Hello @Anja Dyna ,
Yes, users can login to the VM (or over RDP) using an organizational Azure AD account when VMs are Azure AD joined (via the Account settings screen of Windows 10) even if you didn't checked the Login with Azure AD option while VM creation.
By this way users experience all AAD SSO benefits but administrator/user have to setup manually by going to account setting from Windows 10/2019 to join devices to Azure AD whereas Login with Azure AD
feature would automatically take care of all configuration needed for users Signin with the help of AADLoginForWindows extension
during VM deployment without having administrator to setup manually.
In addition to that you experience additional management features such as Azure role-based access control (Azure RBAC) policy, specify who can login to a VM as a regular user or with administrator privileges. Two Azure roles are used to authorize VM login (Virtual Machine Administrator Login / Virtual Machine User Login) when you use "Login with Azure AD" feature .
To learn more, refer :https://learn.microsoft.com/en-us/azure/active-directory/devices/howto-vm-sign-in-azure-ad-windows
Hope this helps.
------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.