Entra-only users cannot log into hybrid joined Windows 11 device | syncing 400 bad request problems and Number of retry attempts exceeds expectation

Information Tech 0 Reputation points
2025-12-24T19:06:48.7866667+00:00

Hello, I'm running into a brick wall trying to get an Entra-only user logged into a Windows 11 hybrid device that's joined to our on-prem Active Directory.

It allows other local user accounts and domain admins to login, but anyone with an Entra-only account gets the error "The username or password is incorrect. Try again."

Under both my domain admin and local admin accounts, the user can log into portal.office.com just fine with their credentials. They have a Microsoft 365 Business Premium license assigned. They do not have an on-prem user account.

Device is running Windows 11 Business version 25H2 and connected to corporate network via Ethernet on dock. It's showing compliant in Intune.

What I've tried:

  • Updated and repaired M365 apps
  • Cleared cached Windows credentials in Credential Manager
  • Forced gpupdate
  • Repaired the dsregcmd join state
  • Reset user's password (initially thought it was password problem at first)
  • Deleted device from Entra and Azure, then re-enrolled
  • Added and removed Entra account from Settings > Accounts > Access work or school
  • Different username login formats:
    • azuread\username
    • azuread******@domain.com
    • azuread******@domain.onmicrosoft.com
    • ******@domain.onmicrosoft.com
    • .\username
    • .******@domain.com

I can sync the device from Intune, but when I try to sync it under 'Access work or school', I get the error "The sync could not be initiated (0x80190190 Bad request (400). )"

And then if I try log into an M365 desktop app like Outlook and register the device, it times out after connecting with this error "Something went wrong - Error code -8951561991. Message: Number of retry attempts exceeds expectation."

Any help would be appreciated, I'm 2.5 hours in and checked many other troubleshooting articles - nothing has resolved yet.

Microsoft 365 and Office | Other

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer recommended by moderator
Information Tech 0 Reputation points
2026-01-14T14:44:16.3666667+00:00

Self-resolved, reimaged device fully and deleted from local AD and Intune and Azure.

After reimage - went back into Settings >Accounts > Access work or school, added user's Entra MS account, then went into Intune to change device ownership to Corporate and add it to a specific dynamic Intune security group.

After letting it sync and sit overnight, removed/disconnected user's MS account, tried adding another MS account and finally got the option to Join this device to Azure Active Directory - this was the missing piece; I can now log into Windows as that user's Entra account

220102-image.png

Huge thanks to https://learn.microsoft.com/en-us/answers/questions/922761/adding-an-azure-user-to-windows-11 for the tip!

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2025-12-24T19:07:03.32+00:00

    It seems you are facing multiple issues with Entra-only users logging into a hybrid joined Windows 11 device. Here are some troubleshooting steps based on the context provided:

    1. Check User Account Synchronization: Ensure that the Entra-only user account is properly synchronized with Microsoft Entra ID. Since the user does not have an on-premises account, confirm that their account is set up correctly in the Entra directory.
    2. Credential Format: When logging in, use the recommended UPN format. For example, try using ******@domain.onmicrosoft.com or ******@domain.com. Avoid using the azuread ame format as it may not be recognized correctly in some scenarios.
    3. Password Synchronization: Since the user is an Entra-only account, ensure that password synchronization is enabled for cloud-only users if applicable. If the user recently changed their password, it may not have synced yet, which can lead to login issues.
    4. Network Connectivity: Given the error "The sync could not be initiated (0x80190190 Bad request (400))", check for any network connectivity issues that may prevent the device from reaching the necessary endpoints. Ensure that the device can access the Microsoft Entra authentication services without any outbound proxy issues.
    5. Event Logs: Review the Microsoft Entra operational and analytic logs for any specific error codes that might provide more insight into the authentication failures. Look for Event ID 1081 or 1084, which may contain relevant error codes and descriptions.
    6. Device Compliance: Since the device shows as compliant in Intune, ensure that all policies are correctly applied and that there are no conflicting settings that could affect the login process.
    7. Retry Attempts Exceeded: The error "Number of retry attempts exceeds expectation" could indicate that the device is having trouble registering with the Microsoft Entra services. Ensure that the device is not blocked or restricted in any way that would prevent it from completing the registration process.

    If these steps do not resolve the issue, consider reaching out to Microsoft support for further assistance, as they may have more specific tools and resources to diagnose the problem.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?