Domain Join to Cloud Only (AADJ) Migration without Wipe and Load!!

Sdílet
Vložit
  • čas přidán 20. 08. 2024
  • All organisations should be striving toward Azure AD Joined devices for the majority of their workforce, removing as many blockers as possible to make that happen.
    One blocker has been the requirement to Wipe & Load devices when moving from Domain Joined to Cloud Only.
    This video showcases an unsupported but awesome tool for making that migration happen WITHOUT a Wipe & Load.
    #SayNoToHAADJ
    Want more? Dean's full Intune for Windows course has you covered. Here's an exclusive CZcams discount: www.udemy.com/...
    Sources:
    andrewstaylor....
    www.modernendp...

Komentáře • 67

  • @parkerjenson3343
    @parkerjenson3343 Před rokem +3

    My company is looking to migrate fully from in on prem to cloud! This video is so helpful, appreciate it!

    • @theCMC
      @theCMC  Před rokem +2

      You're welcome. Watch out for the next few videos to cover the other (more approved and supported!) methods.
      Whilst this is a nice proof of concept, it's really a last resort in my opinion :-)

  • @danpowell7421
    @danpowell7421 Před rokem

    Haha, I also look forward to Andrew's Friday Newsletter!!
    But I didn't notice this! looks like magic. moving from AD joined to Azure AD joined device is a real bore! will certainly be checking this out.

  • @networkn
    @networkn Před měsícem

    Forensit Prowiz was designed exactly moving existing computers to another domain, azure AD or other combinations without a wipe.

  • @alwaysdns625
    @alwaysdns625 Před rokem +1

    Seems a good option, I have done this in the past using the USMT but need to have twice the local profile size in free disk space or a very fast network location.

  • @Uncleruckus-N0Relati0n
    @Uncleruckus-N0Relati0n Před rokem +8

    I'm trying to test this, but his guide on setting up the directory was a little vauge. Can you explain how you set up your folder structure? I got confused because he says Download the PowerShell App Deploy Toolkit and place the contents in the “Toolkit” folder, but there is no toolkit folder in the AADMigration folder, does he mean for us to copy the appdeploy toolkit folder to the AADM folder? And when he says to place the OnedriveLib and bulk token to the files directory, is he meaning AADM\FILES or AADM\Toolkit\files as there is a files folder within the toolkit folder.

    • @FUSION619
      @FUSION619 Před rokem +3

      i was able to get the folder structure all sorted out and it "starts" migration...i just cant seem know why is not azuread joining if i even have the ppkg file going correctly

    • @Uncleruckus-N0Relati0n
      @Uncleruckus-N0Relati0n Před rokem +1

      @@FUSION619 would you mind emailing me screenshots of your deployment folder? I would be really grateful!

    • @Uncleruckus-N0Relati0n
      @Uncleruckus-N0Relati0n Před rokem +1

      @@FUSION619 I have script I can send you that’ll work for the bulk token.

    • @FUSION619
      @FUSION619 Před rokem +2

      @@Uncleruckus-N0Relati0n sorry for the delay, just sent the screenshots over...

    • @FUSION619
      @FUSION619 Před rokem +2

      again, there will need some tweaks if it doesnt work, so if you are able to get it going, share some tips to fix it, im stuck with end points not azuread joining and when they do, users cant login

  • @spitzer666
    @spitzer666 Před rokem +2

    I have seen many of nice hacks using power shell script, but these cant be used in Production but good to know 😊

  • @PhilCrombieMTB
    @PhilCrombieMTB Před 3 měsíci +1

    Heya, I'm looking for a video that helps with steps to move away from hybrid and ad connect to just Cloud. Do you have a video that shows how to get rid of ad connect and just run with Entra after hybrid (for users) has been in place? Thanks for all the content you create!

    • @theCMC
      @theCMC  Před 3 měsíci +1

      Hey Phil - I don’t have that actually, but I can see how it might be a good video to create.

    • @PhilCrombieMTB
      @PhilCrombieMTB Před 3 měsíci +1

      That would be amazing 🤩, most videos are like ..here's how to get ad hybrid and then your stuck there lol 😆 thanks again, legend!!

  • @chadayers3049
    @chadayers3049 Před 9 měsíci +2

    Doesn't Profile Wizard Simplify this?

  • @mikewilliams-rt5di
    @mikewilliams-rt5di Před 8 měsíci +1

    can anyone help me with the folder structure, the instructions seem a bit vague?

  • @Wander-iw6ej
    @Wander-iw6ej Před rokem +1

    I actually do want to do a wipe and load. Can you make a video about deploying modern computers with MDT? Where MDT installs vanilla Windows 11 and Autopilot takes over?

    • @theCMC
      @theCMC  Před rokem +1

      Sure can. I’ll see what I can do!

  • @der_klee
    @der_klee Před rokem +2

    We use ForensiT ProfWiz for these migrations. Can recommend it!

    • @theCMC
      @theCMC  Před rokem +2

      I wonder if I can get a license to do a video of it…!

    • @ThisGuyDakota
      @ThisGuyDakota Před rokem

      Same here. We use ImmyBot deployment. There's a task built-in to run ProfWiz. So we really just pay for the number of licenses and get ImmyBot to push the task to several computers at a time. Works great!

    • @stevenwest992
      @stevenwest992 Před rokem

      Do you have good documentation for this because ForensIT documentation is horrible when trying to follow it. Also how many machines did you do this for? I've been told I have to pay for the corporate license per machine and it will be well over $6,000 for us.

    • @der_klee
      @der_klee Před rokem

      @@stevenwest992 I used the documentation from them. While testing it out I discovered how it worked. I used it for smaller environments of my customers, so I got the professional edition for about 160€.

  • @kevinjackson5191
    @kevinjackson5191 Před rokem +3

    Hi, thanks for this info. However, i've just done my first migration. Never even heard of "Wipe and load".
    This is what i did to my hybrid joined w10 devices:
    1. unjoin device from domain (ensure local admin account access)
    2. reboot into local admin account
    3. rename computer and reboot back into admin account
    4. Join AAD using intune licenced admin account
    5 sign out and back in as AAD user (so that they are not granted admin access).
    This process takes about 15 mins per device. The main caveat i've found is that if the domain-joined account has a profile that takes up a lot of hard disk space, then you will essentially double that when joined AAD as above (OneDrive for business is in operation here).
    Does your method convert or remove the domain only profile?

    • @theCMC
      @theCMC  Před rokem

      Thanks Kevin,
      The only MS Supported method to migrate is Wipe & Load (AKA Rebuild the device).
      The method shown here is experimental, unsupported and for illustration purposes only, to show what is technically possible.
      According to the blog (www.modernendpoint.com/managed/Migrating-AD-Domain-Joined-Computer-to-Azure-AD-Cloud-only-join/#determine-your-delivery-method-and-update-prepare-devicemigrationps) it does not migrate user data and leverages OneDrive for Business, so very likely has a similar result to your own.

    • @kevinjackson5191
      @kevinjackson5191 Před rokem

      @@theCMC Thanks for the reply. That's very interesting. I'm the PM running the migration project with our external IT Provider and i've followed their recommended method. And they are supposed to be a MSP Gold Partner. No wonder i'm doing more work on the project than they are.

    • @wesleyjones6535
      @wesleyjones6535 Před 6 měsíci

      Kevin, I am trying to do it the way you have described only, I am not able to login with the AAD account. I can still access the local account. Any ideas?

    • @kevinjackson5191
      @kevinjackson5191 Před 6 měsíci

      @@wesleyjones6535 Hi, its been a while since i did this now. Are you step 4, in my list? You certainly need to ensure that the AAD account has as intune licence.

    • @wesleyjones6535
      @wesleyjones6535 Před 6 měsíci

      @@kevinjackson5191 yes. I’m piloting this and my test group, all user have E5 licenses. I am a global admin. I see on my test device, it didn’t get the AzureADPRT. I’ve open a case with Microsoft.

  • @beefstu413
    @beefstu413 Před 8 měsíci +1

    You might as well have just created a blog that states the process works for all the help this one is

    • @theCMC
      @theCMC  Před 8 měsíci

      From my experience blog posts aren’t great on CZcams, but thanks for the suggestion!

  • @SweDownhill
    @SweDownhill Před rokem +1

    This looks incredible! One question though.. Onedrive was setup pre migration, but what happened after migration? I assume the intune policy for Onedrive (if created/assigned) would kick in, but I didn't see anything about this in your video..
    Sidenote, I've had issues with signing in silently with OneDrive on AAD joined VMs despite setting up the policy in Intune. Compliant devices are excluded from requiring MFA with Conditional Access but the Onedrive app remains untouched (logged out). If anyone has got an idea what might be wrong, I'd appreciate some guideance 😊 I was thinking that maybe the device being a VM may be the reason behind this behaviour since interactive/remote logon is used via the Hyper-V manager. Haven't had the time to test with AAD joined physical hardware yet, so I don't know if the outcome will be different. (Edit: physical hardware gave the same result, so I'm still head scratching 😉)
    Thanks for great content Dean!

  • @sastreaj
    @sastreaj Před rokem +1

    How would you recommend the final step: turn of sync and turning users into Cloud only ?

    • @theCMC
      @theCMC  Před rokem

      I wouldn’t suggest you move the users over unless you really need to. Hybrid Users aren’t so bad in my opinion.

    • @sastreaj
      @sastreaj Před rokem +2

      @@theCMC
      Thank you but I’m demoting the only AD hardware to have my 28 users in the cloud.

  • @danielgardiner8254
    @danielgardiner8254 Před rokem

    This is really promising however reading the instructions im slightly lost regarding on where the files are required to go for this to work?

  • @vindonhadaway240
    @vindonhadaway240 Před rokem

    Thanks for the video. But what configuration must take place on Azure to facilitate this?

  • @NDSLAB
    @NDSLAB Před 6 měsíci

    Question: What happens if I run this using the system account? Eg:- using the RMM tool? GUI won't display to the user, right?

  • @peterkorsbjerg1557
    @peterkorsbjerg1557 Před rokem +1

    Hi, Thanks for some great content. Is this a better method for migrating from local AD to Azure AD, than using Forensit User Profile Wizard Release 24 ? I have been using Forensit for years, with very few problems.

    • @theCMC
      @theCMC  Před rokem +1

      I have to admit I've not used Forensit UPW, R24. Or any Forensit tool for that matter!
      I will highlight that this approach (like the wipe & load approach) relies on OneDrive Known Folder Move approach, which won't necessarily include all user data.
      I'd be interested to hear your thoughts!

    • @thejesusofbaghdad
      @thejesusofbaghdad Před rokem

      We also used Forensit and it handled re-ACLing of the existing user profile like a champ. Minimal downtime, no new user profile. AAD-joined, in our case also Intune-managed device on the other side with same user profile they were using prior to migration. I highly recommend Forensit as a solution to migrate devices to AAD.

    • @AK-SHIVA84
      @AK-SHIVA84 Před 5 měsíci

      ​@@thejesusofbaghdad
      Hi bro.
      If you have any document regarding this entire process.
      Pre migration steps.
      Migration steps.
      Post migration steps.
      Please share link

  • @imfuctifino
    @imfuctifino Před 3 měsíci

    i'm looking to do this transfer from hybrid to entra ID AD joined , is this still the best way (other than wipe and load) given this video is over a year old ?

  • @bradwilson6102
    @bradwilson6102 Před 8 měsíci

    I'm not sure what's going wrong, but after following the video and the configuration steps from the link, it appears to do the right steps, installs onedrive (if not installed), onreboot it checks for sync and then starts the process, creating the temp account, a couple more restarts for the migration account and then get the migration complete message. In AD the device has been disabled, but it hasn't been added to Azure. And then of course, the AD accounts not longer work on the device.
    Any one had this and what did I miss?

    • @vilkoskoric1082
      @vilkoskoric1082 Před 5 měsíci

      I'm having the same issue. Did you resolve it?

  • @cyphernz
    @cyphernz Před rokem

    For domain join only (not hybrid) who will the primary user be onthe device?

    • @theCMC
      @theCMC  Před rokem

      Sean believes that it will be considered a Shared device. Check out this blog post for more info: www.modernendpoint.com/managed/Dynamically-Update-Primary-Users-on-Intune-Managed-Devices/

  • @saulinvictus51
    @saulinvictus51 Před 7 měsíci

    Hi, trying to test this. Anyone figure out the folder structure perhapss?

  • @peacejon2019
    @peacejon2019 Před rokem +2

    I am not going to tell you how to do dat either 😂😂😂😂😂

    • @theCMC
      @theCMC  Před rokem +2

      I have to admit, it sounded much more mean than I had hoped when I came to editing!

    • @peacejon2019
      @peacejon2019 Před rokem +1

      @@theCMC lol

    • @Uncleruckus-N0Relati0n
      @Uncleruckus-N0Relati0n Před rokem

      Easy, just host the files on an ftp then run this command:
      curl $fileaURL -o $C:\destinationfolder\filename