Windows 11 25H2 PC that is Azure AD Joined will not accept RDC using Azure AD user and password.

Dennis Bowtell 20 Reputation points
2026-02-12T21:08:48.6066667+00:00

Hi,

For a lot of years our clients have worked from home by using a remote access VPN and then using RDC to connect to their office PC with their Office 365 email address and password.Recently this has stopped working, and it is causing some frustration for many of our clients.

Observations:-

  1. Local accounts are able to login with username and password over the VPN, not AzureAD accounts
  2. If the client has a company supplied laptop that is also Azure AD Joined, and they have Windows Hello set up on their laptop, they can login over RDC using Face, Finger or PIN registered to the Laptop. They just can't use the password. Most of our WFH clients use a Home PC to connect, so the Windows Hello is not appropriate.
  3. We have tried setting the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PasswordLess\Device - DevicePasswordLessBuildVersion DWORD to values 0, 1 and 2, but this has not helped.

We read about a Settings -> Accounts -> Sign In options -> Additional Settings thing called 'For improved security, only allow Windows Hello sign-in for Microsoft accounts on this device' but I can't find that anywhere. I really want to turn this option off I think.

Thanks for considering my issue :)

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-02-12T21:09:01.6+00:00

    It seems that you are experiencing issues with Azure AD accounts not being able to log in via Remote Desktop Connection (RDC) using a password, while local accounts can. This is a common issue that can arise due to various reasons, especially with recent updates and configurations in Windows 11.

    Here are a few points to consider:

    1. Passwordless Authentication: Azure AD accounts can utilize passwordless authentication methods such as Windows Hello. If users are unable to log in with their password, it might be due to the system prioritizing these passwordless methods. Since your clients are using home PCs without Windows Hello, this could be a significant factor.
    2. Group Policy Settings: Ensure that there are no Group Policy settings that restrict Azure AD account logins over RDP. Sometimes, policies can inadvertently block certain authentication methods.
    3. RDP Properties: When using the "Use a web account to sign in to the remote computer" option, ensure that the hostname matches the Azure AD device name and is network addressable. If the hostname is not resolving correctly, it could lead to authentication failures.
    4. Windows Updates: Check if there are any pending Windows updates, as updates can sometimes resolve existing issues with remote connections. Specifically, look for updates related to Azure AD and RDP.
    5. Registry Settings: Modifying registry settings can sometimes have unintended consequences. If the changes to DevicePasswordLessBuildVersion did not help, it may be best to revert those changes.
    6. Security Settings: The setting you mentioned regarding Windows Hello for Microsoft accounts could be affecting the login process. However, if you cannot find this setting, it may not be available on all devices or versions of Windows 11.

    If these suggestions do not resolve the issue, you may want to consider reaching out to Microsoft support for further assistance, as they can provide more tailored support for Azure AD and Windows 11 issues.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.