Migrating Devices from On-Premises Active Directory to Microsoft Intune
Moving from domain-joined devices managed by Group Policy to modern Intune management is one of the most impactful infrastructure projects you can do. Here is how to plan and execute it without disrupting your users.
Thousands of organisations are still managing Windows devices the traditional way: domain-joined to on-premises Active Directory, controlled by Group Policy Objects, requiring VPN for remote management. This model was designed for a world where everyone worked in the office. For most businesses today, it creates friction, security gaps, and unnecessary infrastructure overhead.
Microsoft Intune, combined with Microsoft Entra ID (formerly Azure Active Directory), gives you a cloud-native alternative. Devices are managed over the internet with no VPN required, policies are applied in real time, and Windows Autopilot enables zero-touch provisioning direct from the manufacturer. The question is not whether to migrate, but how.
Understanding your starting point. Before planning your migration, you need to know the current join state of your devices. There are three states you will commonly encounter. On-premises AD joined only: traditional domain join, managed by Group Policy, no cloud management. Hybrid Entra joined: joined to both on-premises AD and Entra ID simultaneously, a common transitional state. Entra joined (cloud-only): the target state for modern management, no dependency on on-premises AD.
The migration paths. Path one is hybrid Entra join as a stepping stone. Devices are joined to both on-premises AD and Entra ID simultaneously using Entra Connect (formerly Azure AD Connect). This allows Intune management to begin immediately without changing anything on the device itself. You can then gradually shift policy workloads from Group Policy to Intune, moving compliance, Windows Update, and resource access policies across at a pace that works for your team. This is the preferred, non-disruptive path for most organisations. Path two is seamless migration to Entra-only join. Using a migration tool, existing AD-joined devices can be silently transitioned to Entra ID join and enrolled into Intune without requiring a device reset or any action from the end user. This removes the on-premises AD dependency cleanly while keeping users productive throughout.
Prerequisites before you start. You will need Intune licences for all users (included in Microsoft 365 Business Premium, EMS E3, or E5). For hybrid join, you need Entra Connect synchronising your on-premises AD with Entra ID. MDM authority must be set to Intune in your tenant. You should also review your Group Policy Objects and map them to Intune configuration profiles before cutting over. Microsoft provides the Group Policy Analytics tool within Intune to identify which GPOs can be directly translated.
Handling user data and applications. Because devices are not reset during migration, user data and locally installed applications remain intact. However, it is still best practice to ensure OneDrive Known Folder Move is configured so Desktop, Documents, and Pictures are cloud-backed before the migration begins. Application deployment should also be configured in Intune ahead of time so any additional required apps are pushed automatically once the device is under Intune management.
What to do on migration day. For hybrid join: enable Entra Connect device writeback, configure automatic MDM enrolment in Entra ID, and devices will enrol into Intune at next policy refresh with no user impact. For seamless Entra-only migration: run the migration tool in pilot mode on a small group first, validate that Intune policies are applied correctly, then roll out in batches. Verify device compliance in the Intune admin centre after each batch before proceeding.
Cloud Centrify has guided dozens of organisations through this migration. We assess your current environment, map Group Policy to Intune policies, configure Autopilot profiles, and manage the rollout with minimal user disruption. If you are ready to move to modern management, contact us for a free endpoint assessment.
Want to discuss this for your business?
Our team is happy to talk through how any of these topics apply to your specific environment.
Book a Free ConsultationTransform Your Business with Secure Cloud Solutions
Join 150+ organisations across the UK and Europe that trust Cloud Centrify as their Microsoft cloud and cybersecurity partner. Get a free, no-obligation consultation today.
