Automatic enrollment of Hybrid Azure AD joined devices using Group Policy Object
You can configure to automatically mass-enroll a large number of Hybrid Azure AD joined corporate devices into BigFix MCM without any user intervention or Admin user credentials. The enrollment into MDM is triggered by a group policy created on the local Active Directory.
What is Hybrid Azure AD join
Hybrid Azure AD joined device means that it is visible in both your on-premises AD and in Azure AD. After adding the devices to Domain Controller (On-premises AD), when you integrate On-premises AD with Azure AD, the devices become Hybrid Azure AD joined devices. Azure AD joined devices automatically get enrolled to BigFix MCM, when Azure AD is configured. This way, you can apply group policies to multiple devices and enroll to BigFix MCM with non-admin user credentials. For more information, see https://docs.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-join-hybrid
How to configure
- Integrate On-premises AD with Azure AD.Note: You can integrate through the Azure AD Connect, after which all the objects are synchronized to Azure AD from on-premises AD.
- Define group policies in the domain controller.
- Assign a group policy to Hybrid AD joined devices.
Once the Hybrid AD joined device is assigned to a group policy, the device automatically gets enrolled to BigFix MCM service.
Requirements
- Domain controller or On-premises AD with users and devices configured
- Azure AD with BigFix MCM application configured
- Administrator privileges on both on-premises and Azure AD
Procedure
- Download Azure AD Connect,
open Azure AD Connect, and click Configure.
- Select Customize synchronization options and click
Next.
- Enter Azure AD Global Administrator credentials and click
Next. The credentials are verified and connected
to Azure AD.
- After the Azure AD is connected, enter Enterprise Admin credentials to
connect to on-premises AD. When the Connect your directories screen appears,
enter connection information of the on-premises directories and click
Add Directory.
- After the directory is listed under CONFIGURED DIRECTORIES, click Next.
- On the next screen, select Sync all domains and OUs
options and click Next.
- In the next screen, ensure the required optional features are selected and
click Next.
- On the next screen, click Configure.
Once the synchronization is completed, all the users, devices in the on-premises AD appears in Azure AD as well.
- Users synchronizedOn-premises ADAzure AD
- Devices Synchronized and become Hybrid AD joined devicesOn-premises ADAzure AD
- From Group Policy Management screen, under
Domains, select your domain, click
Group Policy Objects, right click, and from
the context menu select New.
- In the NEW GPO pop-up, enter the group policy
name and click OK. The created policy is listed
under Group Policy Objects.
- To enable non-admin user to enroll to BigFix MCM, select the
created group policy, click Settings.
Under , do the following:
- Enable the setting “Enable automatic MDM enrollment using default Azure AD credentials”
- For Select Credential Type to Use, select User
Credential
Now, the group policy is created and defined to enable non-admin user to enroll.
Next step: Associate the defined policy to devices
- To enable non-admin user to enroll to BigFix MCM, select the
created group policy, click Settings.
Under , do the following:
- Assign the group to the organization
- Under Group Policy Management, select
Domains, select (the organization), right
click, and select Link an Existing GPO.
- In the Select GPO pop-up, select the desired
Group Policy object and click
OK.
- Under Group Policy Management, select
Domains, select (the organization), right
click, and select Link an Existing GPO.
- Assign the device to Organization
- To move the Computers to the organization, From Azure Directory Users and Computers, navigate to Computers.
- Select the device, right click, and click
Move.
- From the Move pop-up, select the organization and click
OK.
Now, the computer is moved to the selected organization. Now, this device is eligible for automatic enrollment.
Enrollment process


To begin the enrollment process, do the following steps:
- Open the Windows device that is associated with the MDM server. Connect to the Internet. Enter the password as set in Azure AD. Update the password.
- The End User License Agreement page appears. Select the license agreement check
box after reading and click Accept. The autopilot
enrollment process begins.After the enrollment is completed, go toto verify MDM server details.Click Info to verify the policy and application details.