Tool Detail
Smart Intune Hybrid Join Toolkit
First stable packaged release for LOT-based Hybrid Entra Join and Intune enrollment repair, with conservative AD, Intune, and optional Entra selection, a local WPF launcher, PsExec-based SYSTEM execution, and evidence-first reporting.
LOT
Manual or automatic LOT selection
Create operator-reviewed LOT folders manually or build conservative automatic LOTs from AD and Intune inventories, with optional Entra enrichment, collision filtering, exclusion evidence, and preview exports before any repair window starts.
WPF
Local WPF launcher and SYSTEM workflow
Use the WPF LOT launcher to create or open LOT folders, validate PsExec availability, and launch the autonomous signed repair workflow that runs on endpoints as SYSTEM through PsExec.
GRD
Guarded repair and reboot controls
Hybrid Join fixes, Intune enrollment repair paths, and reboots stay guarded through evidence checks, repair path flags, reboot limits, and Preview or Audit-first workflows instead of blind destructive actions.
RPT
CSV, HTML, and collected evidence
Each run keeps live CSV status, final CSV results, merged HTML summaries, PsExec logs, central evidence folders, and automatic run archives so support teams can review what happened before re-running anything.
Validated capabilities
Built for cautious batch recovery, not opaque remediation
The stable toolkit supports manual LOT folders and automatic LOT creation with conservative AD, Intune, and optional Entra selection logic. Automatic mode can filter by literal computer-name contains values, exclude devices already present in Intune, apply stale-AD exclusion, preserve preview evidence, and create the LOT without launching it.
The endpoint workflow is autonomous and signed, which lets the same repair script run as SYSTEM through PsExec while the launcher keeps local concurrency limits, technician-side run guards, backoff history, and controlled-stop behavior for long repair batches.
Reports stay local and supportable: live HTML and CSV cycle reporting, endpoint evidence collection, changed-state inventory refresh, archived prior runs, and clear audit signals before broader repair actions are enabled.
Security and package scope
Signed scripts, no bundled PsExec, and no private data in the release
PsExec is not redistributed in the public package and must be obtained separately from Microsoft Sysinternals. The launchers look for PsExec.exe in the toolkit, Windows system paths, or PATH, but the release ZIP itself does not ship that binary.
The package does not include any customer LOT, inventory export, log, report, tenant identifier, device name, or account data. PowerShell scripts are Authenticode-signed by workplacecloudhub.com, and the repository license for the release remains GPL-3.0.
Expected ZIP SHA-256: C0B3ADB4801C399F2829063A7FF0DCE96F8F395601EAA1E72CA547C669A3E7BA
Quick start
Download, verify, extract, add PsExec, and start with audit evidence
1. Download the public ZIP package from GitHub Releases.
2. Verify the ZIP against the published SHA-256 file and expected hash C0B3ADB4801C399F2829063A7FF0DCE96F8F395601EAA1E72CA547C669A3E7BA.
3. Extract the complete ZIP to a local folder.
4. Download PsExec separately from Microsoft Sysinternals and place it where the launcher can find it.
5. Run Start-IntuneHybridJoinRepair-LotLauncher-GUI.cmd and accept the Windows UAC prompt if elevation is required.
6. Start with Preview or Audit evidence, review the generated LOT and run reports, then enable guarded repair actions only after the pre-checks are clean.