Hybrid join failures are quiet. Users still sign in to the domain, and nobody notices until a Conditional Access policy that needs a compliant or hybrid joined device starts blocking them. Windows tells you most of what you need in one command. In this post I'll walk through reading dsregcmd /status, then work back through the service connection point, Microsoft Entra Connect and the device itself.
Symptoms#
dsregcmd /statusshowsDomainJoined : YESbutAzureAdJoined : NO.- In Entra ID › Devices › All devices the computer is missing, or its Registered column says Pending.
- Users hit
AADSTS53001orAADSTS53000, get no single sign-on, or never see Windows Hello for Business provisioning.
Why it happens#
In a managed domain, hybrid join is a relay with three legs:
- The device reads the service connection point (SCP) in its forest's configuration partition, or a client-side registry override, to learn the tenant ID and domain.
- Windows writes a hybrid join certificate to the computer object's
userCertificateattribute. Entra Connect only synchronizes Windows computers that carry this certificate and sit in an OU that's in sync scope. The synced object shows up in Entra ID as Pending. - The device completes registration with the device registration service, in SYSTEM context, and the object becomes registered.
Federated domains can also register through the federation service and fall back to this sync join if that fails. A break anywhere (missing or wrong SCP, an out-of-scope OU, a proxy the computer account can't authenticate to, stale objects) leaves the device unjoined or Pending.
How to fix it#
1. Read the device state#
Run the command as the signed-in user, then again from an elevated prompt. The elevated run performs the pre-join diagnostics in SYSTEM context, which is closest to the real join.
dsregcmd /status| Field | Healthy | If not |
|---|---|---|
AzureAdJoined | YES | The join hasn't finished; read Diagnostic Data. |
DomainJoined | YES | Without a domain join, hybrid join isn't possible. |
WorkplaceJoined | NO | A work account was added before the join completed. |
DeviceAuthStatus | SUCCESS | "Device is either disabled or deleted": check the object in Entra ID. |
AzureAdPrt | YES (user context) | Joined, but no SSO token; check the SSO State section. |
2. Find the failed phase and error code#
On a domain-joined device that can't hybrid join, the Diagnostic Data section shows Error Phase (pre-check, discover, auth or join), Client ErrorCode and the server response.
| Code | Meaning | Look at |
|---|---|---|
0x801c001d | SCP couldn't be read | SCP (step 3) |
0x801c003a | Tenant not found: wrong tenant ID in the SCP | SCP keywords |
0x801c0021 / 0x80072ee2 | Discovery failed / network timeout | System-context network and proxy |
0x8007000d | Response couldn't be parsed, often a proxy returning an HTML page | Proxy authentication for the computer account |
0x801c03f2 | DirectoryError: device object not found | Entra Connect sync (step 4) |
0x80090016 | TPM keyset missing: cleared TPM or bad sysprep image | TPM and imaging |
3. Check the service connection point#
From any domain-joined machine, read the SCP keywords. Expect azureADName: followed by a verified domain and azureADId: followed by your tenant ID.
$rootDSE = [ADSI]"LDAP://RootDSE"
$configNC = $rootDSE.Properties["configurationNamingContext"][0]
$scp = [ADSI]"LDAP://CN=62a0ff2e-97b9-4513-943f-0d221bd30080,CN=Device Registration Configuration,CN=Services,$configNC"
$scp.Properties["keywords"]For targeted rollouts, TenantId and TenantName under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CDJ\AAD take precedence over the directory SCP, so check the GPO that sets them. Every forest with domain-joined computers needs its own SCP.
4. Check Entra Connect scope and userCertificate#
Confirm the computer's OU is selected in Entra Connect's domain and OU filtering and that the default device attributes aren't excluded. Then check the certificate:
(Get-ADComputer -Identity "PC-0042" -Properties userCertificate).userCertificate.CountZero means the device hasn't written its certificate yet; it needs line of sight to a domain controller. Once populated and in scope, the object syncs on the next cycle, or run Start-ADSyncSyncCycle -PolicyType Delta on the Entra Connect server. A 0x801c03f2 error before that sync is expected; the next attempt after it succeeds.
5. Read the User Device Registration log#
In Event Viewer, open Applications and Services Logs › Microsoft › Windows › User Device Registration › Admin. Microsoft's guide maps events 304, 305 and 307 to join failures, 201 to discovery errors, 204 to errors returned by the registration service, and 220 to Windows being unable to read the computer object in AD.
6. Retry the join#
The join runs from the Automatic-Device-Join task in Task Scheduler Library › Microsoft › Windows › Workplace Join. After fixing the cause, restart the device or start the task from an elevated prompt:
schtasks /run /tn "\Microsoft\Windows\Workplace Join\Automatic-Device-Join"If a registered device fell back to Pending, typically after its computer object left sync scope and came back, run dsregcmd /leave elevated and restart so it registers again.
Verify the fix#
dsregcmd /statusshows AzureAdJoined and DomainJoined as YES, DeviceAuthStatus as SUCCESS, and AzureAdPrt as YES for the signed-in user.- In Entra ID › Devices › All devices, the join type is Microsoft Entra hybrid joined and Registered shows a date.
- List any remaining Pending devices with Microsoft Graph PowerShell:
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -All -Filter "TrustType eq 'ServerAd'" |
Where-Object { -not $_.AlternativeSecurityIds } |
Select-Object DisplayName, DeviceId, OperatingSystemVersionPrevent it next time#
- Treat computer OUs as part of your sync design: moving a hybrid joined computer out of scope deletes its Entra object, and moving it back creates a Pending one.
- Allow
enterpriseregistration.windows.net,login.microsoftonline.comanddevice.login.microsoftonline.comthrough your proxy in machine context, and keep the registration endpoints out of TLS inspection. - Never capture a sysprep image from a machine that's joined or registered to Entra ID.
- Microsoft's Device Registration Troubleshooter (DSRegTool) script automates most of these checks.