Azure Virtual Desktop Web Client – Sign-in Failed After Successful Entra ID Authentication (AzureADJoined VM)

SB 0 Reputation points
2025-10-04T06:34:08.3433333+00:00

Hello Azure Community,

I’m currently facing a persistent sign-in failure issue when connecting to my Azure Virtual Desktop (AVD) environment. The initial web client login (via https://client.wvd.microsoft.com/arm/webclient) succeeds using Microsoft Entra ID SSO, but when the connection is redirected to the session host, it fails with the message:

“Sign-in failed. Please check your username and password and try again.”


Environment Details

Deployment Type: Azure Virtual Desktop (pooled host pool)

Join Type: Entra ID joined (not hybrid)

VM OS: Windows 11 (non-ARM)

Host Pool Name: HP-Lab-internal

Users: ******@unieyes.in, ******@unieyes.in

Licenses: Microsoft 365 Business Premium + Entra ID P2

Access Method: Web client

Region: East US


Diagnostics (dsregcmd /status output summary)

AzureAdJoined: YES

EnterpriseJoined: NO

DomainJoined: NO

AzureAdPrt: NO

DeviceAuthStatus: SUCCESS


Troubleshooting Performed

Confirmed that users have valid Microsoft 365 Business Premium + Entra ID P2 licenses.

Verified RDP Properties – tested both with and without Microsoft Entra single sign-on.

Added users to Remote Desktop Users group on session host.

Disabled MFA enforcement for affected users.

No active Conditional Access Policies enforcing MFA or device restrictions.

Re-ran dsregcmd /join (successful device join).

Checked Sign-in Logs → shows MFA failure (AADSTS50076 or interaction_required) or status 52006 (credential prompt failed).



Request for Help

Can anyone help me identify why AVD Entra ID–joined session hosts fail at credential handoff even though:

Device registration and join state are successful, and

SSO works at web login, but RDP credential exchange fails?

Is this related to missing Entra Primary Refresh Token (PRT), MFA token handoff, or RDP properties configuration (CredSSP / Entra SSO)?Hello Azure Community,

I’m currently facing a persistent sign-in failure issue when connecting to my Azure Virtual Desktop (AVD) environment. The initial web client login (via https://client.wvd.microsoft.com/arm/webclient) succeeds using Microsoft Entra ID SSO, but when the connection is redirected to the session host, it fails with the message:

“Sign-in failed. Please check your username and password and try again.”

Screenshot {A574EC0F-CE63-4630-A0F6-6C918A84FB9E}

{59177957-09F9-4843-BA08-489818326EE3}

{56B188CC-7408-48FB-89C4-4D87BF8A08CE}

{1745F61D-1F63-4C53-A104-31345BA18D31}

{A487B1B5-0CD7-49D4-8A96-C62A4A2B3CF7}


Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.