HomeBlogMoving From an Office Server to Intune: The Hybrid Route for Small Businesses
How to

Moving From an Office Server to Intune: The Hybrid Route for Small Businesses

16 min readUpdated 7 October 2026
Moving From an Office Server to Intune: The Hybrid Route for Small Businesses

Last checked: 7 October 2026.

The short version:

  • Syncing your office Active Directory to Microsoft Entra ID, with device sync switched on, lets each PC get a cloud identity. It does not put the PC into Intune.
  • One built-in Group Policy setting tells hybrid-joined PCs to enrol in Intune on their own. No scripts needed.
  • For a normal small business, choose User Credential in that policy. Device Credential is only supported in a couple of specific setups.
  • Hybrid is best treated as a stepping stone. New laptops can go cloud-only, and the server can retire on your timetable.

You turned on sync. Staff now sign in to Microsoft 365 with the same password they use on their office PC. Someone told you that means the laptops are "in the cloud" now. Then you open the Intune admin centre to push a policy, and the Devices page is empty.

This catches out a lot of small businesses that still run a server in the office. The good news is the missing piece is small. Syncing handles who the device is. Intune needs a second step that decides who manages it. Below, we explain both, walk through the setup on a Windows domain, and cover the problems we see most when moving from Active Directory to Microsoft Intune.

If you have no server and are starting fresh with new laptops, you want the cloud-only route instead. Our guide to managed Windows devices for small businesses covers that, with Autopilot and Entra join.

Does syncing Active Directory put my PCs into Intune?

No. Sync tools copy your users from the office server into Microsoft Entra ID. With device sync configured as well, your PCs can register and become "hybrid joined", which gives each one a cloud identity. Syncing users and passwords alone doesn't do that. Intune is a separate management service again. A PC only appears in Intune once it enrols, and enrolment is a step you have to switch on.

Think of it like a new member of staff. Sync gives them an ID badge, so the building knows who they are. Enrolment is them signing the staff handbook, which is what lets you set rules for them. One doesn't happen just because the other did.

That difference matters because the things most businesses actually want sit on the management side:

  • Forcing BitLocker encryption on every laptop.
  • Pushing Windows updates on a schedule, including to staff who never come into the office.
  • Installing and removing apps without visiting each desk.
  • Wiping a lost or stolen laptop.
  • Showing which devices meet your security rules, for Cyber Essentials or a client questionnaire.

None of that works until the PC is enrolled.

Which sync tool do you need for hybrid join?

Either of Microsoft's two sync tools will do it. Microsoft Entra Connect Sync is the long-standing full install on a server. Microsoft Entra Cloud Sync is a lighter agent that Microsoft manages from the cloud. As of October 2026, both support syncing computers for hybrid join, but in Cloud Sync you have to switch device sync on separately.

This changed recently. For years, Cloud Sync didn't handle computer objects at all, and many guides online still say so. Microsoft's device sync guide for Cloud Sync now covers it, including the service connection point (SCP) your PCs use to find your tenant. Device sync is off by default, so it is easy to miss.

Here is how the two compare for a small business:

Entra Connect SyncEntra Cloud Sync
Where it runsFull install on a serverLight agent on a server, managed from the cloud
Hybrid join for PCsSupportedSupported, once device sync is switched on
Size limitsNo per-domain object limitUp to 150,000 objects per domain
Best forExisting installs and complex setupsNew setups and simpler single-office domains

Microsoft's decision guide for moving to Cloud Sync is worth reading before you pick. A small business is nowhere near Cloud Sync's size limits. If you already run Connect Sync and it works, there is no reason to change it for this project.

If your office server is getting old and nobody is sure how it was set up, this is the point where we usually suggest a short review. We look at what the server still does before anyone changes sync settings. Our managed IT service starts every hybrid move this way.

What you need before you start

Five things must be in place before Group Policy can enrol anything: Intune and Entra ID P1 licences for each user, the MDM user scope switched on, hybrid join working, a supported Windows Pro (or higher) edition on every PC, and user sign-in names that match a domain you own. Missing any one of them is the usual reason enrolment silently fails.

  1. Intune and Entra ID P1 (or P2) licences for every user. Automatic enrolment needs both. Microsoft 365 Business Premium includes Intune and Entra ID P1, so it covers both in one licence. Business Basic and Business Standard include neither. Our Microsoft 365 licensing guide explains the plans in plain English.
  2. MDM user scope set to Some or All. In the Intune admin centre, go to Devices, then Device onboarding, Enrollment, the Windows tab and Automatic Enrollment. If the MDM user scope says None, nothing will enrol. Set it to Some (with a pilot group) while you test, then All.
  3. Device sync and hybrid join configured. This includes the service connection point (SCP), which is how PCs find your Microsoft tenant. In Connect Sync, the wizard sets it up under "Configure device options". In Cloud Sync, you switch on device sync and set up the SCP yourself. Either way, your computer OUs must be inside the sync scope.
  4. Windows 11 Pro, Enterprise or Education. Windows Home can't join a domain, so Home PCs need upgrading to Pro first. Windows 10 reached end of support on 14 October 2025. Intune still lets Windows 10 PCs enrol, but Microsoft no longer guarantees features will work on them, so plan to upgrade or replace them.
  5. Routable sign-in names. Many older office domains use something like company.local. In the usual setup (password hash sync, no federation), users need a sign-in name (UPN) on your real, verified domain, such as name@company.co.uk. Microsoft's hybrid join planning guide covers the federated exceptions. Check which setup you have before changing anyone's sign-in.

We'd also strongly suggest a pilot OU: a separate folder in Active Directory with three or four test PCs from different teams. You link the new policy there first, so if something goes wrong it affects four people, not forty.

How to switch on automatic enrolment with Group Policy

Once the prerequisites are in place, the setup has four parts. Check hybrid join on a test PC, create one Group Policy Object, choose the credential type, then wait for the PC to pick it up and enrol. The change itself is small. Most of the work is the planning and checking around it.

Step 1: Check hybrid join with dsregcmd

Sign in to a test PC, open Command Prompt and run:

dsregcmd /status

Under Device State, you need to see both of these:

AzureAdJoined : YES
DomainJoined : YES

Then scroll to Tenant Details and look for an MdmUrl line with an address in it. If it is blank, the MDM user scope from the checklist above isn't set, or doesn't include this user. That one line saves a lot of guessing later.

If AzureAdJoined says NO, stop here. The PC hasn't finished hybrid join yet. It can take a sync cycle and a restart or two. If it stays at NO, the SCP or the sync scope is usually the cause.

Step 2: Create the auto-enrolment policy

  1. On a domain controller, open Group Policy Management.
  2. Create a new GPO and link it to your pilot OU.
  3. Edit it and go to: Computer Configuration > Policies > Administrative Templates > Windows Components > MDM
  4. Open Enable automatic MDM enrollment using default Azure AD credentials. In newer policy templates the same setting is called Enable automatic MDM enrollment using default Microsoft Entra credentials.
  5. Set it to Enabled.

If you can't see the setting at all, your domain controller has old policy templates. Microsoft's guide to enrolling Windows devices with Group Policy explains how to update them in the central store.

Step 3: User Credential or Device Credential?

Choose User Credential. It enrols the PC using the signed-in member of staff's Microsoft 365 account, which matches how Intune is licensed. Microsoft only supports Device Credential for co-management with Configuration Manager or Azure Virtual Desktop multi-session, neither of which most small businesses run.

A lot of guides recommend Device Credential because it can enrol a PC with nobody signed in. It sounds tidier. The catch is that Intune licences are tied to users, and Microsoft's own enrolment guidance limits Device Credential to those two scenarios. If you pick it on a normal office domain, you are outside what Microsoft supports, and that's not where you want to be when something breaks.

The practical effect of User Credential is small: a PC enrols once someone with an Intune licence signs in. In an office where people log in every morning, that happens on day one anyway.

Step 4: How long does it take?

PCs refresh Group Policy every 90 minutes, plus a random delay of up to 30 minutes, or straight away after gpupdate /force and a restart. Once a PC reads the policy, Windows creates a scheduled task that tries to enrol every five minutes for a day.

You can see that task in Task Scheduler under Microsoft > Windows > EnterpriseMgmt. If it is there, the policy arrived. Once the PC appears in the Intune admin centre and starts receiving its policies, that pilot device has worked.

The enrolment journey at a glance

Office server Active Directory Step 1 Entra device sync Microsoft Entra ID Hybrid joined (identity) Step 2 Group Policy enrolment Microsoft Intune Enrolled (managed) 1. Your PCs exist only in the office server. No cloud identity, no remote management. 2. Device sync registers each PC in Entra ID. Hybrid joined: an identity, not management. 3. Group Policy tells each PC to enrol. Now Intune can update, encrypt and wipe it.

Why doesn't my PC show up in Intune?

Most failed enrolments come down to five causes: the user has no Intune licence, the MDM user scope is None or excludes them, the PC isn't fully hybrid joined, the sign-in name is on a .local domain, or the PC is still enrolled in an old MDM tool. Check them in that order.

  • No licence. Check the user in the Microsoft 365 admin centre. They need Intune and Entra ID P1. Business Standard includes neither.
  • Scope. If the MDM user scope is Some, make sure the user is in the chosen group. A blank MdmUrl in dsregcmd /status points here.
  • Not hybrid joined. Run dsregcmd /status again. If AzureAdJoined is NO, fix sync and the SCP before touching the policy.
  • Wrong sign-in name. Users on @company.local need their UPN changed to your real domain in Active Directory, then a sync.
  • Old MDM leftovers. A PC that was once in another management tool may need that enrolment removed first.

For the detail, look in Event Viewer under Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin. Failed enrolments leave an error there with a code you can search.

If a PC has lost contact with the domain altogether, our guide to fixing domain trust relationship errors covers that separate problem.

Is hybrid the end goal, or a stepping stone?

For most small businesses, hybrid is a stepping stone. Microsoft now steers new devices towards cloud-native endpoints that are Entra joined with no office server involved. Hybrid lets you manage the PCs you have today while you work out what the server still does and move it piece by piece.

A typical path looks like this:

  1. Now: hybrid join plus Group Policy enrolment, so every existing PC lands in Intune.
  2. Next laptop purchase: new machines go straight to Entra join through Autopilot. They never touch the domain.
  3. Move the files: shared drives move to SharePoint and OneDrive. Our guide to moving a file server or NAS to SharePoint covers how.
  4. Move the settings: Group Policy settings get rebuilt as Intune policies, one area at a time.
  5. Retire the server: once nothing depends on it, it goes. No more server warranty, backups or replacement bill.

Some businesses keep a server for longer, and that's fine. An accounts package that needs a domain login, or a line-of-business app nobody can replace yet, is a real reason to stay hybrid. The point is to choose that on purpose, not to drift.

What an office rollout looks like when we run it

A typical office we help has a server in the cupboard, Microsoft 365 for email, and a mix of PCs set up by hand over the years. The owner wants laptops encrypted, updated and manageable from anywhere, without a weekend of downtime. Here is how we run that move, and the snags we plan for.

We check every PC before touching the policy. We run dsregcmd /status on each machine, check its Windows edition and match every user to a licence. That is usually where the surprises are: a laptop bought from a high street shop still on Windows Home, or a few staff whose sign-in name still ends in .local. Fixing those first stops the rollout stalling halfway through.

The pilot includes the awkward machines. We don't pilot on the newest, cleanest laptops. We pick the accounts PC with the old finance package, the reception PC everyone shares and a laptop that mostly works from home. If the policies break something, it shows up on four machines, not the whole office.

Shared PCs need a plan. With User Credential, a PC enrols when a licensed user signs in. A reception or warehouse PC that only ever uses a shared local account won't enrol on its own. We decide how each shared PC will be handled before the rollout, not after it fails.

Policies go on in layers. Enrolment comes first, then updates, then BitLocker encryption, then apps. Turning everything on at once makes it hard to tell which setting caused a problem.

The handover is a list, not a promise. At the end, you get every PC with its enrolment, encryption and update status, plus what still depends on the server and what we'd move next.

How Verge Tech runs the move for you

If your office still runs on a server and you want your PCs managed from the cloud, we can plan and run the move. One named senior engineer owns your job from the first look to the handover. The person who explains the plan is the person who does the work.

Here's how it goes:

  1. Look. We check your server, sync setup, licences, sign-in names and every PC, on-site or remotely.
  2. Explain. You get a plain-English summary of what the server does, what's blocking Intune, and the options.
  3. Agree. We agree the route (hybrid first, or straight to cloud-only) and the cost before any change.
  4. Do it. Pilot first, then the rest of the office in groups, with Intune policies for encryption, updates and security.

Microsoft Intune means you can encrypt, update and wipe your company laptops from one web page, wherever your staff are working, instead of visiting each desk. We pair it with Microsoft 365 support so email, files and devices are looked after together.

Business IT support is £95 an hour on-site and £60 an hour remote. Ongoing device management is available as part of our managed IT service. We cover London, Berkshire and Surrey.

Frequently Asked Questions

Does Entra Connect enrol devices in Intune?

No. Entra Connect, or Cloud Sync with device sync switched on, lets domain-joined PCs register in Microsoft Entra ID as hybrid joined. Enrolling them in Intune is a separate step, usually done with the "Enable automatic MDM enrollment" Group Policy setting.

Do I need Microsoft 365 Business Premium for Intune?

Not necessarily, but each user needs both an Intune licence and Entra ID P1 (or P2). Business Premium includes Intune, Entra ID P1 and Defender for Business in one licence, which is why we usually recommend it. Business Basic and Business Standard include neither.

Can Windows 11 Home PCs enrol this way?

No. Windows Home can't join a domain, so it can't be hybrid joined, and it can't be Entra joined as a company device either. For a business-owned PC, upgrade it to Windows 11 Pro first.

Will staff notice anything when their PC enrols?

Very little. Enrolment runs in the background after they sign in. They may see new policies appear later, such as BitLocker encryption starting or a new app installing, depending on what you configure in Intune.

Can we skip hybrid and go straight to cloud-only?

Yes, if the server isn't doing anything your PCs still depend on. Existing PCs would need resetting and joining to Entra ID, which takes planning. Many offices use hybrid for current PCs and cloud-only for new ones.

Managed IT and device management

Want your Macs and PCs managed properly, not just fixed when they break?

Verge Tech sets up and runs device management for small businesses across London, Berkshire and Surrey — Intune, Autopilot, Apple Business, MDM, patching, encryption and Cyber Essentials-ready security baselines, all for a fixed monthly cost.

Keep reading

Related IT guides

Written by

Noman Maqsood (Nomi)

Senior IT Engineer · Azure Certified

Nomi has 7+ years in cloud, networking, and hybrid infrastructure. He writes about practical IT solutions — no jargon, just what actually works.

More from Nomi at nmaqsood.com →

Get help today

Need help with your computer or IT setup?

We cover London, Berkshire and Surrey — remote or on-site.

Microsoft & CompTIA Certified
4.9★ Google Rated
020 3376 1140

We use analytics cookies to see which pages help visitors, so we know what to improve. We only set them if you accept. Read our privacy policy.

WhatsApp

Message an engineer

Start with a common issue

Open WhatsApp chat