Entra ID hybrid join was generally enabled for Windows 10 devices and Windows Server 2016 or better in the NETID domain on June 25, 2020, via a change to settings in our Entra ID Connect. A computer in the NETID AD can end up in a hybrid joined state one of two ways:
A device is said to be hybrid joined if it has both an AD object and an Entra ID object, which allow users of that device to sign in with an AD user account, which provides access to resources which are protected by either the AD or the Entra ID user. A hybrid joined computer is joined to both AD and Entra ID, but the AD join is primary because the device initially uses AD authentication. Only Windows devices can be hybrid joined. Please reference our cloud-based device management glossary for terms you are unfamiliar with. Microsoft supplies a detailed process diagram for hybrid join which may help you understand how it works.
Only Windows 10 or Windows Server 2016 or later devices can hybrid join, due to the UW's Entra ID Connect configuration. Microsoft does not provide good guidance on this question, providing an answer about a registry value at https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan which testing demonstrates does not work. You can disable hybrid join by preventing one of the requirement elements from triggering hybrid join registration:
For hybrid Entra ID joined devices, make sure to turn off automatic registration (see 'how to disable' section). Then the scheduled task (see 'Entra ID device registration' section) doesn't register the device again. Next, open a command prompt as an administrator and enter dsregcmd.exe /debug /leave. Or run this command as a script across several devices to unjoin in bulk. This answer comes from https://docs.microsoft.com/en-us/azure/active-directory/devices/faq.
When enabled for hybrid join, the trigger for Entra ID device registration is a default scheduled task with several triggers:
Note: the scheduled task comes installed with Windows 10; you do not need to add it, but you can trigger it manually yourself. See the links in the troubleshooting section for more info on this. Note: An additional user sign in may be required to get an Entra ID primary refresh token (PRT)
If your computer is off the UW network, you'll need to get it connected via a VPN prior to user sign-in to trigger Entra ID device registration. Please read our document about that.
Please consult https://docs.microsoft.com/en-us/azure/active-directory/devices/troubleshoot-hybrid-join-windows-current for how to verify and troubleshoot hybrid join. Other pages which may be useful are:
The known benefits are: