Azure Hybrid Domain Resources and SSO environment

Modified on Thu, 14 Sep, 2023 at 4:45 PM

Understanding hybrid Azure AD join and co-management:

https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/understanding-hybrid-azure-ad-join-and-co-management/ba-p/2221201


Azure AD Connect Sync Architecture Simplified:

https://blog.matrixpost.net/azure-ad-connect-sync-architecture-simplified/

https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/identity/azure-ad


Hybrid identities SCENARIOS and options chart:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-hybrid-identity

Enrollement:

https://docs.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-windows


Prerequisites for Azure AD Connect:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-prerequisites


How to: Plan your hybrid Azure Active Directory join implementation:

https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan


Plan a single sign-on deployment:

https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/plan-sso-deployment


VIDEO step by step login and credentialing process in Windows:

https://techcommunity.microsoft.com/t5/itops-talk-blog/deep-dive-windows-hybrid-join-single-sign-on-to-azure-active/ba-p/2602107


Azure Active Directory (AD, AAD) Tutorial | Identity and Access Management Service:

https://docs.microsoft.com/en-gb/azure/active-directory/hybrid/how-to-connect-pta

https://www.youtube.com/watch?v=Ma7VAQE7ga4


Which authentication method should I use:

https://www.youtube.com/watch?v=YtW2cmVqSEw


https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/identity/azure-ad


SSO (Single Sign On) Quickstart:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start


Windows Autopilot using Intune controlled settings, a background connection flowchart, with Win32 VPN clients including Sonicwall and thirdparty, etc:

https://www.youtube.com/watch?v=WnuBwwfYu4k


What is Microsoft Intune device management:

https://docs.microsoft.com/en-us/mem/intune/remote-actions/device-management


Deploy hybrid Azure AD-joined devices by using INTUNE and Windows Autopilot:

https://docs.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-windows


https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot-hybrid#:~:text=In%20the%20Microsoft%20Endpoint%20Manager%20admin%20center%2C%20select,of%20the%20setup%2C%20select%20Configure.%20Select%20Sign%20In.


https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot-hybrid


AD integration with MDM:

https://docs.microsoft.com/en-us/windows/client-management/mdm/azure-active-directory-integration-with-mdm


Configure certificate auto-enrollment:

https://docs.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment


Enroll a Windows 10 device automatically using group policy:

https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy


Troubleshooting Join errors and codes:

https://docs.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-hybrid-join-windows-current

https://docs.microsoft.com/en-us/azure/active-directory/devices/faq


Pending join states:

https://www.youtube.com/watch?v=QBR1c81kaxA&t=2s


DSREGCMD /STATUS command statuses defined:

https://docs.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-device-dsregcmd#:~:text=User%20state%201%20NgcSet%3A%20Set%20to%20"YES"%20if,DestructiveAndNonDestructive%2C%20or%20Unknown%20if%20error.%20More%20items...%20


Pending States - Register and unregister device in Hybrid AD:

https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/pending-devices

https://www.youtube.com/watch?v=QBR1c81kaxA&t=2s


Hybrid Azure AD joined Windows Hello for Business Certificate Trust Provisioning:

https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-provision


Windows Easy to understand Hello signin:

https://www.youtube.com/watch?v=G-GJuDWbBE8&t=6s


Windows Hello for business:

https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-videos#windows-hello-for-business-user-enrollment-experience


Windows Hello for business FAQ:

https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-faq


WINDOWS HELLO for business Troubleshooting:

https://www.brookspeppin.com/2021/09/24/troubleshooting-windows-hello-for-business/

For troubleshooting tool install:

https://howardsimpson.blogspot.com/2021/01/warning-unable-to-resolve-package-source-https-www-powershellgallery-com-api-v2.html

https://www.netspi.com/blog/technical/network-penetration-testing/15-ways-to-bypass-the-powershell-execution-policy/


Using FIDO2 hardware key passwordless:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-security-key-on-premises


Backing up AD:

https://theitbros.com/backup-active-directory/


Using ADSIEdit:

https://theitbros.com/adsi-edit/


Azure AD Connect Sync: Attributes synchronized to Azure Active Directory:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-sync-attributes-synchronized


Refreshing Schema and MSDS-KeyCredentialsLink attribute:

https://techcommunity.microsoft.com/t5/azure-active-directory-identity/azure-ad-mailbag-windows-hello-for-business/ba-p/445349


https://social.technet.microsoft.com/Forums/en-US/754b99a8-d158-43b6-b756-25c9b6fe40ea/windows-hello-msdskeycredentiallink-problems-with-synchronizaton-this-option-is-temporarily#:~:text=Hi%2C%20You%20can%20open%20up%20Azure%20AD%20Connect,on%20the%20relevant%20msDS-Device%20in%20the%20RegisteredDevices%20folder.


https://social.technet.microsoft.com/Forums/en-US/754b99a8-d158-43b6-b756-25c9b6fe40ea/windows-hello-msdskeycredentiallink-problems-with-synchronizaton-this-option-is-temporarily


Hacking that helps with Windows Hello Key Trust flow understanding:

https://www.dsinternals.com/wp-content/uploads/eu-19-Grafnetter-Exploiting-Windows-Hello-for-Business.pdf


Configuring the CDP and AIA Extensions on CA Server:

https://docs.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-the-cdp-and-aia-extensions-on-ca1


Azure AD Connect: Automatic upgrade:

https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/how-to-connect-install-automatic-upgrade



NDES for Intune:

https://www.jeffgilb.com/ndes-for-intune/

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article