Entra IDTroubleshooting

Troubleshooting Microsoft Entra hybrid join with dsregcmd /status

Read dsregcmd /status for hybrid join failures, check the SCP and Entra Connect sync, use the User Device Registration log and clear devices stuck in Pending.

Hybrid join failures are quiet. Users still sign in to the domain, and nobody notices until a Conditional Access policy that needs a compliant or hybrid joined device starts blocking them. Windows tells you most of what you need in one command. In this post I'll walk through reading dsregcmd /status, then work back through the service connection point, Microsoft Entra Connect and the device itself.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (6 steps: Read the device state; Find the failed phase and error code; Check the service connection point; Check Entra Connect scope and userCertificate; Read the User Device Registration log; Retry the join). 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x801C03F2, 0x801C001D, 0x801C003A, dsregcmd /status, dsregcmd /leave.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Read thedevice state2Find the failedphase and err…3Check theservice conne…4Check EntraConnect scop…5Read the UserDevice Regist…6Retry the joinTOOLBOX0x801C03F20x801C001D0x801C003Adsregcmd /statusdsregcmd /leaveHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (6 steps: Read the device state; Find the failed phase and error code; Check the service connection point; Check Entra Connect scope and userCertificate; Read the User Device Registration log; Retry the join). 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x801C03F2, 0x801C001D, 0x801C003A, dsregcmd /status, dsregcmd /leave.1Symptoms2Why it happens3How to fix it1Read the device state2Find the failed phase and error code3Check the service connection point4Check Entra Connect scope and userCertificate5Read the User Device Registration log6Retry the join4Verify the fix5Prevent it next timeTOOLBOX0x801C03F20x801C001D0x801C003Adsregcmd /statusdsregcmd /leave
At a glance: how this guide is organised · 6 fix steps · 5 key tools

Symptoms#

  • dsregcmd /status shows DomainJoined : YES but AzureAdJoined : NO.
  • In Entra ID › Devices › All devices the computer is missing, or its Registered column says Pending.
  • Users hit AADSTS53001 or AADSTS53000, get no single sign-on, or never see Windows Hello for Business provisioning.

Why it happens#

In a managed domain, hybrid join is a relay with three legs:

  1. The device reads the service connection point (SCP) in its forest's configuration partition, or a client-side registry override, to learn the tenant ID and domain.
  2. Windows writes a hybrid join certificate to the computer object's userCertificate attribute. Entra Connect only synchronizes Windows computers that carry this certificate and sit in an OU that's in sync scope. The synced object shows up in Entra ID as Pending.
  3. The device completes registration with the device registration service, in SYSTEM context, and the object becomes registered.

Federated domains can also register through the federation service and fall back to this sync join if that fails. A break anywhere (missing or wrong SCP, an out-of-scope OU, a proxy the computer account can't authenticate to, stale objects) leaves the device unjoined or Pending.

How to fix it#

1. Read the device state#

Run the command as the signed-in user, then again from an elevated prompt. The elevated run performs the pre-join diagnostics in SYSTEM context, which is closest to the real join.

Command Prompt
dsregcmd /status
FieldHealthyIf not
AzureAdJoinedYESThe join hasn't finished; read Diagnostic Data.
DomainJoinedYESWithout a domain join, hybrid join isn't possible.
WorkplaceJoinedNOA work account was added before the join completed.
DeviceAuthStatusSUCCESS"Device is either disabled or deleted": check the object in Entra ID.
AzureAdPrtYES (user context)Joined, but no SSO token; check the SSO State section.

2. Find the failed phase and error code#

On a domain-joined device that can't hybrid join, the Diagnostic Data section shows Error Phase (pre-check, discover, auth or join), Client ErrorCode and the server response.

CodeMeaningLook at
0x801c001dSCP couldn't be readSCP (step 3)
0x801c003aTenant not found: wrong tenant ID in the SCPSCP keywords
0x801c0021 / 0x80072ee2Discovery failed / network timeoutSystem-context network and proxy
0x8007000dResponse couldn't be parsed, often a proxy returning an HTML pageProxy authentication for the computer account
0x801c03f2DirectoryError: device object not foundEntra Connect sync (step 4)
0x80090016TPM keyset missing: cleared TPM or bad sysprep imageTPM and imaging

3. Check the service connection point#

From any domain-joined machine, read the SCP keywords. Expect azureADName: followed by a verified domain and azureADId: followed by your tenant ID.

PowerShell
$rootDSE  = [ADSI]"LDAP://RootDSE"
$configNC = $rootDSE.Properties["configurationNamingContext"][0]
$scp = [ADSI]"LDAP://CN=62a0ff2e-97b9-4513-943f-0d221bd30080,CN=Device Registration Configuration,CN=Services,$configNC"
$scp.Properties["keywords"]

For targeted rollouts, TenantId and TenantName under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CDJ\AAD take precedence over the directory SCP, so check the GPO that sets them. Every forest with domain-joined computers needs its own SCP.

4. Check Entra Connect scope and userCertificate#

Confirm the computer's OU is selected in Entra Connect's domain and OU filtering and that the default device attributes aren't excluded. Then check the certificate:

PowerShell
(Get-ADComputer -Identity "PC-0042" -Properties userCertificate).userCertificate.Count

Zero means the device hasn't written its certificate yet; it needs line of sight to a domain controller. Once populated and in scope, the object syncs on the next cycle, or run Start-ADSyncSyncCycle -PolicyType Delta on the Entra Connect server. A 0x801c03f2 error before that sync is expected; the next attempt after it succeeds.

5. Read the User Device Registration log#

In Event Viewer, open Applications and Services Logs › Microsoft › Windows › User Device Registration › Admin. Microsoft's guide maps events 304, 305 and 307 to join failures, 201 to discovery errors, 204 to errors returned by the registration service, and 220 to Windows being unable to read the computer object in AD.

6. Retry the join#

The join runs from the Automatic-Device-Join task in Task Scheduler Library › Microsoft › Windows › Workplace Join. After fixing the cause, restart the device or start the task from an elevated prompt:

Command Prompt
schtasks /run /tn "\Microsoft\Windows\Workplace Join\Automatic-Device-Join"

If a registered device fell back to Pending, typically after its computer object left sync scope and came back, run dsregcmd /leave elevated and restart so it registers again.

Verify the fix#

  • dsregcmd /status shows AzureAdJoined and DomainJoined as YES, DeviceAuthStatus as SUCCESS, and AzureAdPrt as YES for the signed-in user.
  • In Entra ID › Devices › All devices, the join type is Microsoft Entra hybrid joined and Registered shows a date.
  • List any remaining Pending devices with Microsoft Graph PowerShell:
PowerShell
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -All -Filter "TrustType eq 'ServerAd'" |
    Where-Object { -not $_.AlternativeSecurityIds } |
    Select-Object DisplayName, DeviceId, OperatingSystemVersion

Prevent it next time#

  • Treat computer OUs as part of your sync design: moving a hybrid joined computer out of scope deletes its Entra object, and moving it back creates a Pending one.
  • Allow enterpriseregistration.windows.net, login.microsoftonline.com and device.login.microsoftonline.com through your proxy in machine context, and keep the registration endpoints out of TLS inspection.
  • Never capture a sysprep image from a machine that's joined or registered to Entra ID.
  • Microsoft's Device Registration Troubleshooter (DSRegTool) script automates most of these checks.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)