SOLVED

Azure AD Domain Services - DNS issues

%3CLINGO-SUB%20id%3D%22lingo-sub-1060957%22%20slang%3D%22en-US%22%3EAzure%20AD%20Domain%20Services%20-%20DNS%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1060957%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20having%20problems%20joining%20a%20VM%20to%20Azure%20AD%20Domain%20Services.%20The%20VM%20is%20in%20the%20same%20Vnet%20as%20AADDS%2C%20but%20in%20a%20different%20subnet%2C%20as%20the%20documentation%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Fjoin-windows-vm%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Fjoin-windows-vm%3C%2FA%3E)%20suggests.%3C%2FP%3E%3CP%3EThe%20VM%20does%20have%20IP-connectivity%20as%20I%20am%20able%20to%20ping%20both%20the%20AADDS%20nic's%20IP-addresses%20from%20the%20VM%2C%20but%20when%20I%20try%20to%20make%20the%20VM%20a%20domain%20member%20I%20get%20the%20good%20ole%20%22Domain%20Controller%20for%20the%20domain%20could%20not%20be%20contacted%22..%3C%2FP%3E%3CP%3ESince%20everything%20else%20is%20in%20order%2C%20I%20am%20wondering%20if%20there%20is%20anything%20I%20could%20or%20should%20do%20regarding%20DNS%20-%20since%20that's%20what%20seems%20to%20be%20the%20problem.%20I%20should%20NOT%20edit%20the%20DNS%20for%20the%20Vnet%20as%20this%20is%20the%20same%20Vnet%20as%20AADDS%2C%20and%20the%20only%20way%20I%20found%20so%20far%20is%20to%20edit%20using%20a%20member%20server.%20Which%20I%20am%20not%20able%20to%20deploy.%20Biting%20my%20tale%20over%20here.%3C%2FP%3E%3CP%3EAnyone%20have%20any%20idea%20what%20could%20be%20wrong%2C%20or%20how%20I%20could%20get%20out%20of%20this%20mess%3F%20Redeploy%20the%20whole%20thing%20-%20delete%20and%20start%20over%3F%3C%2FP%3E%3CP%3EAnything%20helpful%20is%20much%20appreciated!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1060957%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1065393%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Domain%20Services%20-%20DNS%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1065393%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20DNS%20settings%20do%20you%20have%20on%20the%20VNet%20that%20the%20server%20is%20a%20member%20of%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIP%20connectivity%20isn't%20enough%20Ii.e.%20the%20ability%20to%20ping%20the%20servers%20won't%20allow%20you%20to%20join%20to%20the%20domain).%20The%20virtual%20machine%20will%20need%20to%20be%20able%20to%20resolve%20the%20domain%20name%20of%20your%20Domain%20Services%20instance.%20What%20happens%20when%20you%20ping%20the%20domain%20name%2C%20and%20what%20DNS%20servers%20are%20your%20VM's%20receiving%20at%20the%20moment%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20expect%20this%20to%20work%20out%20of%20the%20box...%20I've%20configured%20this%20across%20disparate%20VNet%20instances%20before%2C%20peered%2C%20and%20with%20DNS%20servers%20set%20on%20the%20VM%20network%20to%20match%20that%20of%20the%20AADDS%20network.%20Never%20with%20a%20subnet%20that's%20int%20he%20same%20VNet%20as%20a%20DS%20instance%20though...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKelvin%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1072103%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Domain%20Services%20-%20DNS%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1072103%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F204415%22%20target%3D%22_blank%22%3E%40Kelvin%20Papp%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20reply%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20also%20deployed%20this%20numerous%20times%20without%20any%20problems.%20This%20time%20it%20was%20my%20own%20fault%2C%20not%20hitting%20the%20big%20blue%20button%20within%20Azure%20AD%20Domain%20Services%20to%20update%20DNS%20server%20settings%20for%20the%20Vnet.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20end%20I%20did%20manually%20edit%20the%20DNS%20servers%20of%20the%20Vnet%2C%20but%20ignored%20this%20button.%20The%20results%20on%20the%20Vnet%20are%20the%20exact%20same%2C%20but%20now%20deployed%20automagicly%2C%20and%20voila!%20Everything%20works%20as%20expected.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi all,

 

I am having problems joining a VM to Azure AD Domain Services. The VM is in the same Vnet as AADDS, but in a different subnet, as the documentation (https://docs.microsoft.com/en-us/azure/active-directory-domain-services/join-windows-vm) suggests.

The VM does have IP-connectivity as I am able to ping both the AADDS nic's IP-addresses from the VM, but when I try to make the VM a domain member I get the good ole "Domain Controller for the domain could not be contacted"..

Since everything else is in order, I am wondering if there is anything I could or should do regarding DNS - since that's what seems to be the problem. I should NOT edit the DNS for the Vnet as this is the same Vnet as AADDS, and the only way I found so far is to edit using a member server. Which I am not able to deploy. Biting my tale over here.

Anyone have any idea what could be wrong, or how I could get out of this mess? Redeploy the whole thing - delete and start over?

Anything helpful is much appreciated!

2 Replies
Highlighted
Best Response confirmed by HenrikBryne (New Contributor)
Solution

What DNS settings do you have on the VNet that the server is a member of?

 

IP connectivity isn't enough Ii.e. the ability to ping the servers won't allow you to join to the domain). The virtual machine will need to be able to resolve the domain name of your Domain Services instance. What happens when you ping the domain name, and what DNS servers are your VM's receiving at the moment?

 

I would expect this to work out of the box... I've configured this across disparate VNet instances before, peered, and with DNS servers set on the VM network to match that of the AADDS network. Never with a subnet that's int he same VNet as a DS instance though...

 

Kelvin

 

 

Highlighted

@Kelvin Papp Thanks for your reply,

 

I've also deployed this numerous times without any problems. This time it was my own fault, not hitting the big blue button within Azure AD Domain Services to update DNS server settings for the Vnet.

 

In the end I did manually edit the DNS servers of the Vnet, but ignored this button. The results on the Vnet are the exact same, but now deployed automagicly, and voila! Everything works as expected.