A cloud-based identity and access management service for securing user authentication and resource access
Hello Charles Lakes II,
Thank you for connecting with us offline.
Typically, issues signing in to a VM using Entra ID are related to Multi-Factor Authentication (MFA) being enforced through per-user MFA settings, Security Defaults, or Conditional Access policies.
During our call, we observed that users have per-user MFA was enabled for your account. As per standard procedure, we disabled it.
When we checked Security defaults, it's enabled in your tenant. To disable it, you opted free trial for Premium license and created Conditional Access requiring MFA excluding the "Microsoft Azure Windows Virtual Machine Sign-in" app (App ID: 372140e0-b3b7-4226-8ef9-d57986796201) from the targeted cloud apps.
However, the sign-in issue persisted. When we verified the device status from command prompt, it's is not Microsoft Entra joined but Microsoft Entra registered Windows 10 or later PC. In that case, you must enter credentials in the AzureAD\UPN format (for example, AzureAD\******@contoso.com) that resolved "The logon attempt failed" error.
Later, you got new error saying, "The requested session access is denied". This error occurred as you assigned "Virtual Machine User Login" role to user, but RDP session is trying to take over the admin session. To resolve it, edit the RDP file in Notepad and modify below entry setting to 0: administrative session:i:0
Once this is done, you are able to login successfully to VM.
For reference, see this Microsoft Learn article: Sign in to a Windows virtual machine in Azure by using Microsoft Entra ID.
Hope this helps! Please feel free to reach out for any further queries.
If the resolution was helpful, kindly take a moment to click on
and Yes for was this answer helpful to close this question.