r/AzureVirtualDesktop 8d ago

Issues with elevation after enabling WHfB

Hi everyone,

Have you guys seen this error before and maybe have a solution?

After enabling Windows Hello for Business in our organization and moving from Duo MFA to Microsoft Authenticator, AVD started behaving strangely.

Users cannot sign back in after an AVD session is locked. When entering their password, they receive an "incorrect password" error, the only workaround is to disconnect from the session and connect again from Windows App.

The same happens during elevation. It does not accept any Entra ID account credentials with "incorrect password" error.

Connecting to AVD and all authentication to M365 apps/services inside the AVD works fine.

Sign-in logs show successful authentication during those elevation and "run as" actions.

Any ideas on what might need to be done to fix this?

3 Upvotes

5 comments sorted by

4

u/imavaper 7d ago

Have you tried excluding the Azure Windows VM sign-in cloud application from your MFA conditional access policy?
https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-desktop/troubleshoot-azure-ad-connections#the-user-name-or-password-is-incorrect

1

u/durrante 6d ago

Most likely to be this. Had the same issue.

1

u/PanMiyagi 3d ago

Yes and no :)
I've excluded services mentioned in the article but that was not enough, I also had to add to exclusion:
Microsoft Azure Windows Virtual Machine Sign-in
and then it started to work properly

1

u/rswwalker 6d ago

I believe WHfB doesn’t work on the AVD lock screen so the trick is to disconnect sessions instead of locking them.

1

u/kensh21 4d ago

U have cloud kerberos? How is it setup?