azureblog.co.uk
← cd ~/posts

Hybrid join without Entra Connect: hybrid join using Entra Kerberos

A new preview lets Windows devices become Entra hybrid joined during provisioning, without device sync through Entra Connect or AD FS.

2 min read⚠ checked 1 Apr 2026Entra ID · Hybrid identity · Windows · What's new
On this page
  1. Why it's interesting
  2. Why traditional hybrid join is slow
  3. Should you use it?
  4. What to test in a lab

has always depended on plumbing: Entra Connect syncing computer objects and a service connection point, or AD FS in federated tenants. Devices often sat in a pending state until the next sync cycle, which confused users and slowed down rollouts.

Traditional hybrid join

Sync or federation

  • Computer object synced by Entra Connect
  • Service connection point in AD
  • Device pending until the next sync
  • Or AD FS in federated tenants

Entra Kerberos preview

At provisioning time

  • No device sync required
  • No AD FS required
  • Joined during provisioning
  • Device-based Conditional Access works immediately
Two routes to a hybrid joined device.

A new preview lets devices become hybrid joined at provisioning time using Entra , without Entra Connect device sync or AD FS.

Why it's interesting

  • No waiting for sync. The device is hybrid joined when it's provisioned, so device-based works straight away.
  • Less infrastructure. It removes one more dependency on , in line with Microsoft's move to .
  • Fewer pending devices. Hybrid join troubleshooting often comes down to sync timing and SCP configuration. This sidesteps most of it.

Why traditional hybrid join is slow

DeviceActive DirectoryEntra ConnectEntra IDDomain join, reads theservice connectionpoint1Registers itself: device shows as pending2Computer object waitsfor the next sync cycle3Synced object completesthe registration4Next sign-in: device gets its primary refresh token5
The classic hybrid join path, and where devices get stuck as pending.

Every step in that chain is a place for something to go wrong: the computer object outside the sync scope, a missing or wrong SCP, a sync cycle that hasn't run yet. Most hybrid join tickets come down to one of them.

Should you use it?

For new Windows deployments, the first question is still whether you need hybrid join at all. with Intune, and cloud Kerberos trust for access to on-premises resources, covers most needs. Where hybrid join is still required, such as apps or policies that depend on domain membership, this preview is worth testing in a lab now.

Does the device need to be domain joined?
No: users only need on-prem file shares or appsEntra join with Intune, plus cloud Kerberos trust
Yes: GPOs, domain-only apps or legacy toolingHybrid join. Test the Entra Kerberos preview for new builds
Not surePilot Entra join with a small team and see what breaks
Do you need hybrid join at all?
Will this replace my existing hybrid joined devices?

No. It's about how new devices get joined. Existing devices carry on as they are.

Can I use it in production?

It's a preview. Test it in a lab and watch for general availability before relying on it.

What to test in a lab

  • A new device built by your normal provisioning process ends up hybrid joined, not pending
  • Device-based Conditional Access works at the first user sign-in
  • Group Policy, domain-only apps and file shares still behave as expected
  • The device appears correctly in Intune if it's co-managed or enrolled
  • Your existing hybrid joined devices are unaffected

This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.

Next in Shrinking hybrid identity · part 4 of 5BYOD Windows access with Entra registration is now GA →