User with Exchange Admin (or Global Admin) role cannot log into the Azure Virtual Desktop Workspace

Eunice Barnes 0 Reputation points
2024-01-18T18:24:00.9066667+00:00

We recently set up an Azure Virtual Desktop environment with a Personal Host Pool. All regular users can sign in using the Azure Virtual Desktop Preview desktop application. However, we have a couple of users who need either the Exchange Admin or Global Admin role assigned to their accounts. When assigning these roles, the users can no longer log into the Workspace. They are able to subscribe successfully (credentials work successfully, no errors) which then loads a SessionDesktop in the Azure Desktop Preview app. After clicking the SessionDesktop, the user is prompted for credentials again, however they receive an error: "Your credentials did not work. The credentials that were used to connect to E1_AVD_Workspace did not work. Please enter new credentials." When we remove the Exchange/Global Admin role assignment for the users, they are able to sign into the SessionDesktop successfully.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,087 questions
Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,853 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Konstantinos Passadis 19,596 Reputation points MVP
    2024-01-18T18:48:29.4666667+00:00

    Hello @Eunice Barnes !

    Welcome to Microsoft QnA!

     I suspect this is a Default Security Baseline issue with MFA

     Can you verify the Defaults are On or OFF ?

     https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults

     In case they are not , can you kindly check and provide the Conditional Access Policies that are ON ?

     Have a look on them and remove the users and recheck !

    Also go to Entra ID and check the Sign In Logs , as well as the Workspace Logs , you can activate them temporarily Kindly tell us your feedback

    I hope this helps!

    Kindly mark the answer as Accepted and Upvote in case it helped!

     Regards


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.