Cannot login to Azure Windows 11 VM from a Entra user account

Stephen Thomas Wheeler 26 Reputation points
2025-03-22T04:45:29.72+00:00

I have created an Azure Windows 11 Pro VM. I can use RDP to login using the default local username that was entered when I created the VM, but cannot login using an Entra Id user account. I have tried many, many combinations without success. I have turned off the NLA. I have tried it from a domain joined PC and a non-domain joined PC.

I have the AADLoginForWindows Extension installed and enabled

I have set the role for the domain users to Virtual Machine User Login or Virtual Machine Administrator Login

I keep getting "Your credentials did not work"

This is a really annoying issue and logging in to a Azure VM from a Entra Id user account should not be so difficult.

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
{count} votes

Accepted answer
  1. Anonymous
    2025-03-25T09:20:51.4533333+00:00

    Hi Stephen Thomas Wheeler,

    Thanks for your post. Please make sure you have enabled MDM autoenrollment, which requires Microsoft Entra ID P1 licenses. After you enable this capability, your Windows VMs in Azure will be Microsoft Entra joined. You cannot join them to another domain, like on-premises Active Directory or Microsoft Entra Domain Services. If you need to do so, disconnect the VM from Microsoft Entra ID by uninstalling the extension. In addition, if you deploy a supported golden image, be aware that you can enable Entra ID authentication installing after the deployment the dedicated extension.

    Reference: Sign in to a Windows virtual machine in Azure by using Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn

    Best Regards,

    Ian Xue


    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Marcin Policht 49,790 Reputation points MVP Volunteer Moderator
    2025-03-22T11:41:54.91+00:00

    Follow https://learn.microsoft.com/en-us/entra/identity/devices/howto-vm-sign-in-azure-ad-windows


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.