# Plan remote-session locking behavior for Entra-authenticated RDP

> What happens when a remote session using Microsoft Entra authentication is locked?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-085-plan-remote-session-locking-behavior-for-entra-authenticated-rdp/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:46+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

What happens when a remote session using Microsoft Entra authentication is locked?

## Potentially affected

Administrators assessing Microsoft Entra authentication in Remote Desktop Connection.

## DSE recommendation

Include the disconnect-on-lock behavior in the pilot instructions and support notes.

## Article

## Source facts

Remote Desktop Connection supports single sign-on through Microsoft Entra authentication. The client option to use a web account for remote sign-in corresponds to the enablerdsaadauth RDP property. Microsoft states that the remote Windows lock screen does not accept Entra tokens or passwordless methods such as FIDO keys. Attempting to lock such a session disconnects it instead, with a message explaining the disconnection. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/remote-desktop-connection-single-sign-on).

## Applicability

Check both computers against the documented operating-system and update prerequisites. Review the intended account, device join state, remote access permissions, and any policy that locks inactive sessions before assessing this sign-in route.

## DSE recommendation

Include the disconnect-on-lock behavior in the pilot instructions and support notes. Ask the application owner to define an acceptable reconnect experience, including any unsaved work concerns. Review the actual session-lock policy with the endpoint team and identify who will investigate failed reconnections.

## Verification

Test initial sign-in, a deliberate lock attempt, a policy-triggered lock, and the subsequent reconnect using a representative account. Record the actual client setting, user-visible messages, and application state after reconnecting. Keep each authentication method tested separate so success with one method is not recorded as proof for all methods.

## Official references

[Microsoft Learn: Connect to a Remote PC with Single Sign-On Using Microsoft Entra Authentication](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/remote-desktop-connection-single-sign-on). Source reviewed September 8, 2026.

## Primary reference

- Name: Connect to a Remote PC with Single Sign-On Using Microsoft Entra Authentication
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/remote-desktop-connection-single-sign-on
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan remote-session locking behavior for Entra-authenticated RDP,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-085-plan-remote-session-locking-behavior-for-entra-authenticated-rdp/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
