Hybrid join without Entra Connect: hybrid join using Entra Kerberos
A new preview lets Windows devices become Entra hybrid joined during provisioning, without device sync through Entra Connect or AD FS.
On this page
Hybrid join has always depended on plumbing: Entra Connect syncing computer objects and a service connection point, or AD FS in federated tenants. Devices often sat in a pending state until the next sync cycle, which confused users and slowed down rollouts.
Traditional hybrid join
Sync or federation
- Computer object synced by Entra Connect
- Service connection point in AD
- Device pending until the next sync
- Or AD FS in federated tenants
Entra Kerberos preview
At provisioning time
- No device sync required
- No AD FS required
- Joined during provisioning
- Device-based Conditional Access works immediately
A new preview lets devices become hybrid joined at provisioning time using Entra Kerberos, without Entra Connect device sync or AD FS.
Why it's interesting
- No waiting for sync. The device is hybrid joined when it's provisioned, so device-based Conditional Access works straight away.
- Less infrastructure. It removes one more dependency on Connect Sync, in line with Microsoft's move to Cloud Sync.
- Fewer pending devices. Hybrid join troubleshooting often comes down to sync timing and SCP configuration. This sidesteps most of it.
Why traditional hybrid join is slow
Every step in that chain is a place for something to go wrong: the computer object outside the sync scope, a missing or wrong SCP, a sync cycle that hasn't run yet. Most hybrid join tickets come down to one of them.
Should you use it?
For new Windows deployments, the first question is still whether you need hybrid join at all. Entra join with Intune, and cloud Kerberos trust for access to on-premises resources, covers most needs. Where hybrid join is still required, such as apps or policies that depend on domain membership, this preview is worth testing in a lab now.
Will this replace my existing hybrid joined devices?
No. It's about how new devices get joined. Existing devices carry on as they are.
Can I use it in production?
It's a preview. Test it in a lab and watch for general availability before relying on it.
What to test in a lab
- A new device built by your normal provisioning process ends up hybrid joined, not pending
- Device-based Conditional Access works at the first user sign-in
- Group Policy, domain-only apps and file shares still behave as expected
- The device appears correctly in Intune if it's co-managed or enrolled
- Your existing hybrid joined devices are unaffected
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.
Next in Shrinking hybrid identity · part 4 of 5BYOD Windows access with Entra registration is now GA →