Mar 25 2019 08:56 AM
Looking at the documentation, it seems an on premise AD is required for Windows Virtual desktop in Azure and Azure domain join is not supported. Can anyone confirm if that's definitely the case? It seems poor to have a new cloud service launched that has a dependency on on-prem AD.
Apr 10 2019 06:35 AM
Hi, I am just curious how did you get it to work with AAD DS . My Deployment keeps on failing on
/dscextension with the error:
" PowerShell DSC resource MSFT_ScriptResource failed to execute Set-TargetResource functionality with error message: User is not authorized to query the management service."
Everywhere i been searching is saying its not possible with AADDS.
thanks for the help
Apr 10 2019 07:11 AM
Hi Stavros,
I do not think I did anything special. I simply followed the steps to add AADDS in a very detailed fashion. (I assume you also have done that and verified that you can join a computer to the domain)
FYI: I am using 2016 datacenter as the base for my session host image.
I then followed the detailed steps in https://docs.microsoft.com/en-us/azure/virtual-desktop/ Tutorial.
(Go back and re-read and make sure you have not missed any steps.)
FYI: I used the following options
- Shared desktop
- 2 VM
- Pretty much default all the way.
I have tested many times and never had any problems even when moving to ARM Template use.
Again - very hard to speculate on what problem you may be hitting, but maybe it is not related AADDS use.
Hope this can help in some small way.
Cheers,
Johan
Apr 10 2019 07:19 AM
Thanks for your quick reply the only thing i am doing different is i was using the windows 10 enterprise mulit session instead of you are using server 2016 datacenter wonder if that could be causing the issue
Apr 10 2019 11:27 AM
@Stavros Mitchell : It should not matter which OS you're basing it off of. With the error you're hitting, make sure that you can install the PowerShell locally and connect with the same username or service principal. If it's a user and requires MFA, then deploying the Azure Marketplace offering will fail because MFA cannot happen in the background.
Apr 15 2019 03:50 AM
Thanks. I have this working now using Azure ADDS. Documentation seemed a bit unclear when I first looked at it
Apr 18 2019 08:22 AM
How were you able to get the machine to connect to the domain mine failed on domain join wondering If i can somehow do it manually
May 02 2019 06:02 AM
@HandA Did you get it to work without need of on-premise AD or AD Connect?
May 02 2019 06:23 AM
May 02 2019 03:46 PM
@Alberto Rodriguez : Do you have access to those VMs? If you can RDP into them, please look at C:\Packages and navigate down to the JsonADDomainExtension folder, you should be able to find a "status" file (or equivalent). If you open it up, it will typically give you the reason that it errored out. Unfortunately, I do not have too many details at the moment because the documentation on the extension is fairly light.
May 03 2019 04:52 AM
@Christian_Montoya [{"version":"1","timestampUTC":"2019-05-02T15:37:19.805151Z","status":{"name":"ADDomainExtension","operation":"Join Domain/Workgroup","status":"error","code":1,"
formattedMessage":{"lang":"en-US","message":"Exception(s) occured while joining Domain 'azure.mnetpr.com'"},"substatus":[{"name":"JoinDomainException for Option 3 meaning 'User Specified'","status":"error","code":1,"formattedMessage":{"lang":"en-US","message":"ERROR - Failed to join domain='azure.mnetpr.com', ou='', user='arodriguez@azure.mnetpr.com', option='NetSetupJoinDomain, NetSetupAcctCreate' (#3 meaning 'User Specified'). Error code 1326"}},{"name":"JoinDomainException for Option 1 meaning 'User Specified without NetSetupAcctCreate'","status":"error","code":1,"formattedMessage":{"lang":"en-US","message":"ERROR - Failed to join domain='azure.mnetpr.com', ou='', user='arodriguez@azure.mnetpr.com', option='NetSetupJoinDomain'
(#1 meaning 'User Specified without NetSetupAcctCreate'). Error code 1909"}}]}}]
May 09 2019 07:05 PM
This worked for me - after adding a custom domain and changing the admin user from the onmicrosoft.com address.
M.
May 22 2019 01:44 AM
Oct 23 2019 01:07 PM
I am currently syncing users and groups with password Hash sync (from on-prem ad to cloud)
To deploy WVD do I also have to enable single sign-on and pass-trough authentication and having Domain services running in Azure?
Oct 23 2019 01:10 PM
I am currently syncing users and groups with password Hash sync (from on-prem ad to cloud)
To deploy WVD do I also have to enable single sign-on and pass-trough authentication with AD Connect and having Domain services running in Azure?
Oct 23 2019 01:13 PM
I am currently syncing users and groups with password Hash sync (from on-prem ad to cloud)
To deploy WVD do I also have to enable single sign-on and pass-trough authentication with AD Connect and having Domain services running in Azure?
Nov 11 2019 12:55 PM
@LA99-999_ : If you are using password hash sync, you should be good to go. Because you are already syncing the password hashes, you can choose either of the two options for your Active Directory in your virtual network:
a. Connect your network to your on-premises infrastructure with an ExpressRoute or Site-to-Site VPN, then domain-join your VMs to that Active Directory.
or
b. Enable Azure AD Domain Services in your Azure subscription, then domain-join your VMs to that Active Directory.
Nov 28 2019 10:46 AM
@Christian_Montoya @Josh Bender @Mike Amox
If we choose option "b.", does the scenario support hybrid Azure AD join for the VMs joined to Azure AD DS ?
According to documentation for Azure AD Domain Services it is not supported to sync from Azure AD DS to Azure AD.
Any news on support for "100% cloud"? Would love to see this :)
Dec 04 2019 12:10 PM
@Marcel Biebricher : No, it does not. VMs domain-joined to the Azure AD DS instance cannot be configured to be hybrid, as Azure AD DS does not allow that.
We're continuing to investigate the "100% cloud" scenario, but nothing to report at this time.
Mar 10 2020 01:42 PM
Mar 10 2020 01:44 PM
I have WVD running in a production environment and it is critical to business what I can say to get this going with aads you need to setup just about everything in powershell first then do your deployment. There is a document floating around here that helped me greatly. @415Group_Ray