A cloud-based identity and access management service for securing user authentication and resource access
Azure AD Device Registration Failure: SCP Discovery Error (0x801c001d) Causing M365 Sign-In Loop on RDS Host
roblem
Users on a Windows RDS host are stuck in a continuous M365 sign-in loop — error 53000, device compliance issue. Sign-in log Conditional Access details show a "Require Compliant Device" policy is the cause: everything matches except device compliance, since the device is workplace-joined only and never MDM-enrolled. Separately, dsregcmd /status shows a device registration discovery failure (SCP discovery error 0x801c001d). Unsure if these two are related or independent.
Environment
Windows Server VM, RDS host, Azure Central US Stable for 3+ years, workplace-joined ("Registered") since 2022 Domain-joined to Microsoft Entra Domain Services (AADDS) — no Azure AD Connect / on-prem AD
What I've tried
dsregcmd /status (non-elevated + elevated/SYSTEM) — consistent both times:
AzureAdJoined: NO, AzureAdPrt: NO
AD Configuration Test: FAIL [0x80070002]
Error Phase: discover, Client ErrorCode: 0x801c001d
User Device Registration event log — Windows Hello for Business events say AAD joined: Yes, conflicting with dsregcmd's NO. Can't explain the discrepancy.
Queried the SCP object directly in the AADDS domain — object doesn't exist in the forest's configuration partition.
Ruled out: recent CA policy changes, DNS/connectivity to all relevant MS endpoints, reboot/patch history, time sync, RDS licensing.
Found the exact CA policy via sign-in logs. Its last modification predates this issue by ~12 weeks — can't confirm a causal link (audit retention doesn't go back that far).
Interim fix: excluded the affected device from the CA policy to restore access.
Took a VM disk snapshot before making changes.
Questions
Is a missing SCP object expected/normal in an AADDS-only environment (no AD Connect)? If it should exist — does Microsoft provision it, or do we configure it manually? Is manual creation safe in AADDS? Is the SCP failure related to/causing the CA compliance failure, or are they independent? What's the right long-term approach for an RDS host that's workplace-joined but never MDM-enrolled, since it can't natively satisfy "compliant device"?
Goal: Restore reliable device registration and M365 sign-in, and understand root cause well enough to prevent recurrence.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
1 answer
Sort by: Most helpful
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
1 deleted comment
Comments have been turned off. Learn more