EntraID (add) joined VM on Azure cannot login

Razzi29 336 Reputation points
2023-11-01T15:46:42.79+00:00

Hope someone can help shine a light here... I provisioned a a few Windows 11 VMs on Azure; and created them natively Azure joined (AD is not an option, only ADD here). I can see that the Extensions blade that addLoginforWindows is enabled/ installed. I added the Virtual Machine Admin Login role and added my account to the RG. I can see all the settings are right, but when I try to RDP using my ADD UPN is saying login failure. I then logged in to the VM with a local user and I verified is ADD joined there. What am I missing?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,040 questions
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} vote

3 answers

Sort by: Most helpful
  1. Alan Kinane 16,951 Reputation points MVP Volunteer Moderator
    2023-11-01T21:53:47.8666667+00:00

    Have a read of this page in full: https://learn.microsoft.com/en-us/windows/client-management/client-tools/connect-to-remote-aadj-pc

    The below section might be the issue.

    User's image


  2. Prrudram-MSFT 28,281 Reputation points Microsoft Employee Moderator
    2023-11-03T09:43:49.99+00:00

    Hi Razzi29,

    Thank you for providing the feedback. We noticed that you rated an answer as not helpful. To make this a positive experience for you, I am providing some debugging steps that will help with your issue.

    Recommendations:

    1. From your verbatim, I understand that you have created the VMs with AAD login enabled like shown in the belowUser's image
    2. Then, before you log in to the VM by using your Microsoft Entra credentials, you have followed configure role assignments steps and assigned "Virtual Machine Administrator Login" to the Virtual Machine resource. Detailed Steps: https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal?tabs=delegate-condition
    3. After that, you followed the steps from this? https://learn.microsoft.com/en-us/entra/identity/devices/howto-vm-sign-in-azure-ad-windows#log-in-using-passwordlimited-passwordless-authentication-with-microsoft-entra-id
    4. For your Microsoft Entra registered Windows 11 PC, you must enter credentials in the AzureAD\UPN format (for example, AzureAD\******@contoso.com). At this time, you can use Azure Bastion to log in with Microsoft Entra authentication via the Azure CLI and the native RDP client mstsc.

    If you have completed all the above without a miss, then it may not be an issue in configuration. However, you can check the below article one more time and make sure all the settings are suitable, https://learn.microsoft.com/en-us/entra/identity/devices/howto-vm-sign-in-azure-ad-windows#configure-role-assignments-for-the-vm

    If you still get the same issue, I recommend you open an azure support case. If you don't have the ability to open a technical support ticket, please let me know and I can help you further with this.

    If you are satisfied with the answer, please "Accept as Answer" and give a thumbs up, so that you can help others in the community looking for remediation for similar issues.

    0 comments No comments

  3. Brett Hacker 0 Reputation points
    2024-04-23T02:20:15.1533333+00:00

    It doesn't address the issue. All of these steps are followed, the machine has an FQDN, I can successfully authenitcate to the web login interface. The next screen, every time, is CAA20002 / AADSTS293004. On MY machine, I don't see an option for AAD join in settings, only to add a work/school account. I've done this. I've tried AzureAD/FullName (what shows up in the settings panel after adding), and also AzureAD/UPN, and also simply UPN. Auth every time, fail with these errors every time.

    The documentation is horrible.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.