question

ChrisParker-0685 avatar image
0 Votes"
ChrisParker-0685 asked ChrisParker-0685 answered

Can't login with AzureAD Virtual User role

Hi all.

I have enabled login with AzureAD Credentials when setting up my vms but continue to have trouble logging in with anything other than the local admin account "Admin".

A little insight on my environment. Connecting to devices over the Azure VPN Client.
VM's only have private IPs. I have added other azure ad account access to the VMs by using the " net localgroup "Remote Desktop Users" /add "AzureAD\test@domain.com" In addition to that I have also edited the RDP client to include "enablecredsspsupport:1:0" and "authentication level :i:2". There isn't any NSG attached to the vm to interfere.

I can login with one azuread account but it is a global admin. It only works when using the the windows hello pin. When trying to use just the credential it fails to connect to the vm client over rdp or bastion. All azuread users have the "Virtual Machine User Login" added through IAM of the VM. These are Windows 10 2004 gen2 VMs. Login with AzureAD credentials was selected when creating the devices.110689-rdp-in-notepad.png110711-rdp-windows-security-screen.png110721-rdp-failed-login-pin-prompt.png110690-remote-desktop-users-screen.png


azure-ad-authentication
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @ChrisParker-0685,
Just checking in to see if the below answer helped. If this answers your query, please don’t forget to click "Accept the answer" and Up-Vote for the same, which might be beneficial to other community members reading this thread. And, if you have any further query do let us know.
Thanks,

0 Votes 0 ·
ChrisParker-0685 avatar image
0 Votes"
ChrisParker-0685 answered

110654-dsregcmd-1.png110693-dsregcmd-2.png



dsregcmd-1.png (3.7 KiB)
dsregcmd-2.png (20.1 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

sikumars avatar image
3 Votes"
sikumars answered JamesTran-MSFT commented

Hello @ChrisParker-0685,

Thanks for reaching out.

Could you please confirm if allow Public Key Cryptography Based User-to-User (PKU2U) authentication requests to use online identities option is enabled on both system client as well on remote ?

also check disabling NLA (Network Level Authentication) on remote system after include "enablecredsspsupport:1:0" and "authentication level :i:2" in RDP file would help with success ?

111414-image.png

Here is supported configurations for remotely connecting to an Azure AD-joined PC: https://docs.microsoft.com/en-us/windows/client-management/connect-to-remote-aadj-pc

More information, refer Connect to remote Azure Active Directory-joined PC

Hope this helps.


Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


image.png (215.6 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@ChrisParker-0685
I just wanted to check in and see if you had any other questions or if you were able to resolve this issue?

If you have any other questions, please let me know.
Thank you for your time and patience throughout this issue.


Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

0 Votes 0 ·
ChrisParker-0685 avatar image
0 Votes"
ChrisParker-0685 answered

Sorry for the delay @JamesTran-MSFT

Unfortunately this didn't work completely. I can login with some azuread users but some I can't.
For example the christopher account can login only when using windows hello authentication. If trying to use actual azureAD password the connection does not work. I can login with the mano account using azure credentials when located in the USA but user mano can't login when located in INDIA for example.

Additional issues I run into with this setup. When adding AzureADusers to local admin they disappear after reboot or signoff.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.