How should AzureAD auth over RDP be configured for Win11? (Win10 works, but not Win11 with identical settings)

Brandon Lashmet 0 Reputation points
2024-03-12T16:14:44.22+00:00

AzureAD auth over RDP works for Windows 10 Virtual Machines, when configured as follows:

  • NLA disabled.
  • System Managed Identity assigned to the VM.
  • Virtual Machine extension AADLoginForWindows installed on the VM.
  • Username is AzureAD\first.last@domain.com

Running dsregcmd /status on the Win10 VM shows that it is AzureAD joined, whereas running it on the Win11 VM shows that it is not, and also shows WamDefaultSet : ERROR (0x80070520).

Is something preventing the Win11 box from registering with AzureAD?

Perhaps additional security/RDP settings need to be configured?

Any help appreciated :)

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,474 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Fabio Andrade 640 Reputation points Microsoft Employee
    2024-03-26T23:24:31.4133333+00:00

    Hi @Brandon Lashmet

    I just wanted to check in and see if you had any other questions or if you were able to resolve this issue?

    If you have any other questions, please let me know.

    Thanks,

    Fabio

    0 comments No comments

  2. Fabio Andrade 640 Reputation points Microsoft Employee
    2024-03-28T21:17:11.6633333+00:00

    Hi @Brandon Lashmet

    I just wanted to check in and see if you had any other questions or if you were able to resolve this issue?

    If you have any other questions, please let me know.

    Thanks,

    Fabio

    0 comments No comments