A cloud-based identity and access management service for securing user authentication and resource access
AzureAD user can not login to RDP on Windows 11Pro
Can not login to windows 11 pro using RDP with azure email.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
-
Anonymous
2025-10-07T02:50:26.4033333+00:00 Hello Erik Golias
Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
- Is the device Azure AD (Entra ID) joined, and does the account used for RDP have the correct format (such as AzureAD******@domain.com or ******@domain.com)? - https://learn.microsoft.com/en-us/windows/client-management/client-tools/connect-to-remote-aadj-pc
- Has the Azure AD user been added to the local “Remote Desktop Users” group or provided the necessary VM login role (such as “Virtual Machine Administrator Login” or “Virtual Machine User Login”)?
- What is the exact error message displayed during the failed RDP login attempt (“credentials did not work,” “logon attempt failed,” etc.) ?
Regards
Himanshu
-
Erik Golias • 0 Reputation points
2025-10-07T13:37:28.85+00:00 Hi Himanshu
My Windows11 Pro PC is connected to AzureAD
I can Login to PC with my azureAD email ******@......com and PIN which I created on setup.
I have user AzureAD\iPads in my Remote Desktop Users list
When I try to RDP to PC it is asking for User and Password and can not pass this screen. I'm entering my AzureAD\iPads user password.
This is what I get.
I can not login to RDP.
-
Anonymous
2025-10-08T05:33:32.92+00:00 Hello @Erik Golias IP address can't be used with Use a web account to sign in to the remote computer option. The name must match the hostname of the remote device in Microsoft Entra ID and be network addressable, resolving to the IP address of the remote device.
There're ways to resolve the issue:
Modify the HOSTS entry on client machine, add an A DNS record which pointing the correct device name (confirm from AAD Device record) to the IP of target machine. Use that device name in mstsc.
- Check if the target machine is managed and if the hostname is set through Group Policy or MDM via the [DNS Client PrimaryDnsSuffix value] If this is set and is incorrect, it needs to be removed or set correctly. The dsreg client gives precedence to this value compared to the value set. https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-admx-dnsclient#dns_primarydnssuffix
- When customer requires to use FQDN to connect but AAD Device name is a short name, login to the target machine via local admin, add a “Primary DNS Suffix” for their domain suffix. Detailed instructions: Navigate to Advanced System Settings/System Properties -> Computer Name tab -> Click the "Change" button to rename the computer -> Click "More..." under the existing computer name -> Type in your domain name and click OK -> Save and reboot. Once it’s done, we can RDP with FQDN directly and no need to modify the HOSTS entry.
Note: In such case, when Primary DNS Suffix is added, the Device-Sync scheduled task will be triggered which adding the FQDN into AAD device "hostnames" attributes. This is why it will resolve the issue.
Please let us know if you need more assistance. Thanks
-
Erik Golias • 0 Reputation points
2025-10-08T23:37:09.2266667+00:00 Hi.
I’m connecting to PC in my office from home. I will VPN to office network and after I will RDP to my office pc. I can ping IP of office pc but I can not connect to pc with PC’s name.
PC name is WS04-ErikPres
how can I RDP to it?
-
Anonymous
2025-10-09T06:44:23.3333333+00:00 Hello @Erik Golias
I understand that You’re trying to RDP into a Windows 11 Pro machine that is Entra joined, but the credentials fail even though you can log in locally with a PIN.
- The PC is connected to Entra ID
- You have AzureAD\iPads in the Remote Desktop Users group.
- RDP prompts for username/password, not PIN.
- Error says: Remote machine is AAD joined. Try using your work email address
As per the screenshot, we might suspect that this might happen due to the MFA related error.
If you configure a legacy per-user Enabled/Enforced Microsoft Entra multifactor authentication setting and you see the error, you can resolve the problem by removing the per-user MFA setting. For more information, see the article Enable per-user Microsoft Entra multifactor authentication to secure sign-in events.
Kindly refer the below document for the reference: https://learn.microsoft.com/en-us/entra/identity/devices/howto-vm-sign-in-azure-ad-windows?pivots=identity-extension-vm#mfa-sign-in-method-required
Please let us know if this helps or need more assitance.
-
Aditya N • 3,890 Reputation points • Microsoft External Staff • Moderator
2025-10-13T09:32:10.29+00:00 Hello @Erik Golias
Please could you let us know whether you had a chance to look into my associate's recommendation. Please feel free to reach out to us if you need assistance.
-
Erik Golias • 0 Reputation points
2025-10-15T00:34:25.8433333+00:00 Hi.
we need to use MFA for user which needs to connect to RDP
-
Aditya N • 3,890 Reputation points • Microsoft External Staff • Moderator
2025-10-22T17:23:31.8566667+00:00 Hello @Erik Golias
Apologies for delayed response. If you need MFA directly on RDP, you can use one of these options:
- MFA through VPN login (authenticate before connecting to your office network), or
- Install the NPS Extension for Azure MFA or use RD Gateway to enforce MFA before the RDP session starts.
I see from your comments that you're using VPN, please could you try the above once and let us know.
Providing the official documentation link below.
https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-nps-extension-rdg
-
Aditya N • 3,890 Reputation points • Microsoft External Staff • Moderator
2025-10-23T14:11:54.2333333+00:00 Hello @Erik Golias
Please could you let us know if you had a chance to visit my response. Please let us know if you need any assistance,
Sign in to comment