Migrating devices from Entra Hybrid join to Entra Join

Naren Joseph 20 Reputation points
2025-02-11T21:35:50.95+00:00

We are in the discovery phase of migrating all our devices from Entra Hybrid join to Entra join enrolment. What are the things we should consider before migrating some devices for a PoC.

Windows Autopilot
Windows Autopilot
A collection of Microsoft technologies used to set up and pre-configure new devices and to reset, repurpose, and recover devices.
502 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,437 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,487 questions
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 16,355 Reputation points Microsoft External Staff
    2025-02-12T02:03:59.32+00:00

    @Naren Joseph,Thanks for posting in Q&A.

    For your issue, here are some things we should consider before migrating some devices for a PoC.

    1. Evaluate Device and OS Requirements

    Supported Platforms: Verify that your devices meet the minimum operating system requirements (e.g., Windows 10/11 with the latest updates) to support Entra join enrollment.

    Hardware Considerations: Ensure that hardware (such as TPM version, network adapters, etc.) is compatible with the new enrollment model.

    1. User Experience and Profile Migration

    Profile Impact: Determine whether migrating devices will require wiping the device or if you can preserve user profiles. In many cases, a device wipe (as in Autopilot scenarios) may be needed, which means planning for backup/restore of user data.

    1. Infrastructure and Management Readiness

    Intune/MDM Configuration: Ensure that your mobile device management (MDM) platform (e.g., Microsoft Intune) is set up to handle Entra join enrollment, including the creation of proper policies, compliance settings, and application deployments.

    Policy Transition: Review how existing Group Policy settings and configurations will translate into cloud-based Intune policies.

    1. Network, Security, and Authentication

    Connectivity: Confirm that devices will have reliable connectivity to Microsoft Entra services and that network configurations (such as DNS and firewall settings) support the new enrollment method.

    SSO and Conditional Access: Revisit your authentication methods and conditional access policies to ensure that users experience seamless single sign-on (SSO) and that security controls remain effective after migration.

    Encryption and Compliance: Verify that security policies (e.g., BitLocker, antivirus settings) are preserved or reconfigured to match the cloud-managed environment.

    1. Migration Methodology and Automation

    Approach Decision: Decide between a “wipe and re-enroll” approach (clean start via Autopilot) versus a migration approach that attempts to preserve existing profiles. Each method has trade-offs in terms of user disruption and support requirements.

    Rollback Plan: Develop a contingency plan to quickly revert devices to their pre-migration state if unexpected issues arise.

    1. Pilot and Feedback

    Limited Scope PoC: Start with a small, diverse group of devices and users (covering different roles and usage scenarios) to capture a broad range of potential issues.

    Monitoring: Set up monitoring to capture enrollment success, performance metrics, and user feedback. Use these insights to adjust the process before a wider rollout.

    Hope above information can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.