Connect to PC joined to AzureAD via RDP

Connect to PC joined to AzureAD via RDP

avatar

Hi,

I can't seem to figure out how to connect to a PC joined to Azure AD, where I need to login using AzureAD credentials. It does not accept using my xxx@xxx.com Azure AD account.

Br,
Kenneth

All Comments (9)

avatar

Hello,

Could you post a print screen of the properties of your RDP session in RDM please.

I specially need to see the General tab where the credentials are configured.

Best regards,

Jeff Dagenais

avatar

I'm struggling with this as well but one suspects that it's a problem with RDP & Azure AD joined devices. One found this article but one suspects, like commenters have said, that it doesn't work:

https://docs.microsoft.com/en-us/windows/client-management/connect-to-remote-aadj-pc

The RDP file solution posted here does sort of work and one can embed or link the RDP file into a RDM connection but it a) opens in a separate window and b) still prompts you for the password.

https://morgansimonsen.com/2015/11/06/connecting-to-an-azure-ad-joined-machine-with-remote-desktop/

I continue to investigate but suspect some additional functionality will be needed in RDP/Windows to allow it to work in a window.

avatar

We are able to reproduce and will investigate the issue.

Stéfane Lavergne

avatar





Hi Stefane,

Can you please give us an update to this issue?

Thanks,
Kenneth

avatar

We are still investigating...


We have a VM joined to Azure AD (see image). The user that joined the machine to Azure AD can RDP in with his Azure AD credentials via a normal RDM embedded RDP session (no special flags or configuration needed).

The issue we are have is when we want login with a different user Azure AD user.

We are trying to figure out how to enable other Azure AD users RDP rights onto that machine.

Stéfane Lavergne

avatar

Good luck! Azure authentication does feel a little rushed/bolted on to Windows 10. Other tasks that would be easy with local or domain accounts seem a little bit, err, mystical with Azure AD.

avatar

1) On PC you will be connecting to in remote settings, untick "allow connections only from computers running network level authentication"

2) Devolutions properties Connection tab, remove tick from "Activate Network Level Authentication"

3) The username to login to Azure works in this format: AzureAD\darren@myemailaddres.com

I tested this just now and it works.

avatar

Now that CredSSP is in play this does not work even when choosing that in Advanced Tab does anyone else have an answer for how to get Devolutions Client to work with AzureAD joined computers ?

avatar

Hi,

You can find the solution on how to correctly disable CredSSP and modify configuration settings to connect to an Azure AD joined PC with RDP here:

https://forum.devolutions.net/topics/33207/disabling-credssp-on-rdp-is-not-working#140767

Best regards,

Marc-André Moreau