Share via

Unable to authenticate from on-premise network to Azure VM server that has joined Microsoft Entra Domain Services.

Mic Wang 王傳邦 0 Reputation points
2023-10-22T16:45:03.5566667+00:00

Hi Azure Expert,

I had recently created "Microsoft Entra Domain Services" in our azure environment.

I had also done AAD user password reset (So it would do password synced to Domain Services), and performed hash sync so on-premise AD -> AAD -> Domain Services will have all password synced.

I have created two test Azure VM (One Server, and One Computer), and they can joined to ADDS and login using ADDS user account (synced from on-premise AD) without any problem.

Here is my problem:

I can RDP to these two VM from their own VM environment and do 445 file sharing successfully, but when I want to RDP from on-premise computer to these two VM, I am getting message saying either username or password are incorrect. I use both UPN or domain\username methods without success.

Our on-premises network and azure network are connected via S2S vpn, and there is no FW policy from on-premises network to azure network. All FW in this to VMs are turned off.

User's image

My question is:

  1. How can I RDP to AADDS joined computers from on-premises network?
  2. How can I Join on-premises computers to AADDS?
  3. How can I access port 445 to AADDS joined computers from on-premises network?

I think above three questions can be solved by one solution, but I don't know what to do to resolve, and hopfully get a help from expert.

Thank you.

Mic

Microsoft Security | Microsoft Entra | Other

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.