Removing on-prem ad and start using office365/intune

%3CLINGO-SUB%20id%3D%22lingo-sub-302974%22%20slang%3D%22en-US%22%3ERemoving%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-302974%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20using%20exchange%20online%20and%20on-prem%20azure%20with%20dir%20sync%20to%20office365.%3CBR%20%2F%3Ewe%20would%20like%20to%20remove%20the%20DC%20and%20join%20all%20computers%20to%20intune%20and%20move%20the%20users%20to%20azure%20ad%20in%20cloud.%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20is%20the%20best%20way%20to%20do%20it%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-302974%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EProPlus%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303054%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303054%22%20slang%3D%22en-US%22%3EYou%20could%20automate%20that%20but%20the%20only%20part%20that%20need%20to%20be%20Done%20manually%20is%20to%20disconnect%20them%20from%20domain%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303050%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303050%22%20slang%3D%22en-US%22%3EIf%20the%20machines%20are%20domain%20joined%20then%20they%20still%20will%20be%20with%20intune%20management%20after%20that.%20I%20don%E2%80%99t%20know%20of%20a%20way%20to%20automate%20joining%20devices%20strictly%20to%20azure%20ad%20or%20I%E2%80%99d%20be%20doing%20it%20now%20%3B).%20The%20goal%20is%20cloud%20only%20and%20there%20is%20no%20easy%20way%20to%20convert%20a%20domain%20joined%20machine%20to%20azure%20joined%20outside%20of%20leaving%20and%20joining.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303049%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303049%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Guys%2C%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThanks%20all%20for%20the%20tips!%3CBR%20%2F%3EHow%20about%20-%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Auto%20enroll%20to%20to%20intune%20through%20GPO%3CBR%20%2F%3E2.%20stop%20the%20sync%3C%2FP%3E%3CP%3E3.%20disconnect%20them%20from%20on-prem%20domain%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303006%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303006%22%20slang%3D%22en-US%22%3EYup!%20The%20other%20way%20around!!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303005%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303005%22%20slang%3D%22en-US%22%3EFor%20sure!%20It%E2%80%99s%20a%20good%20way%20to%20do%20it%20too.%20I%20would%20do%20it%20exactly%20the%20same%20way!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-303001%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-303001%22%20slang%3D%22en-US%22%3EYeah%20agree%2C%20it's%20a%20huge%20ordeal%20to%20cover%20all%20the%20in's%20and%20out's%20and%20unless%20you%20know%20everything%20it%20can%20be%20overwhelming%2C%20but%20I%20just%20laid%20out%20the%20technical%20high%20level%20plan.%20Of%20course%2C%20all%20the%20on-prem%20%2F%20licensing%20stuff%20needs%20figured%20out%20in%20addition%20too%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-302997%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-302997%22%20slang%3D%22en-US%22%3EFasttrack%20should%20help%20because%20if%20they%20qualify%20Microsoft%20will%20pay%20for%20the%20migration%20and%20do%20a%20discovery%20to%20determine%20if%20it%E2%80%99ll%20be%20cloud%20led%20or%20hybrid%20led.%20If%20they%20have%20local%20apps%20or%20file%20servers%20which%20authenticate%20to%20AD%20and%20they%20can%E2%80%99t%20be%20moved%20to%20the%20cloud%20in%20a%20reasonable%20time%20then%20it%20may%20need%20to%20be%20hybrid%20Azure%20AD%20join%20until%20they%20are%20moved%20or%20switched%20out%20for%20other%20apps.%20I%20used%20to%20use%20AADP1%20to%20get%20round%20this%20before%20Hybrid%20Azure%20AD%20Join%20was%20introduced%20because%20there%20were%20reasons%20they%20couldn%E2%80%99t%20go%20all%20in%20with%20Windows%20AD%20join%20immediately.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20will%20look%20into%20ProfWiz%20though.%20Sounds%20good.%20Been%20using%20Laplink%20or%20USMT%20so%20far.%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-302985%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-302985%22%20slang%3D%22en-US%22%3EFast%20Track%20can%20help%20some%2C%20but%20the%20primary%20steps%20are%20to%20get%20intune%20working%20with%20auto%20enrollment%20first.%20This%20way%20when%20you%20azure%20ad%20join%20your%20machines%20they%20are%20managed%20from%20the%20get%20go.%20Depending%20on%20how%20many%20GPO's%20you%20had%20in%20your%20onprem%20deployment%2C%20you'll%20want%20to%20get%20all%20that%20setup%20ahead%20of%20time%20as%20well.%20You%20can%20setup%20test%20intune%20groups%20and%20assign%20so%20only%20those%20groups%20get%20intune%20when%20joined.%3CBR%20%2F%3E%3CBR%20%2F%3EOnce%20your%20intune%20is%20setup%2C%20you%20can%20use%20a%20tool%20such%20as%20profwiz%20to%20disjoined%20from%20the%20domain.%20Then%20you%20have%20to%20login%20local%2C%20joined%20to%20azure%20ad%2C%20then%20use%20profwiz%20to%20assign%20the%20azure%20AD%20user%20to%20your%20old%20domain%20profile.%20Then%20you%20can%20login%20with%20minimal%20disruption%20to%20the%20user%20and%20it'll%20be%20joined%20to%20azuread.%20With%20intune%20and%20auto%20enrollment%20in%20place%2C%20all%20the%20policies%20will%20apply%20on%20first%20login.%3CBR%20%2F%3E%3CBR%20%2F%3EHere%20is%20article%20I've%20been%20using%20to%20get%20going%20on%20intune%20deployment%20it%20has%20everything%20you%20need%2C%20it%20wasn't%20too%20hard%20but%20will%20take%20a%20few%20days%20to%20figure%20out%20and%20get%20things%20working%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EOnce%20intune%20is%20configured%20and%20you%20get%20your%20devices%20all%20joined%20and%20managed%20to%20azure%20ad%2C%20the%20last%20step%20really%20is%20removing%20your%20azure%20ad%20connect%20so%20you're%20users%20can%20go%20cloud%20only%20so%20you%20can%20disable%20that%20sync%20in%20the%20cloud%3A%20%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2619062%2Fyou-can-t-manage-or-remove-objects-that-were-synchronized-through-the%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2619062%2Fyou-can-t-manage-or-remove-objects-that-were-synchronized-through-the%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-302983%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-302983%22%20slang%3D%22en-US%22%3EChris%20had%20some%20good%20tips!!%3CBR%20%2F%3E%3CBR%20%2F%3EBasically%20the%20steps%20themselves%20are%3A%3CBR%20%2F%3EStopping%20the%20sync%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fturn-off-directory-synchronization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fturn-off-directory-synchronization%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EUninstall%20the%20adconnect%20software%20on%20the%20server!%3CBR%20%2F%3EAfter%20this%20the%20users%20should%20be%20cloud%20only%20users!%3CBR%20%2F%3E%3CBR%20%2F%3EEnroll%20devices!%3CBR%20%2F%3EOf%20course%20there%20are%20some%20prerequisites%20and%20licenses%20%2F%20OS%20requirements%20(%20read%20Chris%20post)%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fquickstart-enroll-windows-device%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fquickstart-enroll-windows-device%3C%2FA%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-302981%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-302981%22%20slang%3D%22en-US%22%3EHave%20a%20look%20at%20this%20...%3CBR%20%2F%3E%3CA%20href%3D%22http%3A%2F%2Fwww.scconfigmgr.com%2F2018%2F11%2F07%2Fhybrid-azure-ad-join-windows-autopilot-devices-using-microsoft-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fwww.scconfigmgr.com%2F2018%2F11%2F07%2Fhybrid-azure-ad-join-windows-autopilot-devices-using-microsoft-intune%2F%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-302977%22%20slang%3D%22en-US%22%3ERe%3A%20Removing%20on-prem%20ad%20and%20start%20using%20office365%2Fintune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-302977%22%20slang%3D%22en-US%22%3EMicrosoft%20365%20which%20includes%20Office%20365%2C%20Windows%2010%20and%20Intune%2FEMS%20depending%20on%20the%20SKU%20you%20select.%20It%20was%20designed%20for%20businesses%20looking%20to%20go%20100%25%20cloud%20and%20take%20out%20the%20local%20AD.%3CBR%20%2F%3E%3CBR%20%2F%3EMicrosoft%20FastTrack%20should%20be%20able%20to%20help%20you%20should%20your%20Organisation%20be%20over%20150%20users%20and%20you%20are%20migrating%20to%20Microsoft%20365.%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Hello,

 

We are using exchange online and on-prem azure with dir sync to office365.
we would like to remove the DC and join all computers to intune and move the users to azure ad in cloud.

What is the best way to do it?

11 Replies
Microsoft 365 which includes Office 365, Windows 10 and Intune/EMS depending on the SKU you select. It was designed for businesses looking to go 100% cloud and take out the local AD.

Microsoft FastTrack should be able to help you should your Organisation be over 150 users and you are migrating to Microsoft 365.

Best, Chris
Chris had some good tips!!

Basically the steps themselves are:
Stopping the sync:
https://docs.microsoft.com/en-us/office365/enterprise/turn-off-directory-synchronization

Uninstall the adconnect software on the server!
After this the users should be cloud only users!

Enroll devices!
Of course there are some prerequisites and licenses / OS requirements ( read Chris post)

https://docs.microsoft.com/en-us/intune/quickstart-enroll-windows-device
Fast Track can help some, but the primary steps are to get intune working with auto enrollment first. This way when you azure ad join your machines they are managed from the get go. Depending on how many GPO's you had in your onprem deployment, you'll want to get all that setup ahead of time as well. You can setup test intune groups and assign so only those groups get intune when joined.

Once your intune is setup, you can use a tool such as profwiz to disjoined from the domain. Then you have to login local, joined to azure ad, then use profwiz to assign the azure AD user to your old domain profile. Then you can login with minimal disruption to the user and it'll be joined to azuread. With intune and auto enrollment in place, all the policies will apply on first login.

Here is article I've been using to get going on intune deployment it has everything you need, it wasn't too hard but will take a few days to figure out and get things working: https://docs.microsoft.com/en-us/intune/

Once intune is configured and you get your devices all joined and managed to azure ad, the last step really is removing your azure ad connect so you're users can go cloud only so you can disable that sync in the cloud: https://support.microsoft.com/en-us/help/2619062/you-can-t-manage-or-remove-objects-that-were-synchr...



Fasttrack should help because if they qualify Microsoft will pay for the migration and do a discovery to determine if it’ll be cloud led or hybrid led. If they have local apps or file servers which authenticate to AD and they can’t be moved to the cloud in a reasonable time then it may need to be hybrid Azure AD join until they are moved or switched out for other apps. I used to use AADP1 to get round this before Hybrid Azure AD Join was introduced because there were reasons they couldn’t go all in with Windows AD join immediately.

I will look into ProfWiz though. Sounds good. Been using Laplink or USMT so far.

Best, Chris
Yeah agree, it's a huge ordeal to cover all the in's and out's and unless you know everything it can be overwhelming, but I just laid out the technical high level plan. Of course, all the on-prem / licensing stuff needs figured out in addition too :)
For sure! It’s a good way to do it too. I would do it exactly the same way!
Yup! The other way around!!

Hello Guys,


Thanks all for the tips!
How about - 

1. Auto enroll to to intune through GPO
2. stop the sync

3. disconnect them from on-prem domain

If the machines are domain joined then they still will be with intune management after that. I don’t know of a way to automate joining devices strictly to azure ad or I’d be doing it now ;). The goal is cloud only and there is no easy way to convert a domain joined machine to azure joined outside of leaving and joining.
You could automate that but the only part that need to be Done manually is to disconnect them from domain
We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE