Hybrid join is when a domain-joined Windows PC also registers in Microsoft Entra ID. When it works, users get single sign-on to Microsoft 365, and Conditional Access can trust the device. When it doesn't, you get an endless "pending" device, Conditional Access blocks, and users prompted for credentials they already entered.
Everything starts with one command, run on the affected PC as the signed-in user:
dsregcmd /statusDevice State
| Field | Healthy value | If not |
|---|---|---|
AzureAdJoined | YES | The device hasn't completed hybrid join. Start at "Join never completes" below. |
DomainJoined | YES | It isn't domain-joined, so hybrid join can't apply. Use Entra join instead. |
EnterpriseJoined | NO | YES is only for on-prem device registration, and is rare. |
Device Details
DeviceId: search for it in Entra ID -> Devices to find this PC's object.TpmProtected:YESis preferred.NOon hardware with a TPM points to a TPM problem.DeviceAuthStatus: must beSUCCESS.FAILEDusually means the device object was deleted or disabled in Entra ID.
SSO State
AzureAdPrt : YESmeans the user has a Primary Refresh Token, which is what single sign-on runs on. If this isNOwhileAzureAdJoinedisYES, the join worked but the user's sign-in didn't. Check the "Diagnostic Data" section of the output for the error code.AzureAdPrtUpdateTimeshould be recent. An old timestamp means the PRT isn't being refreshed, often because the PC can't reach Microsoft's endpoints.
Failure: join never completes
Work through these in order:
- The computer object is in a synced OU. Entra Connect only syncs devices in the OUs you selected. Check the sync scope.
- The SCP is configured. Domain PCs discover your tenant through a service connection point in AD (or a registry setting for targeted rollouts). Without it, they never try.
- The device has synced. In Entra ID, the device should appear as Microsoft Entra hybrid joined. If it shows as Pending, the PC hasn't completed its side of registration yet.
- The PC can reach Microsoft endpoints as SYSTEM, not just as the user:
enterpriseregistration.windows.net,login.microsoftonline.com, anddevice.login.microsoftonline.com. Proxies that need user authentication break this. - The scheduled task ran. Task Scheduler -> Microsoft -> Windows -> Workplace Join -> Automatic-Device-Join. It runs at sign-in and on a schedule.
- The event log is clean. Check Applications and Services Logs -> Microsoft -> Windows -> User Device Registration -> Admin for errors.
To force a retry after fixing the cause:
# Run as administrator
dsregcmd /leave
# Restart, sign in with a domain account, wait a few minutes, then:
dsregcmd /statusFailure: stuck in "Pending"
Pending means Entra ID knows about the device from sync, but the device hasn't finished registering. The usual causes are the scheduled task not running, endpoints blocked as SYSTEM, or an old or incorrect userCertificate on the computer object. Removing stale certificates from the object and letting the task run again fixes most of these.
Failure: joined, but no SSO
AzureAdJoined : YES with AzureAdPrt : NO:
- The user signed in with a local account or cached credentials without line of sight to a DC or the internet.
- The user's UPN suffix isn't verified in the tenant, so their on-prem UPN doesn't match their cloud UPN.
- Look for the error code in
dsregcmd /statusunder Diagnostic Data, and search it in the User Device Registration log.
Should you still be using hybrid join?
Hybrid join is a bridge. For new PCs, Microsoft Entra join with Intune and Autopilot is simpler, with no line-of-sight to a DC and no sync dependency. Most small businesses I work with move to Entra join as devices get replaced. See Autopilot from scratch.