Hi Stephen Thomas Wheeler,
Thanks for your post. Please make sure you have enabled MDM autoenrollment, which requires Microsoft Entra ID P1 licenses. After you enable this capability, your Windows VMs in Azure will be Microsoft Entra joined. You cannot join them to another domain, like on-premises Active Directory or Microsoft Entra Domain Services. If you need to do so, disconnect the VM from Microsoft Entra ID by uninstalling the extension. In addition, if you deploy a supported golden image, be aware that you can enable Entra ID authentication installing after the deployment the dedicated extension.
Best Regards,
Ian Xue
If the Answer is helpful, please click "Accept Answer" and upvote it.