I need to connect from one hybrid-joined Windows 11 device to another over Remote Desktop without entering a password. Remote Credential Guard doesn't seem ideal because, after connecting, applications such as Outlook, Teams, and OneDrive may still require separate Entra ID or Microsoft 365 authentication on the remote computer. We also want to avoid certificate-based Windows Hello for Business, smart cards, and FIDO2 security keys. Is there another native way to achieve passwordless authentication over RDP in this scenario?
3 Answers
Try the Remote Desktop client’s Advanced option called “Use a web account to sign in to the remote computer.” This enables web-account authentication, commonly configured with `enablerdsaadauth:i:1`. Connect using the target computer’s Entra-registered DNS hostname rather than its IP address. For hybrid-joined devices, the setup may also require an Azure AD Kerberos Server object for the domain.
As far as native Windows RDP goes, web-account sign-in appears to be the only realistic passwordless route in this situation. It generally depends on the device being cloud-managed or hybrid joined and connecting by DNS name. Once certificate-backed Windows Hello, smart cards, and FIDO2 are excluded, there doesn’t seem to be another clean built-in option.
Remote Credential Guard can provide single sign-on for the RDP authentication itself, but it doesn’t necessarily pass that sign-in through to applications running inside the remote session. You may still need to authenticate separately to Microsoft 365 apps on the remote device, so it doesn’t fully solve the broader passwordless experience.

I tested web-account sign-in, but it failed with an error suggesting that the Azure AD Kerberos Server object might not exist for the domain.