Unable to log into the "Autopilot (Entra Joined) device" using a "Hybrid Entra user account". When attempting to log in, it shows the error: **Password is incorrect.**

Chadwick Jerington 0 Reputation points
2025-02-24T19:14:06.1933333+00:00

Hi,

Recently, we wanted to onboard users using Autopilot. Initially, we planned to use Hybrid Join instead of Entra Join. However, due to its complexity, we opted for Entra Join instead.

Our organization primarily relies on an on-premises server to grant access to shared drives, and most user accounts are created on this server. We have set up Azure AD Connect to synchronize existing on-premises objects with the cloud. For cloud sign-ins, we use DUO mfa, which is configured on our ADFS server.

Here's what happened:

  1. I created a user account on our on-premises server, and since our domain is federated with ADFS, I used that account to log into an Autopilot-enrolled device (with an Entra Join profile).
  2. Initially, everything worked fine. The apps and policies were installed successfully, and I was able to log in with MFA during the OOBE (Out-of-Box Experience) process.
  3. After reaching the desktop, I checked Settings > Accounts > Access work or school, and it confirmed that the account was joined to the Entra ID domain.
  4. I performed a sync, and the account successfully synced with Entra ID.

However, after some time, when I locked the screen and tried to log back in, I received a "password is incorrect" error.

  • I restarted the computer multiple times.
  • I reset the password three times.
  • Despite these attempts, I was still unable to log in with that user account.

Interestingly, when I logged in using my Global Administrator account, I was able to access the device without any issues. Checking Settings > Accounts confirmed that the device was joined to the Entra ID domain but with the current admin credentials. The previous user credential, completely vanished. To test, I then locked the device and successfully unlocked it without encountering any errors from the admin account. I tried to log into the previous user credentials but it said "username or password is incorrect". I swear the credentials I entered is correct, i checked both the UPN on AD and Entra.

Despite this, I am still unable to log in with the original user account that was used during onboarding. The account appears in the Entra Admin Center when I search for users, but I just can't sign in with it on the device.

Can anyone help me understand what might be causing this issue? Your assistance would be greatly appreciated.

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,434 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 52,321 Reputation points Microsoft Vendor
    2025-02-25T01:25:07.2933333+00:00

    @Chadwick Jerington, Thanks for posting in Q&A. For Microsoft Entra joined device, it can allow any Microsoft Entra user to login. From the information you provided, I know global administrator can login successfully. But the user UPN can't login with "password incorrect error". I think the issue is with the user account.

    To double confirm with this, please login the affected user account to Intune portal or Microsoft Entra portal to see if it will get the same error.

    If it is failed, then please check the following information:

    1, Check Account Synchronization: Ensure that the user account is properly synchronized between your on-premises AD and Entra ID. Sometimes, synchronization issues can cause login problems. You can verify this by checking the synchronization status in Azure AD Connect.

    2, Check Password Hash Synchronization: Make sure that password hash synchronization is enabled and functioning correctly. If the password hashes are not synchronized, the user might not be able to log in

    3, ADFS Configuration: Since you're using ADFS for federation, ensure that the ADFS configuration is correct and that the user account is allowed to authenticate via ADFS. Sometimes, issues with ADFS can cause login problems.

    4, Account Lockout: Ensure that the user account is not locked out. This can happen if there are multiple failed login attempts

    Please check the above information and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.