Enabling Microsoft Entra authentication for RDP
If you log on to an Entra-joined session host for the first time (or again after a while), you will be asked if you trust the specific session host:
Figure 8.14 – Allow the connection to a specific host
Entra will remember the decision for 15 individual hosts for up to 30 days. This can be annoying in a multi-user pool, where a user gets another host each day. Fortunately, there is a solution to prevent this behavior.
We can create a dynamic device group containing our session hosts and configure this Entra to no longer ask this question to users.
We will start creating a group in Entra with the following settings:
Configuration |
Value |
Security type |
Security |
Group name |
Name of the group (e.g., |