How to log in to a Windows server in Azure using an AAD account?

Evgeny Lotosh 156 Reputation points

I've created a new Win2022 server in Azure. I can log in using a locally created admin account. Now I need to log in using an account in my Azure AD (the default instalce). AAD integration option was enabled in the creation wizard.

The user account has been assigned Virtual Machine Administrator Login role. However, I can't log in using these credentials. They don't work. The Security log in Windows contains "unknown user name or bad password" event.

I also can't join the server to my AAD domain. The domain name simply can't be resolved.

What should I do to access the server with AAD credentials?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,608 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,604 questions
{count} votes

4 answers

Sort by: Most helpful
  1. Evgeny Lotosh 156 Reputation points

    One more link related to the subject:

    Everything was done as described, signing in with AAD accounts is still impossible.

    1 person found this answer helpful.
    0 comments No comments

  2. Evgeny Lotosh 156 Reputation points

    OK, here seems to be the final answer. I was trying to sign in to the AAD-joined VM over RDP from my home computer (that is not joined to anything). This turned to be the root cause for the issue. When I created another Azure VM joined to the same AAD tenant, I was able to log in without any issue (UPN + password).

    1 person found this answer helpful.
    0 comments No comments

  3. James Hamil 23,216 Reputation points Microsoft Employee

    Hi @Evgeny Lotosh , have you followed this document to configure this? I assume you have as you mentioned you're having issues with the domain. Did you get any other error codes?

    0 comments No comments

  4. Evgeny Lotosh 156 Reputation points

    @James Hamil

    I saw the dociment you mentioned. However, it doesn't contain any specific steps for integrating a VM with Azure. It's just a general description of VM creation.

    The problem is, the AAD domain name can't be resolved. I can't figure out how to configure the local DNS setings to make them point to a DNS server that can resolve the name. Properties of my AAD domains (both the default one and another I created manually) don't contain any hints.

    0 comments No comments