Article

Auto login with Entra joined devices

Introduction

Automatic login for Microsoft Entra joined devices is supported in Virtual Cabinet version 5.6.1.158 and onwards. This feature allows Virtual Cabinet to take advantage of the Entra sign-in context on a user’s device, providing a seamless sign-in experience in cloud based environments. 

Microsoft Entra is part of Microsoft 365 and manages user identities and device sign-ins. This article explains what Entra joined devices are, how this works in Virtual Cabinet, and key considerations when deploying the feature.

 

What are Entra joined devices and what does this mean

An Entra joined device is a computer that is joined directly to Microsoft Entra ID (formerly Azure Active Directory), rather than a traditional on premises Active Directory domain.

Users sign in to these devices using their Entra ID (work or school) account. Microsoft Entra then provides a single sign-on (SSO) context that applications can use to authenticate the user without requiring additional credentials.

It is common for organisations to use Entra alongside a traditional on premises Active Directory domain. In these environments, the local Active Directory is typically synchronised with Microsoft Entra, allowing users to have the same identity across both on premises and cloud systems.

From a Virtual Cabinet perspective, this means the signed-in Entra identity on the device can be used to identify the user automatically.

 

Entra joined device support in Virtual Cabinet

From version 5.6.1.158 onwards, the Virtual Cabinet can use the Entra sign-in context to support automatic login on Entra joined devices.

This removes the need for users to manually enter credentials when signing in, provided their Entra identity matches the user record stored in Virtual Cabinet.

 

Important behaviour to be aware of (Entra Domain Services scenarios only)

One important consideration when using automatic login is how User Principal Names (UPNs) are stored and compared.

When users are added to Virtual Cabinet via Active Directory Import, the UPN stored in Virtual Cabinet may contain uppercase or mixed-case characters. Microsoft Entra typically presents the user’s UPN in lowercase format during sign-in.

Example:

UPN imported from Active Directory:
John.Smith@workiro.com

UPN presented by Entra at sign-in:
john.smith@workiro.com

While Microsoft Entra authentication itself is not case sensitive, Virtual Cabinet compares UPNs as case-sensitive values. For automatic login to work correctly, the UPN stored in Virtual Cabinet must exactly match the value presented by Entra.

 

Ensuring the correct UPN is stored in Virtual Cabinet

If users are added via Active Directory and the AD environment does not enforce lowercase UPNs, one of the following approaches should be used:

  • A Virtual Cabinet Administrator updates the user’s UPN in Virtual Cabinet to the lowercase value
    OR

  • The user signs in using Username and Password, then enables Automatic Login via the Virtual Cabinet, which will update the stored UPN to the correct lowercase value automatically

 

Key points and requirements

  • The user’s computer must be able to communicate with the Virtual Cabinet server over the network

  • Network access must allow the user’s computer to connect to the Virtual Cabinet server on port 8558 (for example, via VPN if working remotely)

  • Virtual Cabinet performs case sensitive matching on UPN values

  • Automatic login for Entra-joined devices is available from version 5.6.1.158 onwards

 

Summary

From version 5.6.1.158, Virtual Cabinet supports automatic login on Microsoft Entra joined devices by using the Entra sign-in context provided by the device. When deploying this feature, ensure that the user’s UPN stored in Virtual Cabinet matches the Entra UPN exactly and that devices can connect to the Virtual Cabinet server over the required network port.

Powered by Zendesk