AzureADPrt showing NO

adil waaziz 20 Reputation points
2025-06-02T08:46:43.4866667+00:00

Hello,

I'm configuring Hybrid Joined for a Windows 11 fleet, the machines are Hybrid Joined but when I run a dsregcmd /status I get the AzureADPrt field in No and the error code 0x800484c0

My domain is federated with Omnissa's Vmware Identity

Do you have any idea where this problem might be coming from?

User's image

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Kancharla Saiteja 5,890 Reputation points Microsoft External Staff Moderator
    2025-06-03T22:08:14.9333333+00:00

    Hi @adil waaziz,

    Based on your query, here is my understanding: I see that you are unable to get PRT for your device and receives the code: 0x800484c0.

    Based on the error, we can confirm that you are trying to login to the device using a federated user which throws this error when the IDP is unable to provide token for the device login. This attempt fails when wstrusttokenresponse fails from the third party IDPs. We have seen many scenarios of the same which occurs due to third party federated IDP's endpoints which are not open or enabled. I would request you to check with your IDP team and check all the ports and endpoints from the IDP are open and available to provide token for device login. There is no issue with Entra here to retrieve PRT for your device.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly "upvote it". If you have extra questions about this answer, please click "Comment".


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.