Azure AD Users cannot logon to on premises workstations

knollknows 1 Reputation point
2020-04-10T14:01:27.593+00:00

Hello,

I have setup Azure AD Connect, can validate the AD replications of users (from on prem) appear in the Azure AD portal. All 'looks well' however, I cannot seem to be able to logon with these Azure AD users. The Azure AD users that I created via the Azure Portal CAN logon to Azure AD Joined machines. These same users however, cannot logon to on premises workstations that are domain joined.

I have tried doing a password reset, validated the users can logon to portal.azure.com with password, can logon to Azure AD joined machine, but with on premises workstation, the message is 'incorrect username/password".

Thanks in advance for any/all help.

-Noel

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
12,610 questions
No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 20,431 Reputation points Microsoft Employee
    2020-05-04T18:34:56.773+00:00

    Hi Noel,

    If you have reset the passwords and the users can log into the portal but not to the on-premises machines, please ensure that password writeback is set up properly. https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback

    You'll need to enable it both in AAD Connect and in the portal if you haven't already. https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback

    If it's already enabled and you are still seeing this issue, I would suggest confirming the network connectivity, restarting the AAD Connect Sync service if needed, installing the latest AAD Connect release, and disabling and re-enabling the writeback service. There are more troubleshooting steps in this guide: https://learn.microsoft.com/en-us/azure/active-directory/authentication/active-directory-passwords-troubleshoot

    Restarting the sync service:
    7860-adconnectsyncrestart.png

    No comments