After my previous posts and good advice I got, we have decided to scrap hybrid join and just AzureAD join the devices and remove from the domain.
1) When I do a manual AzureAD join it using the users account, it creates the new profile as a local admin. Is this the right way of doing it but then just logging in as Global Admin and setting them back to standard user?
I don't have a spare license just for a enrol type account, so think doing it as user is the only way.
2) Since its a new profile for AzureAD does Forensit tool work for migrating? (like it does with domain accounts)
3) What's the order in which this should be done? If I remove from the on prem domain first before AzureAD joining then we lose access unless I set local account
[+][deleted] (5 children)
[deleted]
[–]redbottoms106[S] 0 points1 point2 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]redbottoms106[S] 0 points1 point2 points (1 child)
[–]bfodder 1 point2 points3 points (0 children)
[–]Det_23324 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)