Home

Azure AD advanced user properties and non-default OUs for WVD

%3CLINGO-SUB%20id%3D%22lingo-sub-665035%22%20slang%3D%22en-US%22%3EAzure%20AD%20advanced%20user%20properties%20and%20non-default%20OUs%20for%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-665035%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20the%20need%20to%20implement%20%22home%20folder%22%20for%20WVD%20users%20but%20that%20section%20is%20grayed%20out%20in%20AD%20User%20Properties.%20Somewhere%20in%20the%20documentation%20it%20says%20that%20this%20is%20by%20design%20for%20users%20propagated%20from%20Azure%20AD%20trough%20AZ%20Domain%20Services.%20I%20also%20have%20the%20need%20to%20apply%20different%20group%20policies%20for%20different%20category%20of%20users%20which%20I%20currently%20use%20OU's%20to%20group%20them%20together%20in%20my%20local%20environment.%20Creating%20OUs%20within%20the%20provided%20%22AADDC%20Users%22%20OU%20is%20not%20allowed.%20Moving%20the%20users%20to%20other%20OUs%20is%20not%20allowed.%20When%20I%20create%20a%20new%20OU%20tree%20at%20the%20root%20of%20the%20domain%20and%20then%20create%20accounts%20within%20the%20local%20active%20directory%20I%20do%20have%20full%20access%20to%20all%20AD%20properties%20as%20expected%20however%20these%20local%20users%20are%20not%20recognized%20by%20WVD.%20Apparently%20only%20users%20created%20in%20Azure%20AD%20and%20replicated%20to%20the%20default%20%22AADDC%20Users%22%20OU%20are%20allowed%20to%20login.%20Are%20there%20any%20plans%20to%20remediate%20these%20limitations%3F%20I%20would%20need%20to%20be%20able%20to%20move%20users%20to%20different%20OUs%20for%20organization%20purposes%20and%20be%20able%20to%20apply%20different%20group%20policies%20against%20those%20different%20OUs%20per%20our%20needs%2C%20the%20same%20would%20be%20required%20for%20computer%20accounts.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-672118%22%20slang%3D%22en-US%22%3ERE%3A%20Azure%20AD%20advanced%20user%20properties%20and%20non-default%20OUs%20for%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-672118%22%20slang%3D%22en-US%22%3EHow%20do%20we%20go%20about%20setting%20%22home%20folders%22%20for%20users%20under%20WVD%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-673205%22%20slang%3D%22en-US%22%3ERE%3A%20Azure%20AD%20advanced%20user%20properties%20and%20non-default%20OUs%20for%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-673205%22%20slang%3D%22en-US%22%3EI%20think%20this%20is%20a%20question%20that%20is%20related%20to%20Azure%20AD%20with%20an%20Azure%20AD%20DS%20synching%20from%20it.%20That%20should%20be%20a%20supported%20combination%20that%20you%20can%20tech%20support%20for%20using%20your%20normal%20channels.%20Since%20I%20am%20not%20from%20MSFT%20and%20not%20an%20expert%20I%20can%20just%20give%20you%20an%20amateur%20view.%20If%20you%20have%20the%20setup%20as%20above%2C%20you%20are%20limited%20to%20the%20attributes%20available%20in%20Azure%20AD.%20Azure%20AD%20does%20not%20support%20OU%20and%20home%20drives%2C%20probably%20due%20to%20it%20initially%20being%20focused%20more%20on%20supporting%20Office365%20etc.%20In%20addition%20the%20synch%20between%20Azure%20AD%20and%20Azure%20AD%20DS%20is%20one-way%20from%20Azure%20AD.%20You%20could%20argue%20that%20MSFT%20took%20a%20wrong%20turn%20when%20they%20decided%20that%20the%20structure%20of%20Azure%20AD%20user%2Fmachine%20setup%20was%20a%20small%20subset%20of%20standard%20AD.%20Nevertheless%2C%20I%20think%20your%20problem%20is%20that%20you%20selected%20Azure%20AD%20as%20your%20user%2Fcomputer%20store%20before%20checking%20if%20it%20could%20replicate%20the%20functionality%20you%20want%20(ou%3As%2Fhomedrive%2F...)%20Again%20-%20Not%20really%20WVD%20related%20and%20only%20answered%20by%20an%20amateur.%20Cheers%2C%20Johan%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-674817%22%20slang%3D%22en-US%22%3ERE%3A%20Azure%20AD%20advanced%20user%20properties%20and%20non-default%20OUs%20for%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-674817%22%20slang%3D%22en-US%22%3EFair%20enough%20as%20drive%20mapping%20can%20be%20achieved%20via%20other%20means%2C%20but%20how%20about%20applying%20different%20group%20policies%20to%20different%20OUs%2C%20any%20ideas%20how%20could%20I%20accomplish%20something%20like%20that%20when%20accounts%20cannot%20be%20moved%20to%20other%20OUs%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-682885%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Azure%20AD%20advanced%20user%20properties%20and%20non-default%20OUs%20for%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-682885%22%20slang%3D%22en-US%22%3EApply%20all%20GPO's%20to%20the%20same%20OU%2C%20but%20use%20security%20groups%20to%20limit%20the%20scope%20of%20users%20to%20which%20they%20apply%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-682945%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Azure%20AD%20advanced%20user%20properties%20and%20non-default%20OUs%20for%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-682945%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F309051%22%20target%3D%22_blank%22%3E%40Johan_Eriksson%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20used%20%22Home%20folder%22%20and%20%22Shared%20network%20drives%22%20in%20diffrent%20scenarios%20in%20the%20past.%20it%20is%20not%20very%20reliable.%20I%20think%20it%20is%20the%20time%20to%20move%20to%20Azure%20Files%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-introduction%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20been%20using%20Azure%20Files%20alongside%20Azure%20AD%20in%20production%20and%20can%26nbsp%3Bguaranty%20it%20will%20deliver%20the%20user%20needs.%20I%20agree%20Azure%20AD%20has%20long%20way%20to%20go%20to%20become%20a%20perfect%20cloud%20DC%20(eventually%20it%20will)%20but%20for%20now%20they%20are%20doing%20a%20grea%20job%2C%20Azure%20files%20is%20doing%20even%20a%20better%20job.%26nbsp%3B%20So%20from%20my%20point%20of%20view%2C%20Micrsoft%20idea%20on%20Azure%20Ad%20and%20Files%20is%20leading%20to%20a%20perfection%20direction.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20recommend%20everyone%20to%20vote%20on%20this%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F217298-storage%2Fsuggestions%2F19693045-automatically-mount-an-azure-file-share-to-a-windo%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ffeedback.azure.com%2Fforums%2F217298-storage%2Fsuggestions%2F19693045-automatically-mount-an-azure-file-share-to-a-windo%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMicrosoft%20is%20doin%20a%20great%20job%20to%20get%20Azure%20Files%20to%20parity%20with%20Windows%20File%20Server.%20Using%20Azure%20Files%26nbsp%3B%3CSPAN%3Evia%20GPO%20would%20be%20the%20dream.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThank%20you%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EDav%2C%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
compulinkegf
Occasional Contributor

I've the need to implement "home folder" for WVD users but that section is grayed out in AD User Properties. Somewhere in the documentation it says that this is by design for users propagated from Azure AD trough AZ Domain Services. I also have the need to apply different group policies for different category of users which I currently use OU's to group them together in my local environment. Creating OUs within the provided "AADDC Users" OU is not allowed. Moving the users to other OUs is not allowed. When I create a new OU tree at the root of the domain and then create accounts within the local active directory I do have full access to all AD properties as expected however these local users are not recognized by WVD. Apparently only users created in Azure AD and replicated to the default "AADDC Users" OU are allowed to login. Are there any plans to remediate these limitations? I would need to be able to move users to different OUs for organization purposes and be able to apply different group policies against those different OUs per our needs, the same would be required for computer accounts.

5 Replies
How do we go about setting "home folders" for users under WVD?
I think this is a question that is related to Azure AD with an Azure AD DS synching from it. That should be a supported combination that you can tech support for using your normal channels. Since I am not from MSFT and not an expert I can just give you an amateur view. If you have the setup as above, you are limited to the attributes available in Azure AD. Azure AD does not support OU and home drives, probably due to it initially being focused more on supporting Office365 etc. In addition the synch between Azure AD and Azure AD DS is one-way from Azure AD. You could argue that MSFT took a wrong turn when they decided that the structure of Azure AD user/machine setup was a small subset of standard AD. Nevertheless, I think your problem is that you selected Azure AD as your user/computer store before checking if it could replicate the functionality you want (ou:s/homedrive/...) Again - Not really WVD related and only answered by an amateur. Cheers, Johan
Fair enough as drive mapping can be achieved via other means, but how about applying different group policies to different OUs, any ideas how could I accomplish something like that when accounts cannot be moved to other OUs?
Apply all GPO's to the same OU, but use security groups to limit the scope of users to which they apply

Hi@Johan_Eriksson 

 

I have used "Home folder" and "Shared network drives" in diffrent scenarios in the past. it is not very reliable. I think it is the time to move to Azure Files

https://docs.microsoft.com/en-us/azure/storage/files/storage-files-introduction

 

I have been using Azure Files alongside Azure AD in production and can guaranty it will deliver the user needs. I agree Azure AD has long way to go to become a perfect cloud DC (eventually it will) but for now they are doing a grea job, Azure files is doing even a better job.  So from my point of view, Micrsoft idea on Azure Ad and Files is leading to a perfection direction.

 

I would recommend everyone to vote on this https://feedback.azure.com/forums/217298-storage/suggestions/19693045-automatically-mount-an-azure-f...

 

Microsoft is doin a great job to get Azure Files to parity with Windows File Server. Using Azure Files via GPO would be the dream.

 

Thank you

Dav,

 

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies