Last Friday user logged in to windows 10 PC using their Azure AD account successfully. User then was absent for one week and PC was left untouched.
This morning user is unable to login. PIN number is instantly reported as "incorrect". Password the same.
Diagnosis so far:
- We have confirmed the Anniversary Update was installed on this PC during the users absence and appears related to, if not the direct cause of, the problem.
- We have confirmed that our Azure AD is working correctly, as we are able to login using other Windows 10 PCs, as well as directly to the Azure portal.
I have managed to enable to local admin account using a registry hack. This has allowed me to see that:
- Windows reports "Your device is up to date". I'm on build Version 10.0.14393 Build 14393
There is clearly a horrible bug in Windows Anniversary Update and Azure AD, because I have found other people online complaining of this exact problem. My colleague also had a related Azure AD-Join problem after Anniversary update, indicating it might be a TPM-related issue.
My solution in the end required the following steps:
Very annoying, Microsoft.
My customer had the exact problem, I was able to login as a local administrator, and found out that the user had a Local Admin account with the same name as the Azure AD account.
Login out as the local admin, and signing in with the e-mail address of the azure-ad user solved the problem in this case.