Error login to Azure Remote Environment (Automatically Restarting Server)

Bhashura Perera 0 Reputation points
2026-09-28T06:30:34.9366667+00:00

Issue

This error occurs for users when logging in every time.

Any solutions?

Azure Virtual Machines
Azure Virtual Machines

An Azure service that is used to provision Windows and Linux virtual machines.


2 answers

Sort by: Most helpful
  1. Senthil kumar 2,580 Reputation points
    2026-09-29T05:10:54.8466667+00:00

    Hi @Bhashura Perera

    Root Cause :

    • Windows service crashed.
    • Corrupted user profile.
    • Corrupted system files.
    • Windows update issue.
    • Driver crash after logon.

    Solutions :

    1. Open Event Viewer on the VM and review:

    Windows Logs

    ├─ System

    └─ Application

    Look for events just before the forced restart:

    • Event ID 1074
    • Event ID 6008
    • Event ID 7031 / 7034
    • Event ID 1000 (Application Error)
    1. Verify these services are running:

    sc query RdAgent

    sc query WindowsAzureGuestAgent

    Or check Services:

    • Remote Desktop Agent Loader
    • Windows Azure Guest Agent

    If the VM agent is corrupted, it can cause login-related issues.

    1. In Azure Portal:

    Virtual Machine

    → Help

    → Boot Diagnostics

    Check screenshots and serial logs around the reboot time.

    This often reveals driver failures or startup crashes.

    1. Test in Safe Mode

    If possible, use Azure Serial Console and boot to Safe Mode.

    If users can log in without rebooting in Safe Mode, the cause is typically:

    • Antivirus/EDR
    • Monitoring agent
    • Backup agent
    • VPN client
    • Recently installed software

    Thanks.

    Was this answer helpful?


  2. Andriy Bilous 12,276 Reputation points MVP
    2026-09-29T04:44:15.44+00:00

    Hello Bhashura Perera

    The screenshot indicates a Windows guest OS restart, not primarily an Azure/RDP connection issue. Because it happens when users sign in, first determine whether a critical Windows process is failing.

    Use Azure Portal → VM → Operations → Run command → RunPowerShellScript and check recent events:

    Get-WinEvent -FilterHashtable @{
        LogName='Application'
        Id=1000,1001,1015
        StartTime=(Get-Date).AddDays(-2)
    } | Select TimeCreated, Id, ProviderName, Message
    

    Also check unexpected restart events:

    Get-WinEvent -FilterHashtable @{
        LogName='System'
        Id=41,1074,6008
        StartTime=(Get-Date).AddDays(-2)
    } | Select TimeCreated, Id, ProviderName, Message
    

    Pay particular attention to an event immediately before the restart identifying a failed process such as lsass.exe.

    Boot Diagnostics and Serial Console are also useful if the VM enters a restart loop
    Boot Diagnostics

    Go to:

    VM → Help → Boot diagnostics

    Check the current screenshot and serial log. This helps determine whether Windows is reaching the login screen, crashing during startup, or entering a restart loop.

    If disabled, open Boot diagnostics → Settings, enable it using the managed storage option, and save.

    Microsoft: Azure VM Boot Diagnostics

    Serial Console
    If RDP disconnects before you can troubleshoot:

    VM → Help → Serial console

    For Windows Server, you should normally see:

    SAC>

    Then enter: cmd

    Switch to the created channel: ch -si 1

    Press Enter and authenticate with a local/admin account. You can then run CMD or start: powershell

    and inspect Event Logs/services without using RDP. Newer Azure Windows Server images normally have SAC enabled; older images might require Run command → EnableEMS.

    Microsoft: Azure Serial Console for Windows

    I would first capture the 1000/1015/1074 event immediately before the restart. That should identify whether this is a critical-process crash, software-triggered restart, or another Windows issue.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.