1

What are some ways of diagnosing whether I'm on an Azure VM as opposed to a local Windows 10 installation? I get windows event logs that reference AAD and others that seem to indicate that I'm signing in via RDP Windows Remote Desktop. I don't have to enter any credentials aside from my windows password and there's no browser portal or anything which makes me use RDP explicitly.

Here is one example of an event log that I would like to understand its significance:

EventLog:
Application
RecordNumber:
3,679
TimeGenerated:
6/30/2020 11:24:38 PM
TimeWritten:
6/30/2020 11:24:38 PM
EventID:
1,034
EventType:
4
EventTypeName:
Information event
EventCategory:
0
EventCategoryName:
None
SourceName:
Software Protection Platform Service
Strings:
AAD-WindowsCore-AddAccountRestrictions
100
ComputerName:
DESKTOP-857CLI7
SID:
Message:
Duplicate definition of policy found. Policy name=AAD-WindowsCore-AddAccountRestrictions Priority=100 
Giacomo1968
  • 58,727
Henry A
  • 49

0 Answers0