active Directory Registered devices to Hybrid Azure AD Joined devices.

My organization currently uses Azure AD Connect to sync our local AD to Office 365. We don't use much in Azure, but I need to start using Endpoint Manager for BitLocker and other management policies. To do this, I need to change our sync settings to enable Hybrid (devices are currently Azure AD Registered).

Since I can't stage or test this change, I'm looking for those that have gone through it, and any information they can share with me.

Thank you.

Score:0
gg flag

You'll start by simply enabling more data being synced from your on-premises Active Directory to Azure AD. That won't affect user experience in any way. Just set aside time to enroll a few test or pilot machines with Endpoint Manager and give them a few weeks of normal use. Try to bake in some test plans during that pilot period. Find out what happens during events such as:

  • You need to decrypt a drive
  • You need to re-encrypt a drive
  • A user needs self-service help with their BitLocker PIN/password
  • Online unlock vs offline unlock
  • Pushing management policies to the devices
  • Changing and removing management policies from devices
  • How you handle a lost/stolen device (wipe, etc)
  • And more

Endpoint Manager documentation probably lays out more things to plan for and test during a deployment. This would also be a good time to review your current authentication configuration. (ie: Are you using password hash sync, federation and SSO, password write-back, etc?)

In the end, the impact of switching from a "registered devices" (BYOD) approach hinges on any changes that will add more security restrictions to what might be a personal device. Users will notice changes that require them to have a stronger PIN, policies that prevent them from uploading data to cloud storage, or policies that disable certain features on their phone. Thankfully, these are things that you can test in detail by creating a test group of devices to preview these policies before applying them to everyone.

br flag
Thanks for the reply. I was thinking more in terms of the immediate effect of changing to Hybrid (outside of any policy). Are the end-users going to notice anything or any potential issues. Most clients are Win 10 and fully updated.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.