<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hybrid Join on Kürşat Bal</title><link>http://kursatbal.com/tags/hybrid-join/</link><description>Recent content in Hybrid Join on Kürşat Bal</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 18 Mar 2025 00:00:00 +0000</lastBuildDate><atom:link href="http://kursatbal.com/tags/hybrid-join/index.xml" rel="self" type="application/rss+xml"/><item><title>Intune Hibrit Geçiş Rehberi — On-Prem AD'den Modern Yönetime</title><link>http://kursatbal.com/p/intune-hibrit-ge%C3%A7i%C5%9F-rehberi-on-prem-adden-modern-y%C3%B6netime/</link><pubDate>Tue, 18 Mar 2025 00:00:00 +0000</pubDate><guid>http://kursatbal.com/p/intune-hibrit-ge%C3%A7i%C5%9F-rehberi-on-prem-adden-modern-y%C3%B6netime/</guid><description>&lt;p&gt;Kurumsal ortamlarda yerleşik Active Directory altyapısını sürdürürken Intune yönetimine geçiş, dikkatli planlama gerektiren çok adımlı bir süreçtir. Bu rehber, kimlik senkronizasyonundan cihaz kaydına ve yetki devirlerine kadar tüm bileşenleri kapsar.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="kavramsal-çerçeve-hibrit-ortam-nedir"&gt;Kavramsal Çerçeve: Hibrit Ortam Nedir?
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Hibrit join&lt;/strong&gt; (Entra Hybrid Join), cihazın hem on-prem Active Directory&amp;rsquo;ye hem de Microsoft Entra ID&amp;rsquo;ye (eski adıyla Azure AD) kayıtlı olduğu durumdur. Bu model:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Geçiş döneminde şirket içi GPO yönetimini sürdürürken&lt;/li&gt;
&lt;li&gt;Intune MDM politikalarını aynı anda uygulamaya&lt;/li&gt;
&lt;li&gt;Koşullu erişim politikalarının cihaz durumuyla çalışmasına&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;olanak tanır.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cihaz kimlik modelleri karşılaştırması:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Model&lt;/th&gt;
&lt;th&gt;AD Kaydı&lt;/th&gt;
&lt;th&gt;Entra Kaydı&lt;/th&gt;
&lt;th&gt;Intune Yönetimi&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Domain Joined (klasik)&lt;/td&gt;
&lt;td&gt;Var&lt;/td&gt;
&lt;td&gt;Yok&lt;/td&gt;
&lt;td&gt;Hayır&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Entra Hybrid Joined&lt;/td&gt;
&lt;td&gt;Var&lt;/td&gt;
&lt;td&gt;Var&lt;/td&gt;
&lt;td&gt;Evet (MDM ile)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Entra Joined&lt;/td&gt;
&lt;td&gt;Yok&lt;/td&gt;
&lt;td&gt;Var&lt;/td&gt;
&lt;td&gt;Evet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Registered (BYOD)&lt;/td&gt;
&lt;td&gt;Yok&lt;/td&gt;
&lt;td&gt;Var (registered)&lt;/td&gt;
&lt;td&gt;Evet (MAM ile)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="lisanslama-gereksinimleri"&gt;Lisanslama Gereksinimleri
&lt;/h2&gt;&lt;p&gt;Intune ile MDM yönetimi için kullanıcı başına lisans zorunludur:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Lisans&lt;/th&gt;
&lt;th&gt;Intune MDM&lt;/th&gt;
&lt;th&gt;Conditional Access&lt;/th&gt;
&lt;th&gt;Defender&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;M365 Business Premium&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;Defender for Business&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;M365 E3&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;M365 E5 / EMS E5&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;Defender P2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Intune standalone&lt;/td&gt;
&lt;td&gt;Dahil&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote&gt;
&lt;p&gt;Lisanssız kullanıcıların cihazları MDM ile yönetilemez ve Conditional Access politikaları bu cihazları uyumsuz olarak işaretler.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="entra-id-ve-entra-connect-hazırlığı"&gt;Entra ID ve Entra Connect Hazırlığı
&lt;/h2&gt;&lt;h3 id="entra-id-tenant-yapılandırması"&gt;Entra ID Tenant Yapılandırması
&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Entra admin center&lt;/strong&gt; → Identity → Overview — tenant bilgilerini doğrulayın&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Custom domain&lt;/strong&gt; eklenmiş ve doğrulanmış olmalıdır&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;UPN suffix&lt;/strong&gt; on-prem AD ile eşleşmeli: &lt;code&gt;kullanici@sirket.com&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="entra-connect-klasik-veya-cloud-sync"&gt;Entra Connect (Klasik) veya Cloud Sync
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Hangi araç ne zaman?&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Araç&lt;/th&gt;
&lt;th&gt;Uygun Senaryo&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Entra Connect (AAD Connect)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Karmaşık filtreler, özel öznitelik eşleştirme, Exchange hibrit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cloud Sync&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Çoklu orman, basit senkronizasyon, aracı tabanlı yüksek erişilebilirlik&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Cloud Sync kurulumu:&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Microsoft Entra admin center → Hybrid management → Microsoft Entra Connect → Cloud Sync&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Yeni yapılandırma&lt;/strong&gt; → &amp;ldquo;AD&amp;rsquo;den Microsoft Entra Kimliği&amp;rdquo;&lt;/li&gt;
&lt;li&gt;Aracıyı (provisioning agent) indirip Exchange VM&amp;rsquo;ine veya üye sunucuya kurun&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Kapsam filtresi:&lt;/strong&gt; Senkronize edilecek OU&amp;rsquo;ları belirleyin (ör. &lt;code&gt;OU=Users,DC=sirket,DC=com&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Öznitelik eşleştirmesi:&lt;/strong&gt; &lt;code&gt;userPrincipalName&lt;/code&gt; → &lt;code&gt;Trim([mail])&lt;/code&gt; (mail özniteliği dolu olmalı)&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="servis-bağlantı-noktası-scp-yapılandırması"&gt;Servis Bağlantı Noktası (SCP) Yapılandırması
&lt;/h3&gt;&lt;p&gt;SCP, cihazların hangi Entra ID tenant&amp;rsquo;a kayıt olacağını anlamas için gereklidir.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Group Policy üzerinden SCP (Windows 10/11):&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Bilgisayar Yapılandırması → Tercihler → Windows Ayarları → Registry:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Hive : HKEY_LOCAL_MACHINE
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Path : SOFTWARE\Microsoft\Windows\CurrentVersion\CDJ\AAD
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Value : TenantId → &amp;lt;Entra Tenant ID&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Value : TenantName → &amp;lt;doğrulanmış domain adı&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Alternatif — AD&amp;rsquo;de SCP nesnesi:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$scp&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;DirectoryServices&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;DirectoryEntry&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$scp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Path&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;LDAP://CN=62a0ff2e-97b9-4a43-99f6-73c7ecdc9b81,CN=Device Registration Configuration,CN=Services,CN=Configuration,DC=sirket,DC=com&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$scp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Keywords&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;azureADId:&amp;lt;TenantId&amp;gt;&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$scp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Keywords&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;azureADName:&amp;lt;TenantName&amp;gt;&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$scp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;CommitChanges&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="gpo-ile-cihaz-kaydı-otomasyonu"&gt;GPO ile Cihaz Kaydı Otomasyonu
&lt;/h2&gt;&lt;p&gt;Domain-joined Windows 10/11 cihazlarının Entra Hybrid Join sürecini GPO tetikler.&lt;/p&gt;
&lt;h3 id="task-scheduler-görevi-otomatik-kayıt"&gt;Task Scheduler Görevi (Otomatik Kayıt)
&lt;/h3&gt;&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Group Policy Management Editor:
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Bilgisayar Yapılandırması → Tercihler → Denetim Masası Ayarları → Zamanlanmış Görevler
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Ad : Automatic-Device-Join
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Tetik: Kullanıcı oturum açtığında
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Eylem: dsregcmd /join
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Alternatif olarak MDM enrollment GPO ile yapılabilir:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bilgisayar Yapılandırması → İdari Şablonlar → Windows Bileşenleri → MDM:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Enable automatic MDM enrollment using default Azure AD credentials : Enabled
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="mdm-otomatik-kayıt-yapılandırması"&gt;MDM Otomatik Kayıt Yapılandırması
&lt;/h2&gt;&lt;h3 id="intuneda-mdm-kapsam-ayarı"&gt;Intune&amp;rsquo;da MDM Kapsam Ayarı
&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;Intune admin center → Devices → Enrollment → Automatic Enrollment&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MDM user scope:&lt;/strong&gt; &lt;code&gt;All&lt;/code&gt; (veya pilot grup için &lt;code&gt;Some&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MDM terms of use URL, discovery URL, compliance URL&lt;/strong&gt; → varsayılan değerler bırakılabilir&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="kayıt-doğrulama"&gt;Kayıt Doğrulama
&lt;/h3&gt;&lt;p&gt;Cihazda komut isteminden:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-cmd" data-lang="cmd"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;dsregcmd /status
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Beklenen çıktı:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;AzureAdJoined : YES
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;EnterpriseJoined : NO
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;DomainJoined : YES
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;AzureAdPrt : YES
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Intune&amp;rsquo;a kayıt doğrulaması:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-cmd" data-lang="cmd"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;mdmdiagnosticstool.exe -area Autopilot -cab c:\mdm_report.cab
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="doğrulama-ve-uzaktan-yönetim"&gt;Doğrulama ve Uzaktan Yönetim
&lt;/h2&gt;&lt;h3 id="intune-admin-centerdan-cihaz-kontrolü"&gt;Intune Admin Center&amp;rsquo;dan Cihaz Kontrolü
&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;Devices → All Devices → cihazı filtreleyin&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Managed by:&lt;/strong&gt; &lt;code&gt;Intune&lt;/code&gt; görünmeli&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compliance:&lt;/strong&gt; &lt;code&gt;Compliant&lt;/code&gt; (politika henüz atanmadıysa &lt;code&gt;Not evaluated&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Join Type:&lt;/strong&gt; &lt;code&gt;Hybrid Azure AD joined&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="ilk-politika-atamaları"&gt;İlk Politika Atamaları
&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Yeni kaydolan cihazlar için başlangıç grubu: &lt;strong&gt;Tüm Cihazlar&lt;/strong&gt; veya dinamik grup (&lt;code&gt;deviceOSType -eq &amp;quot;Windows&amp;quot;&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;İlk atanacak politikalar: BitLocker encryption, Firewall, Defender settings&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="hibrit-yapının-kısıtlamaları"&gt;Hibrit Yapının Kısıtlamaları
&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Sınırlama&lt;/th&gt;
&lt;th&gt;Açıklama&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;GPO ve MDM çakışması&lt;/td&gt;
&lt;td&gt;Aynı ayar hem GPO hem Intune&amp;rsquo;dan geliyorsa &lt;strong&gt;GPO kazanır&lt;/strong&gt;. Çift yönetimden kaçının.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Şifre yönetimi&lt;/td&gt;
&lt;td&gt;Hibrit Join&amp;rsquo;da şifre değişikliği on-prem DC üzerinden gerçekleşir; Entra SSPR bağımsız çalışmaz&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Autopilot + Hybrid Join&lt;/td&gt;
&lt;td&gt;Pre-provisioning ve Hybrid Join birlikte kullanılıyorsa Intune Connector for AD gereklidir&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;LAPS&lt;/td&gt;
&lt;td&gt;Legacy LAPS on-prem ile çalışır; Windows LAPS Entra&amp;rsquo;ya veya AD&amp;rsquo;ye ayrı ayrı yapılandırılabilir&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Uygulama dağıtımı&lt;/td&gt;
&lt;td&gt;Win32 uygulamaları Intune Management Extension (IME) gerektirir — cihaz her iki kaynaktan uygulama alabilir&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote&gt;
&lt;p&gt;Uzun vadeli hedef: Entra Joined (full cloud) mimarisine geçiş. Hibrit Join bir köprüdür, son durak değildir.&lt;/p&gt;
&lt;/blockquote&gt;</description></item></channel></rss>