{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
        "slug": "dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/"
        },
        "title": "Restore Microsoft Entra sign-in after a Windows VMAccess password reset",
        "summary": "What must be checked beyond local access when VMAccess resets a Windows VM password after Entra sign-in was installed?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:28+00:00",
        "modified_at": "2026-09-10T02:11:17+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 232,
        "potentially_affected": "Authorized recovery of supported Azure Windows VMs using VMAccess and Microsoft Entra sign-in, excluding domain controllers.",
        "dse_recommendation": "Include restoration of the intended Entra sign-in path in the password-recovery plan.",
        "primary_source": {
            "name": "Reset access to an Azure Windows VM - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-windows",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft directs operators to rerun the Entra Login extension after using VMAccess to reset a VM password when that sign-in extension was already installed. VMAccess grants administrative privileges to the specified account and changes Remote Desktop settings during a user update. It is not supported on domain controllers. These recovery effects extend beyond changing the password alone. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-windows\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for an authorized Windows VM recovery where Entra sign-in is part of the intended access design. Confirm the VM role and original authentication arrangement before selecting VMAccess; do not treat this as a domain-controller recovery procedure.</p>\n<h2>DSE recommendation</h2>\n<p>Include restoration of the intended Entra sign-in path in the password-recovery plan. Coordinate the local recovery step with the identity and workload owners. Record the required follow-up extension operation, the approved account, and the access paths to be tested. Keep any temporary recovery access under the same change record so it is reviewed after the intended sign-in path is restored.</p>\n<h2>Verification</h2>\n<p>After following the supported procedure, check the recovery account&#8217;s access and privileges, then test Entra sign-in using an appropriately authorized identity. Inspect the extension execution result and reconcile any Remote Desktop setting changes with the approved design. Retain sanitized evidence for both access paths. Do not declare authentication recovery complete merely because the local password reset succeeded.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-windows\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: VMAccess Extension for Windows</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft directs operators to rerun the Entra Login extension after using VMAccess to reset a VM password when that sign-in extension was already installed. VMAccess grants administrative privileges to the specified account and changes Remote Desktop settings during a user update. It is not supported on domain controllers. These recovery effects extend beyond changing the password alone. Microsoft Learn.\nApplicability\nUse this review for an authorized Windows VM recovery where Entra sign-in is part of the intended access design. Confirm the VM role and original authentication arrangement before selecting VMAccess; do not treat this as a domain-controller recovery procedure.\nDSE recommendation\nInclude restoration of the intended Entra sign-in path in the password-recovery plan. Coordinate the local recovery step with the identity and workload owners. Record the required follow-up extension operation, the approved account, and the access paths to be tested. Keep any temporary recovery access under the same change record so it is reviewed after the intended sign-in path is restored.\nVerification\nAfter following the supported procedure, check the recovery account’s access and privileges, then test Entra sign-in using an appropriately authorized identity. Inspect the extension execution result and reconcile any Remote Desktop setting changes with the approved design. Retain sanitized evidence for both access paths. Do not declare authentication recovery complete merely because the local password reset succeeded.\nOfficial references\nMicrosoft Learn: VMAccess Extension for Windows. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft directs operators to rerun the Entra Login extension after using VMAccess to reset a VM password when that sign-in extension was already installed. VMAccess grants administrative privileges to the specified account and changes Remote Desktop settings during a user update. It is not supported on domain controllers. These recovery effects extend beyond changing the password alone. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-windows).\n\n## Applicability\n\nUse this review for an authorized Windows VM recovery where Entra sign-in is part of the intended access design. Confirm the VM role and original authentication arrangement before selecting VMAccess; do not treat this as a domain-controller recovery procedure.\n\n## DSE recommendation\n\nInclude restoration of the intended Entra sign-in path in the password-recovery plan. Coordinate the local recovery step with the identity and workload owners. Record the required follow-up extension operation, the approved account, and the access paths to be tested. Keep any temporary recovery access under the same change record so it is reviewed after the intended sign-in path is restored.\n\n## Verification\n\nAfter following the supported procedure, check the recovery account’s access and privileges, then test Entra sign-in using an appropriately authorized identity. Inspect the extension execution result and reconcile any Remote Desktop setting changes with the approved design. Retain sanitized evidence for both access paths. Do not declare authentication recovery complete merely because the local password reset succeeded.\n\n## Official references\n\n[Microsoft Learn: VMAccess Extension for Windows](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-windows). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Restore Microsoft Entra sign-in after a Windows VMAccess password reset",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/",
                "headline": "Restore Microsoft Entra sign-in after a Windows VMAccess password reset",
                "description": "What must be checked beyond local access when VMAccess resets a Windows VM password after Entra sign-in was installed?",
                "abstract": "What must be checked beyond local access when VMAccess resets a Windows VM password after Entra sign-in was installed?",
                "articleBody": "Source facts\nMicrosoft directs operators to rerun the Entra Login extension after using VMAccess to reset a VM password when that sign-in extension was already installed. VMAccess grants administrative privileges to the specified account and changes Remote Desktop settings during a user update. It is not supported on domain controllers. These recovery effects extend beyond changing the password alone. Microsoft Learn.\nApplicability\nUse this review for an authorized Windows VM recovery where Entra sign-in is part of the intended access design. Confirm the VM role and original authentication arrangement before selecting VMAccess; do not treat this as a domain-controller recovery procedure.\nDSE recommendation\nInclude restoration of the intended Entra sign-in path in the password-recovery plan. Coordinate the local recovery step with the identity and workload owners. Record the required follow-up extension operation, the approved account, and the access paths to be tested. Keep any temporary recovery access under the same change record so it is reviewed after the intended sign-in path is restored.\nVerification\nAfter following the supported procedure, check the recovery account’s access and privileges, then test Entra sign-in using an appropriately authorized identity. Inspect the extension execution result and reconcile any Remote Desktop setting changes with the approved design. Retain sanitized evidence for both access paths. Do not declare authentication recovery complete merely because the local password reset succeeded.\nOfficial references\nMicrosoft Learn: VMAccess Extension for Windows. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:23:28+00:00",
                "dateModified": "2026-09-10T02:11:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-508-restore-microsoft-entra-sign-in-after-a-windows-vmaccess-password-reset/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Restore Microsoft Entra sign-in after a Windows VMAccess password reset"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 232,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Reset access to an Azure Windows VM - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-windows"
                }
            }
        ]
    }
}