Home

Diagnostic Activity - Where to look next?

%3CLINGO-SUB%20id%3D%22lingo-sub-826369%22%20slang%3D%22en-US%22%3EDiagnostic%20Activity%20-%20Where%20to%20look%20next%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-826369%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20the%20moment%2C%20I'm%20testing%20Windows%20Virtual%20Desktop%20for%20our%20organisation.%20As%20part%20of%20this%20all%2C%20I%20set%20up%20an%20Azure%20Active%20Directory%20Domain%20Services%20(AADDSS)%20domain%20with%20a%20different%20domain%20name%20than%20we%20currently%20use%20since%20that%20domain%20exceed%20the%20character%20count%20limit%20of%2015%20characters.%20I%20also%20created%20a%20virtual%20machine%20that%20acts%20as%20a%20management%20server%20for%20the%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20following%20the%20guide%20at%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2F%3C%2FA%3E%26nbsp%3BI%20was%20successful%20in%20creating%20a%20host%20pool%20and%20assigning%20myself%20to%20an%20RDS%20App%20Group.%20However%2C%20I've%20been%20unsuccessful%20when%20trying%20to%20connect%20to%20the%20host%20pool%20I've%20set%20up.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet-RdsDiagnosticActivities%20shows%20the%20following%20information%20in%20its%20errors%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%3EErrorSource%20%3A%20RDBroker%3CBR%20%2F%3EErrorOperation%20%3A%20OrchestrateSessionHost%3CBR%20%2F%3EErrorCode%20%3A%20-2146233088%3CBR%20%2F%3EErrorCodeSymbolic%20%3A%20ConnectionFailedUserSIDInformationMismatch%3CBR%20%2F%3EErrorMessage%20%3A%20OrchestrateAsync%3A%20SID%20value%20in%20the%20database%20is%20different%20than%20the%20value%20returned%20in%20the%3CBR%20%2F%3Eorchestration%20reply%20from%20the%20agent%20for%20user%20%E2%89%A4me%40domain%E2%89%A5%20with%20Id%3CBR%20%2F%3E%3CMYGUID%3E.%20This%20scenario%20is%20not%20supported%20-%20we%20will%20not%20be%20able%20to%3CBR%20%2F%3Eredirect%20the%20user%20session.%3CBR%20%2F%3EErrorInternal%20%3A%20False%3CBR%20%2F%3EReportedBy%20%3A%20RDGateway%3C%2FMYGUID%3E%3C%2FPRE%3E%3CP%3EThis%20has%20prevented%20me%20from%20going%20any%20further%20with%20testing%20since%20I%20cannot%20even%20connect%20onto%20a%20session.%20The%20resource%20group%20I%20created%20for%20Windows%20Virtual%20Desktop%20shows%20no%20deployment%20errors%2C%20the%20virtual%20machines%20I%20created%20appear%20in%20the%20%22AADDC%20Computers%22%20organisational%20unit%20(and%20can%20be%20accessed%20from%20the%20management%20server).%20I%20can%20even%20access%20the%20virtual%20machines%20created%20by%20the%20WVD%20host%20pool%20provisioning%20process%20from%20the%20management%20server.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20my%20question%20is%2C%20where%20do%20I%20go%20from%20here%3F%20Does%20the%20domain%20that%20I%20use%20to%20sign%20into%20Office%20365%20and%20Azure%20services%20need%20to%20match%20the%20domain%20used%20by%20the%20AADDS%20tenant%20I%20created%3F%20Do%20I%20have%20to%20remove%20the%20host%20pool%20and%20start%20again%20(the%20host%20pool%20was%20set%20up%20before%20I%20had%20properly%20set%20up%20password%20synchronisation%20between%20the%20on-premise%20AD%20DS%20users%20and%20the%20AADDS%20domain)%3F%20Do%20I%20have%20to%20get%20something%20else%20working.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWVD%20does%20look%20interesting%20but%20if%20I%20can't%20resolve%20this%20problem%20I%20can't%20go%20any%20further%20in%20my%20testing%20so%20any%20hints%20will%20be%20useful%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-826579%22%20slang%3D%22en-US%22%3ERE%3A%20Diagnostic%20Activity%20-%20Where%20to%20look%20next%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-826579%22%20slang%3D%22en-US%22%3EThis%20appears%20to%20be%20a%20known%20issue%2C%20as%20referenced%20in%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-Virtual-Desktop%2FAnnouncement-Connectivity-issues-from-synchronized-users-to-VMs%2Fm-p%2F759642%23M1036%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-Virtual-Desktop%2FAnnouncement-Connectivity-issues-from-synchronized-users-to-VMs%2Fm-p%2F759642%23M1036%3C%2FA%3E.%20It%20looks%20fixes%20are%20incoming%2C%20so%20I%20will%20wait%20for%20that%20fix%3C%2FLINGO-BODY%3E
Darren Adams
New Contributor

Hello all,

 

At the moment, I'm testing Windows Virtual Desktop for our organisation. As part of this all, I set up an Azure Active Directory Domain Services (AADDSS) domain with a different domain name than we currently use since that domain exceed the character count limit of 15 characters. I also created a virtual machine that acts as a management server for the domain.

 

After following the guide at https://docs.microsoft.com/en-us/azure/virtual-desktop/ I was successful in creating a host pool and assigning myself to an RDS App Group. However, I've been unsuccessful when trying to connect to the host pool I've set up.

 

Get-RdsDiagnosticActivities shows the following information in its errors:

 

ErrorSource : RDBroker
ErrorOperation : OrchestrateSessionHost
ErrorCode : -2146233088
ErrorCodeSymbolic : ConnectionFailedUserSIDInformationMismatch
ErrorMessage : OrchestrateAsync: SID value in the database is different than the value returned in the
orchestration reply from the agent for user ≤me@domain≥ with Id
<myGuid>. This scenario is not supported - we will not be able to
redirect the user session.
ErrorInternal : False
ReportedBy : RDGateway

This has prevented me from going any further with testing since I cannot even connect onto a session. The resource group I created for Windows Virtual Desktop shows no deployment errors, the virtual machines I created appear in the "AADDC Computers" organisational unit (and can be accessed from the management server). I can even access the virtual machines created by the WVD host pool provisioning process from the management server.

 

So my question is, where do I go from here? Does the domain that I use to sign into Office 365 and Azure services need to match the domain used by the AADDS tenant I created? Do I have to remove the host pool and start again (the host pool was set up before I had properly set up password synchronisation between the on-premise AD DS users and the AADDS domain)? Do I have to get something else working.

 

WVD does look interesting but if I can't resolve this problem I can't go any further in my testing so any hints will be useful

1 Reply
This appears to be a known issue, as referenced in https://techcommunity.microsoft.com/t5/Windows-Virtual-Desktop/Announcement-Connectivity-issues-from.... It looks fixes are incoming, so I will wait for that fix
Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies