Azure AD Device Registration Failure: SCP Discovery Error (0x801c001d) Causing M365 Sign-In Loop on RDS Host

Chris Osborn 0 Reputation points
2026-09-28T22:12:22.7333333+00:00

roblem

Users on a Windows RDS host are stuck in a continuous M365 sign-in loop — error 53000, device compliance issue. Sign-in log Conditional Access details show a "Require Compliant Device" policy is the cause: everything matches except device compliance, since the device is workplace-joined only and never MDM-enrolled. Separately, dsregcmd /status shows a device registration discovery failure (SCP discovery error 0x801c001d). Unsure if these two are related or independent. Environment

Windows Server VM, RDS host, Azure Central US Stable for 3+ years, workplace-joined ("Registered") since 2022 Domain-joined to Microsoft Entra Domain Services (AADDS) — no Azure AD Connect / on-prem AD

What I've tried

dsregcmd /status (non-elevated + elevated/SYSTEM) — consistent both times:

AzureAdJoined: NO, AzureAdPrt: NO AD Configuration Test: FAIL [0x80070002] Error Phase: discover, Client ErrorCode: 0x801c001d

User Device Registration event log — Windows Hello for Business events say AAD joined: Yes, conflicting with dsregcmd's NO. Can't explain the discrepancy. Queried the SCP object directly in the AADDS domain — object doesn't exist in the forest's configuration partition. Ruled out: recent CA policy changes, DNS/connectivity to all relevant MS endpoints, reboot/patch history, time sync, RDS licensing. Found the exact CA policy via sign-in logs. Its last modification predates this issue by ~12 weeks — can't confirm a causal link (audit retention doesn't go back that far). Interim fix: excluded the affected device from the CA policy to restore access. Took a VM disk snapshot before making changes.

Questions

Is a missing SCP object expected/normal in an AADDS-only environment (no AD Connect)? If it should exist — does Microsoft provision it, or do we configure it manually? Is manual creation safe in AADDS? Is the SCP failure related to/causing the CA compliance failure, or are they independent? What's the right long-term approach for an RDS host that's workplace-joined but never MDM-enrolled, since it can't natively satisfy "compliant device"?

Goal: Restore reliable device registration and M365 sign-in, and understand root cause well enough to prevent recurrence.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.

    1 deleted comment

    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.