I need to connect from one hybrid-joined Windows 11 device to another using RDP without entering a password. Remote Credential Guard doesn't seem sufficient because, although it can authenticate the RDP session, applications such as Outlook, Teams, and OneDrive on the remote computer may still require separate Entra ID or Microsoft 365 authentication. We also want to avoid certificate-based Windows Hello for Business, smart cards, and FIDO2 security keys. Is there another native way to achieve passwordless authentication over RDP in this setup?
3 Answers
Other than web-account sign-in, there doesn’t appear to be a native passwordless RDP method once certificate-backed Windows Hello, smart cards, and FIDO2 are excluded. Remote Credential Guard can provide single sign-on for the RDP authentication itself, but it does not generally pass the user’s Entra or Microsoft 365 sign-in through to applications running inside the remote session.
The web sign-in approach is essentially the remaining built-in option. It works only when the target can be properly identified as an Entra or hybrid-joined device, so use its DNS name rather than an address. If that setup cannot be completed, separate authentication on the remote device is likely unavoidable.
Try Microsoft Remote Desktop’s Advanced option called “Use a web account to sign in to the remote computer.” In the .rdp file this is enabled with `enablecredsspsupport:i:0` and `enablerdsaadauth:i:1` depending on the client configuration. Connect using the target device’s Entra-registered DNS hostname rather than an IP address. Hybrid-joined targets can support this, but the environment may need an Azure AD Kerberos Server object configured for the domain.

I tested the web-account sign-in option, but it failed with an error suggesting that an Azure AD Kerberos Server object had not been created for the domain.