SOLVED

Azure VD - AD/AADDS Required?

%3CLINGO-SUB%20id%3D%22lingo-sub-2809880%22%20slang%3D%22en-US%22%3EAzure%20VD%20-%20AD%2FAADDS%20Required%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2809880%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20trying%20to%20set%20up%20an%20Azure%20Virtual%20Desktop%20test%20lab%20for%20evaluation%20purposes.%20I've%20created%20a%20new%20test%20Azure%20tenant%20with%20some%20M365%20Business%20Premium%20licenses.%20I've%20added%20some%20dummy%20test%20users%2C%20assigned%20M365%20licenses%20to%20them%20and%20ADD%20joined%20a%20couple%20of%20Windows%2010%20laptops%20using%20Autopilot.%20This%20is%20all%20work%20great.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20i%20have%20read%20Azure%20Virtual%20Desktop%20either%20requires%20Active%20Directory%20or%20AADDS%2C%20therefore%2C%20i've%20deployed%20AADDS%20to%20the%20tenant.%20Next%20i've%20then%20deployed%20a%20new%20AVD%20host%20pool%20using%20the%20following%20settings%3A%3CBR%20%2F%3E%26nbsp%3B-%20Host%20Pool%20Type%20%3D%20Pooled%3CBR%20%2F%3E%26nbsp%3B-%20LB%20%3D%20Breath-first%3CBR%20%2F%3E%26nbsp%3B-%20Max%20Sessions%20limit%20%3D%2010%3CBR%20%2F%3E%26nbsp%3B-%20Number%20of%20Hosts%20%3D%202%3CBR%20%2F%3E%26nbsp%3B-%20Image%20%3D%20Gallery%20%2F%20Win10Ent%20MultiSession%2020H2%20Gen2%3CBR%20%2F%3E%26nbsp%3B-%20%3CSTRONG%3EDomain%20to%20join%20%3D%20Azure%20AD%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20AVD%20deployment%20completes%20and%20i've%20assigned%20users%20to%20the%20application%20group.%20However%2C%20when%20i%20attempt%20to%20log%20into%20AVD%20(via%20browser%20or%20Remote%20Desktop%20app)%20it%20prompts%20me%20for%20logon%20credentials%20but%20then%20fails%20to%20connect%20with%20an%20error%20%22invalid%20credentials%22.%20I%20know%20the%20credentials%20are%20correct!%20I've%20delete%20the%20AVD%20host%20pool%2C%20resource%20groups%2C%20vms%2C%20etc%20and%20set%20it%20all%20up%20again%20from%20scratch%20but%20i%20still%20get%20the%20same%20error!%20I'm%20obviously%20missing%20something%20here%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%20can%20see%20the%20both%20the%20Azure%20VD%20hosts%20are%20shown%20in%20Azure%20AD%20%26gt%3B%20Device%20and%20both%20are%20listed%20in%20Intune%20as%20(managed%20by%20intune%2Fcompliant).%20I've%20also%20setup%20an%20Azure%20management%20VM%20(Win2016)%2C%20joined%20this%20to%20AADDS%20and%20installed%20the%20RSAT%20tools.%20Using%20the%20AD%20Users%20and%20Computers%20console%20I%20can%20see%20all%20the%20users%20(which%20i%20created%20in%20Azure%20AD)%20have%20sync'd%20over%20but%20i%20cant%20see%20the%20two%20VD%20host%20devices%3F%3CBR%20%2F%3E%3CBR%20%2F%3EDo%20i%20need%20actually%20need%20AD%20or%20AADDS%20as%20the%20Azure%20Virtual%20Desktop%20deployment%20wizard%20allows%20me%20to%20select%20'Azure%20AD'%20under%20'Domain%20to%20Join'%20and%20then%20there's%20no%20mention%20of%20AD%2FAADDS%20during%20the%20wizard.%26nbsp%3B%20If%20i%20can%20remove%20AADDS%20and%20the%20Win2016%20management%20vm%20that%20would%20be%20great.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2813157%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VD%20-%20AD%2FAADDS%20Required%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2813157%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F837583%22%20target%3D%22_blank%22%3E%40PhilPreece1010%3C%2FA%3EHey%20Phil.%26nbsp%3B%20Did%20you%20resolve%20this%20in%20the%20end%3F%26nbsp%3B%20I%20am%20also%20getting%20this%20same%20issue%20with%20the%20password.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20wonder%20if%20it's%20to%20do%20with%20MFA%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EVince%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2813919%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VD%20-%20AD%2FAADDS%20Required%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2813919%22%20slang%3D%22en-US%22%3EHi%20Vince%2C%20no%20still%20having%20issues.%3CBR%20%2F%3EEarlier%20today%20i%20cleaned%20up%20the%20Azure%20tenant%20once%20again.%20I%20deleted%20all%20the%20resources%20that%20were%20deployed%20by%20the%20AADDS%20wizard%20and%20the%20Azure%20Virtual%20Desktop%20wizard.%20I%20then%20successfully%20re-deployed%20AADDS%2C%20applied%20the%20recommended%20DNS%20fix%20and%20ran%20the%20AVD%20wizard%20again.%20This%20time%20i%20selected%20'domain%20to%20join%20%3D%20AADDS'%20but%20the%20wizard%20failed%20again.%20This%20time%20with%20a%20different%20error%3A%3CBR%20%2F%3E%3CBR%20%2F%3Eeasy-button-inputvalidation-job-linked-template%20-%20conflict%3CBR%20%2F%3E%3CBR%20%2F%3EI%20do%20have%20MFA%20enabled%20for%20all%20users%3F%20Perhaps%20that%20is%20the%20issue%20then%3F%3C%2FLINGO-BODY%3E
Occasional Contributor

I'm trying to set up an Azure Virtual Desktop test lab for evaluation purposes. I've created a new test Azure tenant with some M365 Business Premium licenses. I've added some dummy test users, assigned M365 licenses to them and ADD joined a couple of Windows 10 laptops using Autopilot. This is all work great.

 

From what i have read Azure Virtual Desktop either requires Active Directory or AADDS, therefore, i've deployed AADDS to the tenant. Next i've then deployed a new AVD host pool using the following settings:
 - Host Pool Type = Pooled
 - LB = Breath-first
 - Max Sessions limit = 10
 - Number of Hosts = 2
 - Image = Gallery / Win10Ent MultiSession 20H2 Gen2
 - Domain to join = Azure AD

The AVD deployment completes and i've assigned users to the application group. However, when i attempt to log into AVD (via browser or Remote Desktop app) it prompts me for logon credentials but then fails to connect with an error "invalid credentials". I know the credentials are correct! I've delete the AVD host pool, resource groups, vms, etc and set it all up again from scratch but i still get the same error! I'm obviously missing something here?

I can see the both the Azure VD hosts are shown in Azure AD > Device and both are listed in Intune as (managed by intune/compliant). I've also setup an Azure management VM (Win2016), joined this to AADDS and installed the RSAT tools. Using the AD Users and Computers console I can see all the users (which i created in Azure AD) have sync'd over but i cant see the two VD host devices?

Do i need actually need AD or AADDS as the Azure Virtual Desktop deployment wizard allows me to select 'Azure AD' under 'Domain to Join' and then there's no mention of AD/AADDS during the wizard.  If i can remove AADDS and the Win2016 management vm that would be great.

8 Replies
Hi,
For personal hostpool you don't need ADDS or AADDS but can use AAD only.
For pooled hostpools you still require ADDS or AADDS.

For your logon issue:

Have you given Virtual Machine User login role to the users?
Have you specified in the advanced properties that the session host is AAD joined?

Here is the link to the doc's. If you need help just contact me.
https://docs.microsoft.com/en-us/azure/virtual-desktop/deploy-azure-ad-joined-vm

@PhilPreece1010Hey Phil.  Did you resolve this in the end?  I am also getting this same issue with the password.

 

I wonder if it's to do with MFA?

 

Thanks

Vince

best response confirmed by PhilPreece1010 (Occasional Contributor)
Solution
Hi Vince, no still having issues.
Earlier today i cleaned up the Azure tenant once again. I deleted all the resources that were deployed by the AADDS wizard and the Azure Virtual Desktop wizard. I then successfully re-deployed AADDS, applied the recommended DNS fix and ran the AVD wizard again. This time i selected 'domain to join = AADDS' but the wizard failed again. This time with a different error:

easy-button-inputvalidation-job-linked-template - conflict

I do have MFA enabled for all users? Perhaps that is the issue then?
If you use the quickstart wizard you need to use an account that doesn't have MFA enabled. If you check the runbook behind the getting started wizard it will give you that error message.

If you create AADDS with the wizard you also need to make sure that your custom domain is added otherwise the wizard will fail also.
I think your right Vince, i've just stumbled across this article:

https://techcommunity.microsoft.com/t5/azure-virtual-desktop/getting-started-wizard-in-azure-virtual...

2. Requirements and limitations
Accounts used with getting started cannot have MFA.
Phil, correct it's my understanding that MFA is not yet supported when using AAD joined VM's and trying to login to them via AVD. I could be wrong but maybe worth a shot. I will also test this myself tomorrow and let you know.
Thanks all for the assistance. AVD has now deployed successfully.
Quick summary of the steps i took.
- Cleaned up Azure tenant (ie: deleted all the remnants of the failed AVD deployment, such as: adds, avd, all resources, etc).
- Used the AVD 'Getting Started' wizard (rather than 'deploy a host pool' option) and allowed this to build a new instance of Azure ADDS for me.
- Disabled MFA against the accounts i used in the AVD getting started wizard.
- Before logging into the AVD client i had to reset the test users password so the hash is sync'd back to ADDS.
Great News.