Microsoft Entra ID
Troubleshooting

Troubleshoot Hybrid Join Windows Current

In brief

The Windows hybrid-join troubleshooting page received spelling and copy edits covering TPM errors, PRT checks, and Event Viewer guidance.

What Entra admins need to know

Administrators will find the troubleshooting instructions clearer when diagnosing hybrid-join and PRT issues.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Troubleshoot join failures

Error code Reason Resolution
NTE_BAD_KEYSET (0x80090016/-2146893802) The Trusted Platform Module (TPM) operation failed or was invalid. This error indicates that the keyset doesn't exist. This error happens when the TPM is cleared on the systems, or when there's a bad sysprep image.

Avoid clearing the TPM in BIOS or Windows settings. If the TPM is cleared, users might need to recover by removing and readdingreading accounts to fix the problem, especially when they have multiple WAM accounts. Ensure that the machine from which the sysprep image was created isn't Microsoft Entra joined, Microsoft Entra hybrid joined, or Microsoft Entra registered.
TPM_E_PCP_INTERNAL_ERROR (0x80290407/-2144795641) Generic TPM error. Disable TPM on devices with this error. Windows 10 versions 1809 and later automatically detect TPM failures and complete Microsoft Entra hybrid join without using the TPM.
TPM_E_NOTFIPS (0x80280036/-2144862154) TPM in FIPS mode isn't currently supported. Disable TPM on devices with this error. Windows 10 version 1809 automatically detects TPM failures and completes the Microsoft Entra hybrid join without using the TPM.
NTE_AUTHENTICATION_IGNORED (0x80090031/-2146893775) TPM is locked out. Transient error. Wait for the cool-down period. The join attempt should succeed after a while. For more information, see TPM fundamentals.
  1. Select Switch Account to toggle back to the admin session that's running the tracing.
  2. From the elevated PowerShell session, run .\stop-auth.ps1.
  3. Zip (compress) and send the folder Authlogs from the folder where the scripts were executed.

Troubleshoot post-join authentication issues

Step 1: Retrieve the PRT status by using dsregcmd /status

  1. Open a Command Prompt window.
  1. Run dsregcmd /status.

    The "SSO state" section provides the current PRT status.

    If the AzureAdPrt field is set to NO, there was an error acquiring the PRT status from Microsoft Entra ID.

  2. If the AzureAdPrtUpdateTime is more than four hours, there's likely an issue with refreshing the PRT. Lock and unlock the device to force the PRT refresh, and then check to see whether the time updates.

+----------------------------------------------------------------------+


### Step 2: Find the error code

**From the `dsregcmd` output**


**From the Microsoft Entra analytics and operational logs**

Use Event Viewer to look for the log entries logged by the Microsoft Entra CloudAP plug-in during PRT acquisition.

<!-- docutune:disable -->
1. In Event Viewer, open the Microsoft Entra Operational event logs. They're stored under **Applications and Services Log** > **Microsoft** > **Windows** > **AAD**.
<!-- docutune:enable -->
  1. Event 1006 in the analytics logs denotes the start of the PRT acquisition flow, and event 1007 in the analytics logs denotes the end of the PRT acquisition flow. All events in the Microsoft Entra logs (analytics and operational) that are logged between events 1006 and 1007 were logged as part of the PRT acquisition flow.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…