Azure AD User Password Reset Not Reflected On Azure AD Joined device

Daniyal Raza 116 Reputation points
2021-08-12T12:44:45.68+00:00

Hi All,

i am stuck in a scenario can someone please help me to get out from this situation.
i am using Microsoft 365 trial version, i enrolled a windows laptop on Endpoint Manager using Bulk Enrollment method and it went successful.
Now i can login with any of the user already created on Azure AD, but when i reset the user password from Microsoft Admin Center user is still able to login with old credentials on that windows machine which i don't want in my case. i want to block the user to access the laptop with Azure AD credentials.

How can i achieve this or what should i have to do for it? Is it possible?

Looking for urgent Help.

Thanks
Daniyal

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
    2021-08-12T18:49:19.043+00:00

    This is not directly possible today as that's not how logins to an AAD joined device work (note that this is completely unrelated to Intune).

    Watch https://syfuhs.net/ops108-windows-authentication-internals-in-a-hybrid-world for lots of in-depth details on this.

    Can you expand on the use case here? What's the full scenario?


7 additional answers

Sort by: Most helpful
  1. Steve Gladden 1 Reputation point
    2022-03-17T18:28:39.093+00:00

    "conditional access" was not the answer.
    That only leads you to more "apps" and M365"
    It appears to be meant to allow or deny to "app" type resources"
    Things that are completely in the cloud.
    And virtual machines that are in the cloud.

    I'd like to know if ANY local settings can be provisioned or synced starting with the user's password at the Windows 10 computer fromn Azure AD WITHOUT added license
    or complicated apps that may do this.

    I am getting my own impression that the only way to do this is that some local app needs to be running on the machine..
    That app itself "syncs" from settings that are in Azure AD or another cloud "app" that is in the cloud,
    All of which require special additional licensing (versus free or included licensing in many business packages) and somewhat complicated setup.

    Not sure if this is correct but is one of my possible guesses/conclusions.
    And should be way overkill of a solution to centrally manage a small company's ten computer user passwords (and whether they are a local admin or not).

    0 comments No comments

  2. Nawaf Mushtaque Ahmed Mungaye 1 Reputation point
    2022-04-14T03:17:00.327+00:00

    @Jason Sandys , If I have understand correctly the problem statement , I have similar issue with my device too. Recently I have changed the password of my Azure ad account using SSPR but when I tried to login with my Azure AD device, it always prompt me wrong password, & I m able to login with old credentials.

    0 comments No comments

  3. Michel G 20 Reputation points
    2023-07-19T19:38:25.2+00:00

    How is this considered normal behavior? We've reset a user's password, we can log in with the new password online. However we're unable to log in to the user's PC, as we don't know the previous password. We can't even switch users, log in with another user on this Windows 11 Pro machine.

    What a mess!

    The "cloud" was suppose to simplify and unify management, now it's just a mess of identities everywhere, broken services.

    Please tell me what I'm doing (or expecting) wrong!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.