Entra IDTroubleshooting

Dual state, Pending and duplicate device objects in Microsoft Entra ID: a clean-up guide

Why a hybrid joined PC also shows as Entra registered, what Pending really means, and how to clean up duplicates with dsregcmd, BlockAADWorkplaceJoin and Graph PowerShell.

Open Entra ID › Devices › All devices in a tenant that has been around for a few years and you will usually find the same laptop listed twice, hybrid joined objects stuck on Pending, and a long tail of devices nobody has seen since a reimage. These leftovers are not just untidy: they make device-based Conditional Access unpredictable and send your helpdesk chasing the wrong object. In this post I'll explain where each kind of leftover comes from, how to spot it from the device and from the portal, and how to clean up without breaking the devices that are still in use.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (5 steps: Build an inventory; Confirm the state on the device; Remove the registered state; Clear Pending objects; Retire the genuinely stale objects). 4. Verify the fix. 5. Prevent it next time. Toolbox: dsregcmd /status, dsregcmd /leave, Remove-MgDevice, …\Windows\WorkplaceJoin, Devices › All devices.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Build an inventory2Confirm the stateon the device3Remove theregistered state4Clear Pendingobjects5Retire thegenuinely stale ob…TOOLBOXdsregcmd /statusdsregcmd /leaveRemove-MgDevice…\Windows\WorkplaceJoinDevices › All devicesHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (5 steps: Build an inventory; Confirm the state on the device; Remove the registered state; Clear Pending objects; Retire the genuinely stale objects). 4. Verify the fix. 5. Prevent it next time. Toolbox: dsregcmd /status, dsregcmd /leave, Remove-MgDevice, …\Windows\WorkplaceJoin, Devices › All devices.1Symptoms2Why it happens3How to fix it1Build an inventory2Confirm the state on the device3Remove the registered state4Clear Pending objects5Retire the genuinely stale objects4Verify the fix5Prevent it next timeTOOLBOXdsregcmd /statusdsregcmd /leaveRemove-MgDevice…\Windows\WorkplaceJoinDevices › All devices
At a glance: how this guide is organised · 5 fix steps · 5 key tools

Symptoms#

  • One device name appears twice in the devices list: once with join type Microsoft Entra hybrid joined and once as Microsoft Entra registered (the second one usually has a user as owner).
  • Hybrid joined devices show Pending in the Registered column and never get a timestamp.
  • Conditional Access policies that require a compliant or hybrid joined device pass on one day and fail on the next for the same user and PC, or users see You can't get there from here.
  • Intune reports the device as compliant, but the sign-in log shows a different device ID than the one Intune manages.
  • Users on perfectly healthy PCs are told Your organization has deleted the device and are asked to sign in again.
  • On the device, dsregcmd /status shows AzureAdJoined : YES and DomainJoined : YES, and in the User State section also WorkplaceJoined : YES.

Why it happens#

Windows can hold three different relationships with Microsoft Entra ID, and the directory records each of them as a separate device object with its own trustType value:

StatetrustType in Entra IDWhat dsregcmd showsHow it is created
Microsoft Entra joinedAzureADAzureAdJoined : YES, DomainJoined : NOOOBE or Settings, Autopilot
Microsoft Entra hybrid joinedServerADAzureAdJoined : YES, DomainJoined : YESDomain join plus the SCP and the Automatic-Device-Join scheduled task
Microsoft Entra registeredWorkplaceWorkplaceJoined : YES in User State (per user profile)Adding a work account to Windows or an app

Dual state. The registered state is per user and is created the moment someone signs in to an app on a domain-joined PC and answers Yes to the prompt about adding the account to Windows. If you switch on hybrid join afterwards, the same physical device ends up with two identities. Microsoft says hybrid join normally wins during authentication and Conditional Access evaluation, but also that the dual state can make device evaluation nondeterministic and cause access problems, which is exactly the intermittent behaviour above. Since Windows 10 1803 (with KB4489894) Windows removes the registered state for a domain user automatically after the device becomes hybrid joined and that user signs in; it does nothing for local accounts, it cleans up one user at a time, and the Entra object is not deleted immediately when the device is Intune managed.

Pending. The pending state only exists for hybrid join. Microsoft Entra Connect creates the device object first; the device then completes registration against the Device Registration Service and the Registered column gets a date. It stays on Pending when registration never succeeds (connectivity, SCP, federation), or when the object was deleted in Entra ID and re-synced, typically after the computer was moved out of and back into the sync scope. In the second case the device believes it is already registered and never retries.

Duplicates. Microsoft documents three sources: repeated unjoin and rejoin of the same PC, every Windows user who adds a work account creating their own record with the same device name, and a wiped-and-reinstalled device rejoining under its old name. A stale copy keeps its BitLocker keys and its compliance history, which is why a hasty deletion hurts.

How to fix it#

1. Build an inventory#

In Entra ID › Devices › All devices, filter by Join type and Activity, add the Registered column and use Download devices for a CSV; the export carries trustType, registrationDateTime and approximateLastSignInDateTime. For duplicates, Graph PowerShell is quicker:

PowerShell
# Sign in with an account that holds Cloud Device Administrator or Intune Administrator
Connect-MgGraph
Get-MgDevice -All -Property DisplayName,TrustType,ApproximateLastSignInDateTime,AccountEnabled,DeviceId |
    Group-Object DisplayName | Where-Object Count -gt 1 |
    ForEach-Object { $_.Group | Select-Object DisplayName,TrustType,ApproximateLastSignInDateTime,DeviceId }

# Hybrid joined objects still waiting for the client (Pending)
Get-MgDevice -All -Filter "TrustType eq 'ServerAd'" |
    Where-Object { -not $_.AlternativeSecurityIds } |
    Select-Object DisplayName,DeviceId,OperatingSystemVersion

2. Confirm the state on the device#

Run dsregcmd /status as the signed-in user, not from an elevated prompt, otherwise the user-state fields are not reliable. A hybrid joined device with WorkplaceJoined : YES is in dual state. Note the DeviceId under Device Details and compare it with the IDs you exported: the object with that ID is the one Conditional Access should be evaluating.

3. Remove the registered state#

On the PC, go to Settings › Accounts › Access work or school, select the work account that shows as connected and choose Disconnect. This is per user profile, so repeat it for every profile that registered. Do not touch the entry that represents the domain or hybrid join. Then delete the matching Microsoft Entra registered object from the devices list. If that registration also carried an Intune enrollment, retire it in Intune first; Microsoft notes that removing the registered state on 1803 and later unenrols an auto-enrolled device anyway.

4. Clear Pending objects#

From an elevated prompt run dsregcmd /leave, restart, and sign in. The Automatic-Device-Join task under Task Scheduler Library › Microsoft › Windows › Workplace Join re-registers the device and the Pending object becomes the real one. If the diagnostics block of dsregcmd /status reports a failing test instead, fix that first: an AD Configuration Test failure points at the SCP, a DRS Connectivity Test failure at the proxy or firewall.

5. Retire the genuinely stale objects#

Follow Microsoft's disable-then-delete pattern and factor in that the activity timestamp is only refreshed when it is more than 14 days old (plus or minus 5 days), so nothing younger than about 21 days should count as stale. Hybrid joined objects should be disabled or deleted in on-premises AD and allowed to sync; deleting them in Entra ID alone just brings them back as Pending. Retire Intune-managed devices in Intune first, never delete Autopilot (system-managed) devices, and copy any BitLocker keys you may still need.

PowerShell
$cutoff = (Get-Date).AddDays(-120)
Get-MgDevice -All | Where-Object {
    $_.ApproximateLastSignInDateTime -le $cutoff -and $_.TrustType -eq 'Workplace' -and $_.AccountEnabled -eq $false
} | ForEach-Object { Remove-MgDevice -DeviceId $_.Id }

Watch out: Remove-MgDevice does not prompt and deletion is not reversible. Entra device soft delete entered public preview in May 2026 and may give you a recovery window in your tenant, but do not plan on it until you have confirmed it is enabled.

Verify the fix#

  • dsregcmd /status on the device: AzureAdJoined : YES, DomainJoined : YES, WorkplaceJoined : NO, AzureAdPrt : YES and DeviceAuthStatus : SUCCESS.
  • In the devices list the name appears once, with join type Microsoft Entra hybrid joined and a date in Registered.
  • In Entra ID › Monitoring & health › Sign-in logs, open a recent sign-in and check the Device info tab: the device ID matches the surviving object and the join type is what your Conditional Access policy expects.
  • Intune shows the device compliant and Managed by Intune, and the Conditional Access policy result reads Success.

Prevent it next time#

  • Stop domain-joined PCs from getting registered in the first place with the policy registry value HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin, BlockAADWorkplaceJoin = 1 (REG_DWORD). It also blocks users from adding extra work accounts on corporate devices.
  • Keep Windows current so the automatic dual-state clean-up runs, and remember it never touches local accounts.
  • Keep the Entra Connect OU filter stable; every move out of scope deletes the object and every move back creates a Pending one.
  • Use device.trustType in Conditional Access device filters deliberately: ServerAD, AzureAD and Workplace are evaluated against whichever object authenticates, so clean data matters more than clever rules.
  • Schedule the stale-device script as a monthly job with a disable grace period rather than running it once a year.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)