-
<remote-hostname> must match the hostname exactly as registered in Entra ID, and must actually resolve (DNS or /etc/hosts) — an IP address will not work for this auth flow.-
/w:, /h:, and /smart-sizing fixed a real rendering bug — reconnecting to a previously-disconnected session rendered the remote desktop content squashed into a small corner of the window with the rest black. Explicitly forcing the resolution and enabling smart-sizing (which scales/stretches remote content to fill the client window regardless of the session's actual internal resolution) fixed this completely.## Result
Running that command pops open a real embedded browser window right in the FreeRDP client for the Microsoft sign-in — full Conditional Access / MFA support — no external browser, no manual URL copy-paste. Exactly matching the
mstsc.exe "use a web account" experience, just self-compiled.## Wrapper script
Threw this into a small shell script so I can just run
rdp-aad instead of remembering the whole command:#!/usr/bin/env bash
set -euo pipefail
DEFAULT_HOST="your-vm-hostname"
DEFAULT_USER="youruser@yourdomain.com"
TENANT_ID="your-entra-tenant-id"
FREERDP_BIN="$HOME/FreeRDP/build/client/SDL/SDL2/sdl-freerdp"
RES_WIDTH="2560"
RES_HEIGHT="1440"
HOST="${1:-$DEFAULT_HOST}"
USERNAME="${2:-$DEFAULT_USER}"
if [[ ! -x "$FREERDP_BIN" ]]; then
echo "FreeRDP binary not found at $FREERDP_BIN"
exit 1
fi
if ! getent hosts "$HOST" > /dev/null 2>&1; then
echo "Warning: '$HOST' does not resolve. AAD auth needs a resolvable hostname"
echo "matching the device name registered in Entra ID."
read -r -p "Continue anyway? [y/N] " reply
[[ "$reply" =~ ^[Yy]$ ]] || exit 1
fi
exec "$FREERDP_BIN" \
/v:"$HOST" \
/sec:aad \
/azure:tenantid:"$TENANT_ID" \
/u:"$USERNAME" \
/cert:ignore \
/dynamic-resolution \
/w:"$RES_WIDTH" \
/h:"$RES_HEIGHT" \
/smart-sizing
Hope this saves someone else the trial and error. Happy to answer questions if anyone hits a snag replicating it.
https://redd.it/1vdzgqd
@r_linux