Home

Join script fails for VM that needs to join a Domain Controller over a IPSec VPN

%3CLINGO-SUB%20id%3D%22lingo-sub-639232%22%20slang%3D%22en-US%22%3EJoin%20script%20fails%20for%20VM%20that%20needs%20to%20join%20a%20Domain%20Controller%20over%20a%20IPSec%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-639232%22%20slang%3D%22en-US%22%3E%3CP%3EMy%20current%20topology%20is%20the%20following%3A%3C%2FP%3E%3CP%3EMy%20on-premise%20site%20has%20the%20DC%20(which%20is%20also%20used%20as%20a%20DNS%20server)%2C%20said%20DC%20has%20AzureConnect%20enabled%20as%20well%20and%20syncs%20often.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20Azure%20site%20has%20a%20different%20segment%20of%20IPs%20and%20my%20DNS%20servers%20have%20been%20modified%20so%20that%20the%20VMs%20resolve%20addresses%20with%20help%20of%20my%20local%20DC.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20have%20setup%20a%20VPN%20between%20sites%20correctly%20(I%20know%20this%20because%20I%20have%20done%20several%20failover%20and%20failback%20tests%20that%20require%20it).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EProvisioning%20is%20failing%2C%20and%20I%20am%20using%20a%20local%20identifier%20for%20my%20UPN%20field.%26nbsp%3B%20That's%20%40domain.local%20instead%20of%20%40.domain.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20know%20what%20I'm%20doing%20wrong%2C%20everything%20should%20be%20fine%2C%20here's%20a%20screen%20of%20what%20the%20console%20says%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20571px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F115863i51EA788C38296750%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Screenshot%20from%202019-05-23%2016-47-13.png%22%20title%3D%22Screenshot%20from%202019-05-23%2016-47-13.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-639232%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ecarlos.ramos%40alvatrix.com%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Erafael.gonzalez%40alvatrix.com%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-642766%22%20slang%3D%22en-US%22%3ERe%3A%20Join%20script%20fails%20for%20VM%20that%20needs%20to%20join%20a%20Domain%20Controller%20over%20a%20IPSec%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-642766%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F347749%22%20target%3D%22_blank%22%3E%40ralfAlfa%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22Provisioning%20is%20failing%2C%20and%20I%20am%20using%20a%20local%20identifier%20for%20my%20UPN%20field.%20That's%20%40domain.local%20instead%20of%20%40.domain.com%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20you%20using%20AD%20Sync%3F%20The%20provisioning%20doesn't%20seems%20to%20require%20the%20UPN%20of%20an%20Azure%20AD%20identity.%20If%20you%20are%20using%20ADSync%20then%20use%20the%20.com%20account%20and%20when%20it%20joins%20the%20domain%20it%20should%20find%20the%20associated%20user%20on%20the%20.local%20.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-644294%22%20slang%3D%22en-US%22%3ERe%3A%20Join%20script%20fails%20for%20VM%20that%20needs%20to%20join%20a%20Domain%20Controller%20over%20a%20IPSec%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-644294%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F347822%22%20target%3D%22_blank%22%3E%40WookieGTB%3C%2FA%3EI've%20tried%20both%20ways.%20It%20also%20fails%20when%20the%20identifier%20is%20%40domain.com%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-651205%22%20slang%3D%22en-US%22%3ERe%3A%20Join%20script%20fails%20for%20VM%20that%20needs%20to%20join%20a%20Domain%20Controller%20over%20a%20IPSec%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-651205%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F347749%22%20target%3D%22_blank%22%3E%40ralfAlfa%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDid%20you%20set%20the%20DNS%20servers%20correctly%20in%20your%20VNET%20on%20Azure%3F%20It%20should%20point%20to%20your%20DC%20on-prem.%20Otherwise%2C%20your%20newly%20deployed%20VMs%20will%20not%20be%20able%20to%20resolve%20your%20Domain%20Name%2C%20and%20cause%20this%20joining%20error%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-652679%22%20slang%3D%22en-US%22%3ERe%3A%20Join%20script%20fails%20for%20VM%20that%20needs%20to%20join%20a%20Domain%20Controller%20over%20a%20IPSec%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-652679%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F298270%22%20target%3D%22_blank%22%3E%40michawets%3C%2FA%3EYes%2C%20I%20did%20change%20the%20DNS%20server.%26nbsp%3B%20I%20tried%20a%20different%20solution%20and%20am%20now%20able%20to%20create%20a%20host%20pool%20through%20Az%20powershell.%26nbsp%3B%20I'm%20getting%20errors%20as%20well%2C%20but%20they%20are%20not%20related%20to%20this%20thread%20anymore.%26nbsp%3B%20For%20example%2C%20only%20admin%20users%20can%20start%20a%20session%20amongst%20other%20things.%3C%2FP%3E%3C%2FLINGO-BODY%3E
ralfAlfa
New Contributor

My current topology is the following:

My on-premise site has the DC (which is also used as a DNS server), said DC has AzureConnect enabled as well and syncs often.

 

My Azure site has a different segment of IPs and my DNS servers have been modified so that the VMs resolve addresses with help of my local DC.

I have setup a VPN between sites correctly (I know this because I have done several failover and failback tests that require it).

 

Provisioning is failing, and I am using a local identifier for my UPN field.  That's @domain.local instead of @.domain.com

 

I don't know what I'm doing wrong, everything should be fine, here's a screen of what the console says:

Screenshot from 2019-05-23 16-47-13.png

4 Replies

@ralfAlfa 

 

"Provisioning is failing, and I am using a local identifier for my UPN field. That's @domain.local instead of @.domain.com"

 

Are you using AD Sync? The provisioning doesn't seems to require the UPN of an Azure AD identity. If you are using ADSync then use the .com account and when it joins the domain it should find the associated user on the .local .

@WookieGTBI've tried both ways. It also fails when the identifier is @domain.com

Hi @ralfAlfa ,

 

Did you set the DNS servers correctly in your VNET on Azure? It should point to your DC on-prem. Otherwise, your newly deployed VMs will not be able to resolve your Domain Name, and cause this joining error

@michawetsYes, I did change the DNS server.  I tried a different solution and am now able to create a host pool through Az powershell.  I'm getting errors as well, but they are not related to this thread anymore.  For example, only admin users can start a session amongst other things.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies