Microsoft Entra user unable to sign in to Azure Windows 11 VM

Saheed Damilare Adeleke 0 Reputation points
2026-10-01T21:02:33.32+00:00

I want to sign in to the VM using an Entra ID user account instead of the default local azureuser account created when the VM was set up.

Steps tried:

  1. Created a Windows 11 Azure VM.
  2. Enabled Microsoft Entra ID login.
  3. Installed AADLoginForWindows — provisioning succeeded.
  4. Assigned Virtual Machine User Login to the Entra user/group.
  5. Joined the VM to my Entra tenant.
  6. Created an Entra test user and also tried AzureAD\username and the UPN to sign in.
  7. Restarted the VM, but only the local azureuser account is available.

The Entra users still cannot sign in. What configuration am I missing?

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
0 comments No comments

2 answers

Sort by: Most helpful
  1. Scott Nguyen 2,130 Reputation points Independent Advisor
    2026-10-02T00:12:14.1966667+00:00

    Hello,

    The missing piece is most likely the RDP authentication method, rather than the creation of another Windows user. Microsoft Entra users do not need to appear as local accounts on the Windows sign-in screen.

    Please confirm that the VM has System-assigned Managed Identity enabled, the AADLoginForWindows extension installed successfully, and the required Virtual Machine User Login or Virtual Machine Administrator Login role assigned to the Entra user or group.

    For a Windows 11 VM, open mstsc.exe → Advanced → select Use a web account to sign in to the remote computer. Then connect using the VM's hostname/FQDN rather than its IP address and authenticate using the Entra UPN, for example ******@domain.com.

    Also verify that the test user is a member of the same Microsoft Entra tenant. If authentication still fails, review Event Viewer → Applications and Services Logs → Microsoft → Windows → AAD → Operational for relevant authentication errors.

    For more detailed information, please refer to Microsoft’s documentation: Sign in to Windows virtual machine in Azure using Microsoft Entra ID and Azure Roles Based Access Control

    Was this answer helpful?


  2. AI answer

    2026-10-01T21:02:58.23+00:00

    For Microsoft Entra sign-in to an Azure Windows 11 VM, these are the required checks that match this scenario:

    1. Verify the client device used for RDP
      • Remote sign-in to a Microsoft Entra joined VM is supported only from a Windows 10 or later PC.
      • The client must be Microsoft Entra joined, Microsoft Entra hybrid joined, or Microsoft Entra registered.
      • If the client is only Microsoft Entra registered, enter the username in AzureAD\UPN format, for example AzureAD\******@contoso.com.
    2. Verify the VM role assignment
      • The user must have either Virtual Machine User Login or Virtual Machine Administrator Login on the VM or applicable scope.
      • If this is missing, RDP can fail with: Your account is configured to prevent you from using this device.
    3. Confirm the VM is actually Microsoft Entra joined
      • On the VM, run:
             dsregcmd /status
        
      • Expected result:
        • AzureAdJoined : YES
        • AzureAdPrt : YES
      • If the VM is not fully joined, Microsoft Entra sign-in will not work even if the extension provisioning succeeded.
    4. Verify the AADLoginForWindows extension completed correctly
      • Check: C:\WindowsAzure\Logs\Plugins\Microsoft.Azure.ActiveDirectory.AADLoginForWindows\1.0.0.1\CommandExecution.log
      • If needed, validate the Azure Instance Metadata Service responses from the VM:
             curl.exe -H Metadata:true "http://169.254.169.254/metadata/instance?api-version=2017-08-01"
             curl.exe -H Metadata:true "http://169.254.169.254/metadata/identity/info?api-version=2018-02-01"
             curl.exe -H Metadata:true "http://169.254.169.254/metadata/identity/oauth2/token?resource=urn:ms-drs:enterpriseregistration.windows.net&api-version=2018-02-01"
        
      • Also verify these endpoints are reachable from the VM:
             curl.exe https://login.microsoftonline.com/ -D -
             curl.exe https://login.microsoftonline.com/<TenantID>/ -D -
             curl.exe https://enterpriseregistration.windows.net/ -D -
             curl.exe https://device.login.microsoftonline.com/ -D -
             curl.exe https://pas.windows.net/ -D -
        
        login.microsoftonline.com/<TenantID>, enterpriseregistration.windows.net, and pas.windows.net returning 404 Not Found is expected.
    5. Check that the extension was not removed after join
      • If AADLoginForWindows was uninstalled after the Microsoft Entra join process, sign-in will fail.
    6. Check MFA and Conditional Access
      • VM sign-in does not support legacy per-user Enabled/Enforced Microsoft Entra multifactor authentication.
      • If per-user MFA is enabled, remove that setting.
      • If Conditional Access requires MFA, the client device initiating the connection must use strong authentication such as Windows Hello.
      • If Windows Hello for Business is not available, exclude the Microsoft Azure Windows Virtual Machine Sign-in app from that Conditional Access policy.
      • If connecting from a Windows Server device, device compliance Conditional Access for Azure Windows VM sign-in is not supported.
    7. Check for temporary password or forced password change
      • Temporary passwords cannot be used for remote desktop sign-in.
      • Sign in with the account in a browser first and complete any required password change, then try RDP again.
    8. Review sign-in diagnostics
      • On the VM, review Event Viewer: Applications and Services Logs\Microsoft\Windows\AAD\Operational
      • This captures RDP sign-in attempts using Microsoft Entra accounts.
    9. If the VM still shows only azureuser
      • That does not by itself mean Microsoft Entra sign-in is unavailable.
      • In the RDP sign-in dialog, manually enter the Microsoft Entra username in the correct format rather than selecting only the displayed local account.

    Most likely missing items in this case are:

    • the RDP client device is not in a supported Microsoft Entra state,
    • the VM is not fully Microsoft Entra joined despite successful extension provisioning,
    • per-user MFA or Conditional Access is blocking non-interactive VM sign-in,
    • the username format is incorrect for a Microsoft Entra registered client.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.