Hello, I'm running into a brick wall trying to get an Entra-only user logged into a Windows 11 hybrid device that's joined to our on-prem Active Directory.
It allows other local user accounts and domain admins to login, but anyone with an Entra-only account gets the error "The username or password is incorrect. Try again."
Under both my domain admin and local admin accounts, the user can log into portal.office.com just fine with their credentials. They have a Microsoft 365 Business Premium license assigned. They do not have an on-prem user account.
Device is running Windows 11 Business version 25H2 and connected to corporate network via Ethernet on dock. It's showing compliant in Intune.
What I've tried:
- Updated and repaired M365 apps
- Cleared cached Windows credentials in Credential Manager
- Forced gpupdate
- Repaired the dsregcmd join state
- Reset user's password (initially thought it was password problem at first)
- Deleted device from Entra and Azure, then re-enrolled
- Added and removed Entra account from Settings > Accounts > Access work or school
- Different username login formats:
- azuread\username
- azuread******@domain.com
- azuread******@domain.onmicrosoft.com
- ******@domain.onmicrosoft.com
- .\username
- .******@domain.com
I can sync the device from Intune, but when I try to sync it under 'Access work or school', I get the error "The sync could not be initiated (0x80190190 Bad request (400). )"
And then if I try log into an M365 desktop app like Outlook and register the device, it times out after connecting with this error "Something went wrong - Error code -8951561991. Message: Number of retry attempts exceeds expectation."
Any help would be appreciated, I'm 2.5 hours in and checked many other troubleshooting articles - nothing has resolved yet.