Share via

Entra ID login not appear in Bastion for Windows Server 2025

Talaiti AIHAIMAITI 20 Reputation points
2026-04-27T06:13:53.5666667+00:00

Hi,
I applied Entra ID VM login to Windows Server 2025, but it is not shown in Bastion, Even if:

  • VM is Entra ID joined ✅
  • RBAC roles are correct ✅
  • Bastion networking works ✅ This seems platform support gap, not a configuration issue. For migrating from local account VM login to Entra ID, what would you suggest? and how to fix current issue mentioned above.
    Thanks for your attention.
Azure Bastion
Azure Bastion

An Azure service that provides private and fully managed Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to virtual machines.


Answer accepted by question author

  1. Alex Burlachenko 20,825 Reputation points MVP Volunteer Moderator
    2026-05-05T15:00:57.35+00:00

    Talaiti AIHAIMAITI hi

    just a simple and quick answer. VM config can be fine, Bastion UI/support just hasnt caught up yet & yeah this is likely platform support gap, not ur config. Bastion Entra ID login support is not always available for every new Windows Server image right away, and Windows Server 2025 may not be fully lit up in Bastion UI yet even if the VM itself is Entra joined and RBAC is correct. For now, use local admin or domain account through Bastion, or use normal RDP with Entra login where supported. For migration, dont remove local break-glass admin yet. Keep local admin disabled/rotated but available for recovery, assign Virtual Machine Administrator Login / Virtual Machine User Login, verify Entra login works outside Bastion first, then move users gradually. If Bastion still does not show Entra option only on Server 2025, open support and ask for Windows Server 2025 + Bastion Entra login support confirmation.

    rgds, Alex

    &

    if my answer helps pls accept it.
    

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. TP 156.6K Reputation points Volunteer Moderator
    2026-04-27T08:26:41.1233333+00:00

    Hi,

    I did quick test and was able to connect to [smalldisk] Windows Server 2025 Datacenter Azure Edition VM using Bastion and Entra ID.

    1. If you haven't already, please enable system-assigned managed identity for your vm. You may do this by navigating to the vm in the Azure portal, on left click on Security -- Identity, set Status to On, Save.

    2. Next click on Setting -- Extensions + applications. Click Add, next click on Azure AD based Windows Login, click Next, click Review + create, Create

    User's image

    3. Once the extension has completed installing, wait a few minutes and then click on Connect -- Bastion. You should see Microsoft Entra ID (Preview) option, similar to below screenshot:

    User's image

    For reference, documentation shows Windows Server 2022 or later is supported. Screenshot excerpt below:

    User's image

    Please reply back with your results, whether positive or negative.

    Please click Accept Answer and upvote if the above was helpful.

    Thanks.

    -TP

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.