You enabled hybrid Azure AD join in Azure AD Connect. On several Windows 10 domain-joined devices, dsregcmd /status shows DomainJoined = YES and AzureAdJoined = NO. The output also indicates "SCP not found." You need these devices to automatically complete hybrid Azure AD join. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Run the Azure AD Connect wizard and use Configure device options to create the Service Connection Point in on-premises AD..
Why this is the answer
The correct solution is to run the Azure AD Connect wizard and use "Configure device options" to create the Service Connection Point (SCP) in on-premises AD. The "SCP not found" message clearly indicates that the SCP, which is essential for devices to discover the Azure AD tenant information and initiate hybrid Azure AD join, is missing. Re-running the wizard and configuring this option will create the SCP object in Active Directory, allowing devices to automatically register. Enabling Device writeback is for writing device objects from Azure AD back to on-premises AD, not for initial registration. Running dsregcmd /join manually registers the device, but the goal is automatic completion. Creating a GPO for automatic MDM enrollment is for Intune enrollment, not hybrid Azure AD join. Adding Azure AD sign-in endpoints to the Local intranet zone is typically for seamless SSO, not for resolving SCP issues for hybrid join.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed