A cloud-based identity and access management service for securing user authentication and resource access
Azure VM won't allow AzureAD accounts to login. Local account works fine.
I’ve created two virtual machines: one with Windows 2025 and the other with Windows 2022. Neither of them allows me to log in using our Azure AD accounts. I’ve followed all the suggestions provided by the AI, but it still won't work.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
-
VEMULA SRISAI • 13,985 Reputation points • Microsoft External Staff • Moderator
2025-10-22T19:32:30.2033333+00:00 Hello Eric De La Garza,
Thank you for posting your question in the Microsoft Q&A Forum.
I understand you’re unable to log in to your Azure VMs using Microsoft Entra ID (Azure AD) accounts. Here are the key checks to resolve this:
- Enable Entra ID Login
In Azure Portal → VM → Settings → Login with Microsoft Entra ID, make sure it’s turned ON.
- Verify Extension
Go to Extensions + applications.
Confirm AADLoginForWindows shows Provisioning succeeded.
If not, uninstall and reinstall the extension.
- Assign RBAC Roles
In Access control (IAM), assign:
Virtual Machine Administrator Login
Virtual Machine User Login
- Use Correct Login Format
For RDP, use:
AzureAD******@domain.com
- OS Support
Windows Server 2022/2025: Direct Entra ID login works only for Azure VMs.
For non-Azure VMs, configure Hybrid Join via Microsoft Entra Connect.
If you've already tried these steps and it’s still not working, it might be helpful to provide some additional details:
- Are you receiving any specific error messages when trying to log in with Azure AD accounts?
- Have you checked if the Azure AD accounts have permissions assigned correctly in the Azure portal?
- Could you share how the virtual machines were configured during the setup?
I hope these suggestions help you troubleshoot the issue! If you have any more questions or need further assistance, feel free to ask.
-
VEMULA SRISAI • 13,985 Reputation points • Microsoft External Staff • Moderator
2025-10-23T22:00:03.6466667+00:00 Eric De La Garza did you verify that Login with Microsoft Entra ID is enabled, the AADLoginForWindows extension succeeded, and the correct RBAC roles are assigned?
-
Eric De La Garza • 5 Reputation points
2025-10-24T14:48:05.7033333+00:00 I've been able to get RDP from a mac to work, but RDP from windows does not. Before it would work on the mac, the error message indicated that NLA needed to be turned off on the physical later of the azure VM. So I did that and it started working. It still does not work on any windows RDP client. The only errors on a windows rdp is bad credentials.
Given that it works from the mac, I assume that the for the most part the azure side of things is configured correctly.
I then moved to installing a SQL server only to find out that entra authentication isn't available by default. I've added sql 2022 on my VM and then added an azure sql instance. Niether works.
In the end, I need ALL authentication to be from Entra, ie sql access and I have a service that needs to run as an entra user.
In your comment, item 1, i don't see any settings to 'turn on' that would allow entra logins? When i provinsioned the VMs I clicked the option to allow this, but I don't see it on the settings.
There is no way this should be so difficult.
-
VEMULA SRISAI • 13,985 Reputation points • Microsoft External Staff • Moderator
2025-10-25T00:42:57.02+00:00 Thank you for your follow-up and response. For further assistance, please share details with us via private message only (do not post publicly)
-
Ohad Levi • 0 Reputation points
2025-11-04T15:13:18.0033333+00:00 That also for from MacOS, VMs that works fine now cant RDP from Windows App RDP tool
-
Anonymous
2025-11-13T07:30:15.5333333+00:00 Hello Eric De La Garza,
Could you please check below:- Per-user MFA: Ensure the user isn’t enabled or enforced for per-user MFA.
- Conditional Access: If MFA is required by a policy, exclude the app “Microsoft Azure Windows Virtual Machine Sign-in” (App ID: 372140e0-b3b7-4226-8ef9-d57986796201).
- Device Requirement: Remote connections to Entra ID–joined VMs are allowed only from Windows 10+ PCs that are Entra registered, joined, or hybrid joined to the same directory.
Refer to below docs for more understanding:
Sign in to a Windows virtual machine in Azure by using Microsoft Entra ID
If MFA isn’t enabled through per-user or Conditional Access but login still fails, check if Security Defaults are on. These enforce MFA for Global Admins, preventing VM sign-in. Workaround: create a new Global Admin and backup admin account, then remove the Global Admin role from your main account.
If you are still unable to sign in to the VM using Entra ID credentials, please share your email address and availability for a call over private message, and I’d be happy to assist you further.
Hope this helps!
Regards,
Monalisha
-
Anonymous
2025-11-18T12:15:40.33+00:00 Hello Eric De La Garza,
Could you please provide an update on this post?Kindly let us know if the below helps or you need further assistance on this issue.
-
Eric De La Garza • 5 Reputation points
2025-11-20T17:29:14.1633333+00:00 We've been able to get RDP working from various clients but I still cannot get a service to run using Entra credentials nor can get SQL users to work. I'll review the info you added here on 11/13 and then post back.
Sign in to comment