Configure Autopilot Hybrid Azure-AD and ADDS Domain Join
Prerequisites
Hybrid Azure AD join requires devices to have access to the following Microsoft resources from inside your organization’s network. These addresses must be accessed using the SYSTEM context. If you are using Auto Pilot this will be accessed during the enrollment status part:
https://enterpriseregistration.windows.net
https://login.microsoftonline.com
https://device.login.microsoftonline.com
https://autologon.microsoftazuread-sso.com
(If you use or plan to use seamless SSO)
To verify if the device is able to access the above Microsoft resources under the system account, you can use Test Device Registration Connectivity script.
Review AD DS UPN support for Hybrid Azure AD join
The table below provides details on support for on-premises AD UPNs in Windows 10 Hybrid Azure AD join
Type of on-premises AD UPN | Domain type | Windows 10 version | Description |
---|---|---|---|
Routable | Federated | From 1703 release | Generally available |
Non-routable | Federated | From 1803 release | Generally available |
Routable | Managed | From 1803 release | Generally available, Azure AD SSPR on Windows lockscreen is not |