An Azure service that is used to provision Windows and Linux virtual machines.
Hello @Eric-5173
Adding a work account does not by itself confirm that the VM became Microsoft Entra joined or MDM-managed. The first step is to establish whether the timing is causal or coincidental.
- Sign in with the account that was added and run:
dsregcmd /status
Check:
- AzureAdJoined - whether the device is Microsoft Entra joined.
- WorkplaceJoined - whether a work account is registered in the current user context.
- Open Settings > Accounts > Access work or school. If the account has an Info option, open it and select Create report > Export to collect the MDM diagnostic report. Also check this Event Viewer location for enrollment or policy activity at the time the account was added:
Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin
- In Azure Network Watcher, run IP flow verify separately for inbound TCP ports 3389 and 53281, using the VM’s private IP and the actual client source IP. IP flow verify reports whether the packet is allowed or denied by the applicable NSG or Azure Virtual Network Manager security-admin rule and identifies the matching rule.
- If IP flow verify reports Allow, start an Azure Network Watcher packet capture filtered for these ports and reproduce the connection attempt. This determines whether the inbound TCP SYN reaches the VM and whether the VM sends a response.
Because both RDP and SFTP stopped simultaneously while both services remain listening, this should be investigated as a shared network-filtering path rather than as an RDP-only problem. If the SYN reaches the guest but no SYN-ACK leaves it, inspect Windows Filtering Platform, IPsec/connection-security rules, and any endpoint-security network filter. Disabling the Windows Firewall profiles does not necessarily remove filters installed by other WFP-based software. Windows Filtering Platform can filter or modify traffic at multiple networking layers.
I cannot find verified official documentation establishing that merely adding a Microsoft 365 work account blocks arbitrary inbound VM ports. The dsregcmd, MDM logs, IP flow result, and packet capture are therefore needed before attributing the outage to Entra registration or an MDM policy.
References:
Troubleshoot devices by using the dsregcmd command
Diagnose MDM enrollment failures
Azure Network Watcher packet capture overview
Windows Filtering Platform auditing and logging
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.