Skip to content

Sign-in on an Entra-joined laptop takes minutes

WAM, Web Account Manager, often hangs on a slow CRL check or an expired device token. Sometimes it is Conditional Access evaluation itself.

Try this first

  1. 1Run dsregcmd /status and check AzureAdJoined, DeviceAuthStatus and TpmProtected
  2. 2Inspect Event Viewer under AAD/Operational around the sign-in time
  3. 3Test reachability of CRL endpoints crl.microsoft.com and mscrl.microsoft.com
  4. 4Reset the WAM token cache with dsregcmd /forcerecovery if the device cert is broken

When to bring us in

For persistent slow sign-ins: capture a Fiddler trace during login and identify the hanging endpoint.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.