For Microsoft Entra sign-in to an Azure Windows 11 VM, these are the required checks that match this scenario:
- Verify the client device used for RDP
- Remote sign-in to a Microsoft Entra joined VM is supported only from a Windows 10 or later PC.
- The client must be Microsoft Entra joined, Microsoft Entra hybrid joined, or Microsoft Entra registered.
- If the client is only Microsoft Entra registered, enter the username in
AzureAD\UPNformat, for exampleAzureAD\******@contoso.com.
- Verify the VM role assignment
- The user must have either Virtual Machine User Login or Virtual Machine Administrator Login on the VM or applicable scope.
- If this is missing, RDP can fail with: Your account is configured to prevent you from using this device.
- Confirm the VM is actually Microsoft Entra joined
- On the VM, run:
dsregcmd /status - Expected result:
-
AzureAdJoined : YES -
AzureAdPrt : YES
-
- If the VM is not fully joined, Microsoft Entra sign-in will not work even if the extension provisioning succeeded.
- On the VM, run:
- Verify the
AADLoginForWindowsextension completed correctly- Check:
C:\WindowsAzure\Logs\Plugins\Microsoft.Azure.ActiveDirectory.AADLoginForWindows\1.0.0.1\CommandExecution.log - If needed, validate the Azure Instance Metadata Service responses from the VM:
curl.exe -H Metadata:true "http://169.254.169.254/metadata/instance?api-version=2017-08-01" curl.exe -H Metadata:true "http://169.254.169.254/metadata/identity/info?api-version=2018-02-01" curl.exe -H Metadata:true "http://169.254.169.254/metadata/identity/oauth2/token?resource=urn:ms-drs:enterpriseregistration.windows.net&api-version=2018-02-01" - Also verify these endpoints are reachable from the VM:
curl.exe https://login.microsoftonline.com/ -D - curl.exe https://login.microsoftonline.com/<TenantID>/ -D - curl.exe https://enterpriseregistration.windows.net/ -D - curl.exe https://device.login.microsoftonline.com/ -D - curl.exe https://pas.windows.net/ -D -login.microsoftonline.com/<TenantID>,enterpriseregistration.windows.net, andpas.windows.netreturning404 Not Foundis expected.
- Check:
- Check that the extension was not removed after join
- If
AADLoginForWindowswas uninstalled after the Microsoft Entra join process, sign-in will fail.
- If
- Check MFA and Conditional Access
- VM sign-in does not support legacy per-user Enabled/Enforced Microsoft Entra multifactor authentication.
- If per-user MFA is enabled, remove that setting.
- If Conditional Access requires MFA, the client device initiating the connection must use strong authentication such as Windows Hello.
- If Windows Hello for Business is not available, exclude the Microsoft Azure Windows Virtual Machine Sign-in app from that Conditional Access policy.
- If connecting from a Windows Server device, device compliance Conditional Access for Azure Windows VM sign-in is not supported.
- Check for temporary password or forced password change
- Temporary passwords cannot be used for remote desktop sign-in.
- Sign in with the account in a browser first and complete any required password change, then try RDP again.
- Review sign-in diagnostics
- On the VM, review Event Viewer:
Applications and Services Logs\Microsoft\Windows\AAD\Operational - This captures RDP sign-in attempts using Microsoft Entra accounts.
- On the VM, review Event Viewer:
- If the VM still shows only
azureuser- That does not by itself mean Microsoft Entra sign-in is unavailable.
- In the RDP sign-in dialog, manually enter the Microsoft Entra username in the correct format rather than selecting only the displayed local account.
Most likely missing items in this case are:
- the RDP client device is not in a supported Microsoft Entra state,
- the VM is not fully Microsoft Entra joined despite successful extension provisioning,
- per-user MFA or Conditional Access is blocking non-interactive VM sign-in,
- the username format is incorrect for a Microsoft Entra registered client.
References: