Home

unable to join Azure VM to AAD

%3CLINGO-SUB%20id%3D%22lingo-sub-92096%22%20slang%3D%22en-US%22%3Eunable%20to%20join%20Azure%20VM%20to%20AAD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92096%22%20slang%3D%22en-US%22%3E%3CP%3EAccording%20to%20this%20Microsoft%20support%20doc%2C%20what%20I%20am%20trying%20to%20do%20is%20supported%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Factive-directory-ds-admin-guide-join-windows-vm%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Factive-directory-ds-admin-guide-join-windows-vm%3C%2FA%3E%3C%2FP%3E%3CP%3EBut%20I%20am%20unable%20to%20join%20a%20VM%20(Server%202016)%20to%20my%20AAD%20domain%20-%20even%20though%20Azure%20AD%20Domain%20Services%20associated%20with%20the%20domain%20has%20been%20set%20up%20successfully.%3C%2FP%3E%3CP%3EThe%20above%20article%20suggests%20these%20troubleshooting%20steps%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CEM%3EEnsure%20that%20the%20virtual%20machine%20is%20connected%20to%20the%20same%20virtual%20network%20as%20that%20you've%20enabled%20Domain%20Services%20in.%20If%20not%2C%20the%20virtual%20machine%20is%20unable%20to%20connect%20to%20the%20domain%20and%20therefore%20is%20unable%20to%20join%20the%20domain.%3C%2FEM%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EDone%20-%20the%20VM%20is%20active%20on%20the%20correct%20network%20and%20can%20ping%20other%20VMs%20successfully%3C%2FP%3E%3CUL%3E%3CLI%3E%3CEM%3EIf%20the%20virtual%20machine%20is%20connected%20to%20another%20virtual%20network%2C%20ensure%20that%20this%20virtual%20network%20is%20connected%20to%20the%20virtual%20network%20in%20which%20you've%20enabled%20Domain%20Services.%3C%2FEM%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThis%20is%20not%20necessary%2C%20the%20VM%20is%20on%20the%20same%20network%20as%20Domain%20Services%3C%2FP%3E%3CUL%3E%3CLI%3E%3CEM%3ETry%20to%20ping%20the%20domain%20using%20the%20domain%20name%20of%20the%20managed%20domain%20(for%20example%2C%20'ping%20contoso100.com').%20If%20you're%20unable%20to%20do%20so%2C%20try%20to%20ping%20the%20IP%20addresses%20for%20the%20domain%20displayed%20on%20the%20page%20where%20you%20enabled%20Azure%20AD%20Domain%20Services%20(for%20example%2C%20'ping%2010.0.0.4').%20If%20you're%20able%20to%20ping%20the%20IP%20address%20but%20not%20the%20domain%2C%20DNS%20may%20be%20incorrectly%20configured.%20You%20may%20not%20have%20configured%20the%20IP%20addresses%20of%20the%20domain%20as%20DNS%20servers%20for%20the%20virtual%20network.%3C%2FEM%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EI%20can%20not%20ping%20(no%20reply)%20the%202x%20DNS%20server%20IPs%20that%20were%20auto%20configured%20during%20Domain%20Services%20setup.%3C%2FP%3E%3CP%3EI%20also%20cannot%20resolve%20the%20domain%20(ping%20x.com)%20-%20it%20cannot%20be%20found.%3C%2FP%3E%3CP%3EThe%20implication%20is%20that%20DNS%20is%20not%20running%20at%20the%20IP%20addresses%20that%20were%20auto%20configured%20and%20supplied%20via%20Domain%20Services%20setup%2C%20or%20that%26nbsp%3Bcomms%20is%20not%20possible%20with%20these%202x%20DNS%20servers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-92096%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Sid Merrett
Occasional Contributor

According to this Microsoft support doc, what I am trying to do is supported:

https://docs.microsoft.com/en-us/azure/active-directory-domain-services/active-directory-ds-admin-gu...

But I am unable to join a VM (Server 2016) to my AAD domain - even though Azure AD Domain Services associated with the domain has been set up successfully.

The above article suggests these troubleshooting steps:

 

  • Ensure that the virtual machine is connected to the same virtual network as that you've enabled Domain Services in. If not, the virtual machine is unable to connect to the domain and therefore is unable to join the domain.

Done - the VM is active on the correct network and can ping other VMs successfully

  • If the virtual machine is connected to another virtual network, ensure that this virtual network is connected to the virtual network in which you've enabled Domain Services.

This is not necessary, the VM is on the same network as Domain Services

  • Try to ping the domain using the domain name of the managed domain (for example, 'ping contoso100.com'). If you're unable to do so, try to ping the IP addresses for the domain displayed on the page where you enabled Azure AD Domain Services (for example, 'ping 10.0.0.4'). If you're able to ping the IP address but not the domain, DNS may be incorrectly configured. You may not have configured the IP addresses of the domain as DNS servers for the virtual network.

I can not ping (no reply) the 2x DNS server IPs that were auto configured during Domain Services setup.

I also cannot resolve the domain (ping x.com) - it cannot be found.

The implication is that DNS is not running at the IP addresses that were auto configured and supplied via Domain Services setup, or that comms is not possible with these 2x DNS servers.

 

 

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies