oeltayeb.com · Entra ID Toolkit

Checklist

Hybrid join troubleshooting checklist

Based on the article: Troubleshooting Microsoft Entra hybrid join with dsregcmd /status · 4 min read

Hybrid join failures are quiet. Users still sign in to the domain, and nobody notices until a Conditional Access policy that needs a compliant or hybrid joined device starts blocking them. Windows tells you most of what you need in one command. In this post I'll walk through reading dsregcmd /status, then work back through the service connection point, Microsoft Entra Connect and the device itself.

Symptoms to confirm

  • dsregcmd /status shows DomainJoined : YES but AzureAdJoined : NO.
  • In Entra ID › Devices › All devices the computer is missing, or its Registered column says Pending.
  • Users hit AADSTS53001 or AADSTS53000, get no single sign-on, or never see Windows Hello for Business provisioning.

Likely causes

In a managed domain, hybrid join is a relay with three legs:

  • The device reads the service connection point (SCP) in its forest's configuration partition, or a client-side registry override, to learn the tenant ID and domain.
  • Windows writes a hybrid join certificate to the computer object's userCertificate attribute. Entra Connect only synchronizes Windows computers that carry this certificate and sit in an OU that's in sync scope. The synced object shows up in Entra ID as Pending.
  • The device completes registration with the device registration service, in SYSTEM context, and the object becomes registered.

Checklist

  1. 1

    Read the device state

    Run the command as the signed-in user, then again from an elevated prompt. The elevated run performs the pre-join diagnostics in SYSTEM context, which is closest to the real join.

    cmd
    dsregcmd /status
    FieldHealthyIf not
    AzureAdJoinedYESThe join hasn't finished; read Diagnostic Data.
    DomainJoinedYESWithout a domain join, hybrid join isn't possible.
    WorkplaceJoinedNOA work account was added before the join completed.
    DeviceAuthStatusSUCCESS"Device is either disabled or deleted": check the object in Entra ID.
    AzureAdPrtYES (user context)Joined, but no SSO token; check the SSO State section.
  2. 2

    Find the failed phase and error code

    On a domain-joined device that can't hybrid join, the Diagnostic Data section shows Error Phase (pre-check, discover, auth or join), Client ErrorCode and the server response.

    CodeMeaningLook at
    0x801c001dSCP couldn't be readSCP (step 3)
    0x801c003aTenant not found: wrong tenant ID in the SCPSCP keywords
    0x801c0021 / 0x80072ee2Discovery failed / network timeoutSystem-context network and proxy
    0x8007000dResponse couldn't be parsed, often a proxy returning an HTML pageProxy authentication for the computer account
    0x801c03f2DirectoryError: device object not foundEntra Connect sync (step 4)
    0x80090016TPM keyset missing: cleared TPM or bad sysprep imageTPM and imaging
  3. 3

    Check the service connection point

    From any domain-joined machine, read the SCP keywords. Expect azureADName: followed by a verified domain and azureADId: followed by your tenant ID.

    powershell
    $rootDSE  = [ADSI]"LDAP://RootDSE"
    $configNC = $rootDSE.Properties["configurationNamingContext"][0]
    $scp = [ADSI]"LDAP://CN=62a0ff2e-97b9-4513-943f-0d221bd30080,CN=Device Registration Configuration,CN=Services,$configNC"
    $scp.Properties["keywords"]
  4. 4

    Check Entra Connect scope and userCertificate

    Confirm the computer's OU is selected in Entra Connect's domain and OU filtering and that the default device attributes aren't excluded. Then check the certificate:

    powershell
    (Get-ADComputer -Identity "PC-0042" -Properties userCertificate).userCertificate.Count
  5. 5

    Read the User Device Registration log

    In Event Viewer, open Applications and Services Logs › Microsoft › Windows › User Device Registration › Admin. Microsoft's guide maps events 304, 305 and 307 to join failures, 201 to discovery errors, 204 to errors returned by the registration service, and 220 to Windows being unable to read the computer object in AD.

  6. 6

    Retry the join

    The join runs from the Automatic-Device-Join task in Task Scheduler Library › Microsoft › Windows › Workplace Join. After fixing the cause, restart the device or start the task from an elevated prompt:

    cmd
    schtasks /run /tn "\Microsoft\Windows\Workplace Join\Automatic-Device-Join"

Verify

  • dsregcmd /status shows AzureAdJoined and DomainJoined as YES, DeviceAuthStatus as SUCCESS, and AzureAdPrt as YES for the signed-in user.
  • In Entra ID › Devices › All devices, the join type is Microsoft Entra hybrid joined and Registered shows a date.
  • List any remaining Pending devices with Microsoft Graph PowerShell:
powershell
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -All -Filter "TrustType eq 'ServerAd'" |
    Where-Object { -not $_.AlternativeSecurityIds } |
    Select-Object DisplayName, DeviceId, OperatingSystemVersion

Prevent it next time

  • Treat computer OUs as part of your sync design: moving a hybrid joined computer out of scope deletes its Entra object, and moving it back creates a Pending one.
  • Allow enterpriseregistration.windows.net, login.microsoftonline.com and device.login.microsoftonline.com through your proxy in machine context, and keep the registration endpoints out of TLS inspection.
  • Never capture a sysprep image from a machine that's joined or registered to Entra ID.
  • Microsoft's Device Registration Troubleshooter (DSRegTool) script automates most of these checks.

Microsoft Learn references