Home

Need to advise WVD service, User profile disks(fslogix), performance in WVD session, AD-Connect

%3CLINGO-SUB%20id%3D%22lingo-sub-889670%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20to%20advise%20WVD%20service%2C%20User%20profile%20disks(fslogix)%2C%20performance%20in%20WVD%20session%2C%20AD-Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-889670%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F417779%22%20target%3D%22_blank%22%3E%40DUMPDUMPY%3C%2FA%3E%26nbsp%3B%3A%20Regarding%20%233%20(Password%20hash)%2C%20our%20team%20doesn't%20have%20specific%20guidance.%20I'd%20defer%20to%20Azure%20AD%20Connect%20and%20their%20guidance%20on%20password%20hash%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-password-hash-synchronization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-password-hash-synchronization%3C%2FA%3E%26nbsp%3B.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1028440%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20to%20advise%20WVD%20service%2C%20User%20profile%20disks(fslogix)%2C%20performance%20in%20WVD%20session%2C%20AD-Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1028440%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3ERe%20%231%2C%20did%20you%20consider%20using%20Azure%20NetApp%20Files%3F%20I%20haven't%20got%20to%20it%20yet%20but%20it%20should%20save%20you%20all%20the%20trouble%20with%20spinning%20up%20VMs%20and%20management%20overhead.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-884981%22%20slang%3D%22en-US%22%3ENeed%20to%20advise%20WVD%20service%2C%20User%20profile%20disks(fslogix)%2C%20performance%20in%20WVD%20session%2C%20AD-Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-884981%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20our%20organization%20plan%20to%20deploy%20new%20WVD%20service%20for%20user%20remote%20VDI%20about%20100%2B%20User.%20Basically%2C%20I%20try%20to%20test%20deploy%20the%20result%20is%20work%20good%20but%20I%20want%20more%20suggestion%20for%20best%20pactice%20or%20best%20effective%20for%20WVD%20services.%3CBR%20%2F%3Eabout%20following%20topic%3C%2FP%3E%3CP%3E%3CSTRONG%3E1.User%20profile%20disks(fslogix)%20%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B1.1%20if%20many%20user%20use%20WVD%20profile%20disks%20on%20the%20same%20time%2C%20profile%20service%20might%20go%20performance%20drop(full%20network%20bandwidth%2C%20full%20disk%20iops%20and%20etc..)%2C%20plz%20advise%20me%2C%20VM%20Spec%20or%20do%20Clustering%20fslogix%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B1.2%20fxlogix%20can%20setup%20only%201%20VM%20for%20profile%20container%20services%3F%20Can%20we%20setup%20cluster%2C%20it%20maybe%20can%20improve%20performance%20and%20good%20for%20redundant.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%23Now%20my%20solution%20fxlogix%20by%20using%20Storage%20Account%20(AzureFile)%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20-%20In%20configulation%20-%26gt%3B%20Identity-based%20on%20Directory%20Service%20for%26nbsp%3B%20Azure%20File%20Authentication%20-%26gt%3B%20Choose%20AzureADDS%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B-%20In%20file%20share%20-%26gt%3B%20IAM%20-%26gt%3B%20assing%20user%20who%20have%20permission%20to%20use%20this%20directory%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B-%20Testing%20-%26gt%3B%20login%20to%20WVD%20VM%20as%20admin%20-%26gt%3B%20try%20to%20map%20network%20drive%20%22net%20use%20DRIVE%3A%20PATH%20%22%26nbsp%3B%20%26nbsp%3Bnot%20necessary%20login%20user%20pass%20because%20we%20config%26nbsp%3BIdentity-based%20on%20Directory%20Service%20for%26nbsp%3B%20Azure%20File%20Authentication%20at%20storage%20account%20already.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E2.Slow%20performance%20in%20WVD%20session%20%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B2.1%20if%20user%20have%20delay%20on%20session%20screen%2C%20have%20the%20way%20on%20configulation%20for%20tuning%20on%20WVD%20(CLI%2C%20Parameter%2C%20policy%20or%20etc..)%20this%20is%20regional%20project%20the%20site%20we%20have%20Thailand%2C%20Vietnam%2C%20China%20and%20more.%20the%20pilot%20is%20Vietnam.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E3.User%20Authentication%20use%20Azure%20ADDS%2C%20AzureAD%20and%20AD-Connect%20sync%20user%20on-premise%20AD%20method%20password%20hashsync%20support%20NTLM%2BKerberos.%20%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3BNow%20we%20use%20only%20password%20hash%20sync%20from%20AD%20connect%20to%20AzureAD.%20for%20supporting%20user%20on%20premise%20authentication%20on%20WVD%20VM%2C%20we%20must%20to%20change%20configulation%20on%20AD-Connect%20to%20password%20hash%20sync%20support%20NTLM%2BKerberos.%20Have%20any%20recommend%20script%20(both%20new%20and%20rollback)%3F%20if%20we%20change%20configulation%2C%20Will%20have%20an%20service%20that%20must%20concern%3F%20(we%20have%20O365%20Outlook%2C%20onedrive%2C%20sharepoint%2C%20skype%2C%20team%20services)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20everybody%3C%2FP%3E%3CP%3EDUMPDUMPY%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-884981%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAD-Connect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Efslogix%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWVD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1035372%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20to%20advise%20WVD%20service%2C%20User%20profile%20disks(fslogix)%2C%20performance%20in%20WVD%20session%2C%20AD-Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1035372%22%20slang%3D%22en-US%22%3EHi%20hcuj76%2C%3CBR%20%2F%3Ei%20will%20test%20Azure%20NetApp%20Files.%3CBR%20%2F%3E%3CBR%20%2F%3ENow%20my%20solution%20fxlogix%20by%20using%20Storage%20Account%20(AzureFile)%3CBR%20%2F%3E%3CBR%20%2F%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20-%20In%20configulation%20-%26gt%3B%20Identity-based%20on%20Directory%20Service%20for%26nbsp%3B%20Azure%20File%20Authentication%20-%26gt%3B%20Choose%20AzureADDS%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B-%20In%20file%20share%20-%26gt%3B%20IAM%20-%26gt%3B%20assing%20user%20who%20have%20permission%20to%20use%20this%20directory%3CBR%20%2F%3E%3CBR%20%2F%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B-%20Testing%20-%26gt%3B%20login%20to%20WVD%20VM%20as%20admin%20-%26gt%3B%20try%20to%20map%20network%20drive%20%22net%20use%20DRIVE%3A%20PATH%20%22%26nbsp%3B%20%26nbsp%3Bnot%20necessary%20login%20user%20pass%20because%20we%20config%26nbsp%3BIdentity-based%20on%20Directory%20Service%20for%26nbsp%3B%20Azure%20File%20Authentication%20at%20storage%20account%20already.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1035676%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20to%20advise%20WVD%20service%2C%20User%20profile%20disks(fslogix)%2C%20performance%20in%20WVD%20session%2C%20AD-Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1035676%22%20slang%3D%22en-US%22%3EHi%20DumpDumpy%2C%3CBR%20%2F%3EI%20am%20also%20going%20to%20put%20it%20on%20Azure%20Files%20instead%20of%20NetApp%20files.%20Seems%20too%20much%20hassle%20to%20get%20accepted%20into%20their%20program.%3CBR%20%2F%3E%3CBR%20%2F%3EGlad%20it's%20working%20well%20for%20you.%20It%20would%20be%20good%20to%20stay%20in%20touch.%20Possible%20to%20dm%3F%3C%2FLINGO-BODY%3E
DUMPDUMPY
New Contributor

Hi, our organization plan to deploy new WVD service for user remote VDI about 100+ User. Basically, I try to test deploy the result is work good but I want more suggestion for best pactice or best effective for WVD services.
about following topic

1.User profile disks(fslogix)

     1.1 if many user use WVD profile disks on the same time, profile service might go performance drop(full network bandwidth, full disk iops and etc..), plz advise me, VM Spec or do Clustering fslogix

 

     1.2 fxlogix can setup only 1 VM for profile container services? Can we setup cluster, it maybe can improve performance and good for redundant.

 

    #Now my solution fxlogix by using Storage Account (AzureFile)

        - In configulation -> Identity-based on Directory Service for  Azure File Authentication -> Choose AzureADDS 

       - In file share -> IAM -> assing user who have permission to use this directory

       - Testing -> login to WVD VM as admin -> try to map network drive "net use DRIVE: PATH "   not necessary login user pass because we config Identity-based on Directory Service for  Azure File Authentication at storage account already.

 

2.Slow performance in WVD session

     2.1 if user have delay on session screen, have the way on configulation for tuning on WVD (CLI, Parameter, policy or etc..) this is regional project the site we have Thailand, Vietnam, China and more. the pilot is Vietnam.

 

3.User Authentication use Azure ADDS, AzureAD and AD-Connect sync user on-premise AD method password hashsync support NTLM+Kerberos.

     Now we use only password hash sync from AD connect to AzureAD. for supporting user on premise authentication on WVD VM, we must to change configulation on AD-Connect to password hash sync support NTLM+Kerberos. Have any recommend script (both new and rollback)? if we change configulation, Will have an service that must concern? (we have O365 Outlook, onedrive, sharepoint, skype, team services)

 

Thanks everybody

DUMPDUMPY

4 Replies
Highlighted

@DUMPDUMPY : Regarding #3 (Password hash), our team doesn't have specific guidance. I'd defer to Azure AD Connect and their guidance on password hash: https://docs.microsoft.com/azure/active-directory/hybrid/how-to-connect-password-hash-synchronizatio... .

Hi,
Re #1, did you consider using Azure NetApp Files? I haven't got to it yet but it should save you all the trouble with spinning up VMs and management overhead.
Hi hcuj76,
i will test Azure NetApp Files.

Now my solution fxlogix by using Storage Account (AzureFile)

        - In configulation -> Identity-based on Directory Service for  Azure File Authentication -> Choose AzureADDS 

       - In file share -> IAM -> assing user who have permission to use this directory

       - Testing -> login to WVD VM as admin -> try to map network drive "net use DRIVE: PATH "   not necessary login user pass because we config Identity-based on Directory Service for  Azure File Authentication at storage account already.
Hi DumpDumpy,
I am also going to put it on Azure Files instead of NetApp files. Seems too much hassle to get accepted into their program.

Glad it's working well for you. It would be good to stay in touch. Possible to dm?
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies