We're moving off this to Jamf Connect, however I have continue binding for at least the next quarter.
The device must exist in AD - part of the requirement to get past ISE on the internal wired & wireless network.
The org runs a hybrid setup with on-prem AD syncing to Azure.
Can't bind in prestage because it can't reach the controllers since the computer is off-net.
We have situations where the bind policy fails on the first runs - because the device hasn't yet connected to the VPN. Once per computer with rerun on failure.
Configuration profile throws errors because it can't bind with the system off-net.
I'm over thinking this and can't find a way to effectively bind a new out of box system.
I appreciate any input.