Checklist
Hybrid join troubleshooting checklist
Based on the article: Troubleshooting Microsoft Entra hybrid join with dsregcmd /status · 4 min read
Hybrid join failures are quiet. Users still sign in to the domain, and nobody notices until a Conditional Access policy that needs a compliant or hybrid joined device starts blocking them. Windows tells you most of what you need in one command. In this post I'll walk through reading dsregcmd /status, then work back through the service connection point, Microsoft Entra Connect and the device itself.
Symptoms to confirm
dsregcmd /statusshowsDomainJoined : YESbutAzureAdJoined : NO.- In Entra ID › Devices › All devices the computer is missing, or its Registered column says Pending.
- Users hit
AADSTS53001orAADSTS53000, get no single sign-on, or never see Windows Hello for Business provisioning.
Likely causes
In a managed domain, hybrid join is a relay with three legs:
- The device reads the service connection point (SCP) in its forest's configuration partition, or a client-side registry override, to learn the tenant ID and domain.
- Windows writes a hybrid join certificate to the computer object's
userCertificateattribute. Entra Connect only synchronizes Windows computers that carry this certificate and sit in an OU that's in sync scope. The synced object shows up in Entra ID as Pending. - The device completes registration with the device registration service, in SYSTEM context, and the object becomes registered.
Checklist
- 1
Read the device state
Run the command as the signed-in user, then again from an elevated prompt. The elevated run performs the pre-join diagnostics in SYSTEM context, which is closest to the real join.
cmddsregcmd /statusField Healthy If not AzureAdJoinedYES The join hasn't finished; read Diagnostic Data. DomainJoinedYES Without a domain join, hybrid join isn't possible. WorkplaceJoinedNO A work account was added before the join completed. DeviceAuthStatusSUCCESS "Device is either disabled or deleted": check the object in Entra ID. AzureAdPrtYES (user context) Joined, but no SSO token; check the SSO State section. - 2
Find the failed phase and error code
On a domain-joined device that can't hybrid join, the Diagnostic Data section shows
Error Phase(pre-check, discover, auth or join),Client ErrorCodeand the server response.Code Meaning Look at 0x801c001dSCP couldn't be read SCP (step 3) 0x801c003aTenant not found: wrong tenant ID in the SCP SCP keywords 0x801c0021/0x80072ee2Discovery failed / network timeout System-context network and proxy 0x8007000dResponse couldn't be parsed, often a proxy returning an HTML page Proxy authentication for the computer account 0x801c03f2DirectoryError: device object not found Entra Connect sync (step 4) 0x80090016TPM keyset missing: cleared TPM or bad sysprep image TPM and imaging - 3
Check the service connection point
From any domain-joined machine, read the SCP keywords. Expect
azureADName:followed by a verified domain andazureADId:followed by your tenant ID.powershell$rootDSE = [ADSI]"LDAP://RootDSE" $configNC = $rootDSE.Properties["configurationNamingContext"][0] $scp = [ADSI]"LDAP://CN=62a0ff2e-97b9-4513-943f-0d221bd30080,CN=Device Registration Configuration,CN=Services,$configNC" $scp.Properties["keywords"] - 4
Check Entra Connect scope and userCertificate
Confirm the computer's OU is selected in Entra Connect's domain and OU filtering and that the default device attributes aren't excluded. Then check the certificate:
powershell(Get-ADComputer -Identity "PC-0042" -Properties userCertificate).userCertificate.Count - 5
Read the User Device Registration log
In Event Viewer, open Applications and Services Logs › Microsoft › Windows › User Device Registration › Admin. Microsoft's guide maps events 304, 305 and 307 to join failures, 201 to discovery errors, 204 to errors returned by the registration service, and 220 to Windows being unable to read the computer object in AD.
- 6
Retry the join
The join runs from the Automatic-Device-Join task in Task Scheduler Library › Microsoft › Windows › Workplace Join. After fixing the cause, restart the device or start the task from an elevated prompt:
cmdschtasks /run /tn "\Microsoft\Windows\Workplace Join\Automatic-Device-Join"
Verify
dsregcmd /statusshows AzureAdJoined and DomainJoined as YES, DeviceAuthStatus as SUCCESS, and AzureAdPrt as YES for the signed-in user.- In Entra ID › Devices › All devices, the join type is Microsoft Entra hybrid joined and Registered shows a date.
- List any remaining Pending devices with Microsoft Graph PowerShell:
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -All -Filter "TrustType eq 'ServerAd'" |
Where-Object { -not $_.AlternativeSecurityIds } |
Select-Object DisplayName, DeviceId, OperatingSystemVersionPrevent it next time
- Treat computer OUs as part of your sync design: moving a hybrid joined computer out of scope deletes its Entra object, and moving it back creates a Pending one.
- Allow
enterpriseregistration.windows.net,login.microsoftonline.comanddevice.login.microsoftonline.comthrough your proxy in machine context, and keep the registration endpoints out of TLS inspection. - Never capture a sysprep image from a machine that's joined or registered to Entra ID.
- Microsoft's Device Registration Troubleshooter (DSRegTool) script automates most of these checks.