Domian jonin failed when add VM

%3CLINGO-SUB%20id%3D%22lingo-sub-1561206%22%20slang%3D%22en-US%22%3EDomian%20jonin%20failed%20when%20add%20VM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1561206%22%20slang%3D%22en-US%22%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3EHi%2C%20I'm%20new%20to%20azure%2C%20I%20try%20create%20virtual%20desktop%20on%20azure.%20I%20create%20a%20new%20AD%20domain%20servcie%20and%20network%2C%20when%20I%20create%20host%20pool%20and%20new%20new%20VM%2C%20I%20get%20error%20with%20joindomain%20failed.%20Can%20someone%20help%20me%20here%3F%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3E%5B%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%7B%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22code%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22ComponentStatus%2FJoinDomainException%26nbsp%3Bfor%26nbsp%3BOption%26nbsp%3B3%26nbsp%3Bmeaning%26nbsp%3B'User%26nbsp%3BSpecified'%2Ffailed%2F1%22%3C%2FSPAN%3E%3CSPAN%3E%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22level%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22Error%22%3C%2FSPAN%3E%3CSPAN%3E%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22displayStatus%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22Provisioning%26nbsp%3Bfailed%22%3C%2FSPAN%3E%3CSPAN%3E%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22message%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22ERROR%26nbsp%3B-%26nbsp%3BFailed%26nbsp%3Bto%26nbsp%3Bjoin%26nbsp%3Bdomain%3D'xxxx.onmicrosoft.com'%2C%26nbsp%3Bou%3D''%2C%26nbsp%3Buser%3D'xxxx%40xx.com'%2C%26nbsp%3Boption%3D'NetSetupJoinDomain%2C%26nbsp%3BNetSetupAcctCreate'%26nbsp%3B(%233%26nbsp%3Bmeaning%26nbsp%3B'User%26nbsp%3BSpecified').%26nbsp%3BError%26nbsp%3Bcode%26nbsp%3B1909%22%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%7D%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%7B%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22code%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22ComponentStatus%2FJoinDomainException%26nbsp%3Bfor%26nbsp%3BOption%26nbsp%3B1%26nbsp%3Bmeaning%26nbsp%3B'User%26nbsp%3BSpecified%26nbsp%3Bwithout%26nbsp%3BNetSetupAcctCreate'%2Ffailed%2F1%22%3C%2FSPAN%3E%3CSPAN%3E%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22level%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22Error%22%3C%2FSPAN%3E%3CSPAN%3E%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22displayStatus%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22Provisioning%26nbsp%3Bfailed%22%3C%2FSPAN%3E%3CSPAN%3E%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22message%22%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%22ERROR%26nbsp%3B-%26nbsp%3BFailed%26nbsp%3Bto%26nbsp%3Bjoin%26nbsp%3Bdomain%3D'xxx.onmicrosoft.com'%2C%26nbsp%3Bou%3D''%2C%26nbsp%3Buser%3D'xxxx%40xxxxx.com'%2C%26nbsp%3Boption%3D'NetSetupJoinDomain'%26nbsp%3B(%231%26nbsp%3Bmeaning%26nbsp%3B'User%26nbsp%3BSpecified%26nbsp%3Bwithout%26nbsp%3BNetSetupAcctCreate').%26nbsp%3BError%26nbsp%3Bcode%26nbsp%3B1909%22%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%7D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%5D%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1561352%22%20slang%3D%22en-US%22%3ERe%3A%20Domian%20jonin%20failed%20when%20add%20VM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1561352%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20you%20create%20a%20host%20pool%2C%20you%20must%20specify%20the%20name%20of%20the%20domain%20that%20you%20use%20with%20your%20%22local%22%20Active%20Directory.%20For%20example%3A%20contoso.priImportant%2C%20you%20must%20also%20specify%20an%20account%20which%20has%20sufficient%20rights%20to%20perform%20the%20join.%20Regards%20Tom%20Wechsler%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F747196%22%20target%3D%22_blank%22%3E%40xuzhang3%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1564209%22%20slang%3D%22en-US%22%3ERe%3A%20Domian%20jonin%20failed%20when%20add%20VM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1564209%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F747196%22%20target%3D%22_blank%22%3E%40xuzhang3%3C%2FA%3E%26nbsp%3BIs%20it%20possible%20the%20account%20you%20are%20using%20is%20locked%3F%20The%20error%201909%20usually%20means%3C%2FP%3E%3CP%3E%22The%20referenced%20account%20is%20currently%20locked%20out%20and%20may%20not%20be%20logged%20on%20to%22%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fwin32%2Fdebug%2Fsystem-error-codes--1700-3999-%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fwin32%2Fdebug%2Fsystem-error-codes--1700-3999-%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1572939%22%20slang%3D%22en-US%22%3ERe%3A%20Domian%20jonin%20failed%20when%20add%20VM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1572939%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F747196%22%20target%3D%22_blank%22%3E%40xuzhang3%3C%2FA%3E%26nbsp%3BAre%20you%20using%20a%20traditional%20domain%20controller%20in%20Azure%20AD%3F%26nbsp%3B%20If%20so%2C%20did%20you%20modify%20the%20VNET%20DNS%20settings%20to%20point%20to%20your%20domain%20controller.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20trying%20to%20join%20Azure%20AD%20Domain%20Services%20with%20accounts%20synced%20from%20on%20premise%20you%20need%20to%20apply%20the%20DNS%20settings%20to%20the%20VNET%20for%20Azure%20ad%20Domain%20services%20(so%20that%20VNET%20is%20servicing%20that%20vnet)%20although%20its%20recommended%20that%20you%20do%20not%20deploy%20WVD%20directly%20to%20the%20same%20VNET%20that%20is%20hosting%20Azure%20AD%20DS.%26nbsp%3B%20But%20rather%20create%20another%20peered%20network%20and%20use%20that.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EIf%20you%20are%20using%20Azure%20AD%20DS%2C%20then%20you%20need%20to%20make%20sure%20you%20have%20legacy%20password%20has%20synchronisation%20or%20you%20will%20get%20the%20account%20is%20locked%20message.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Ftutorial-configure-password-hash-sync%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory-domain-services%2Ftutorial-configure-password-hash-sync%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20will%20likely%20need%20to%20change%20the%20password%20for%20the%20specific%20account%20you%20want%20to%20use%20to%20join%20the%20domain%20first%20after%20the%20step%20above.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20find%20its%20easier%20to%20deploy%20a%20windows%2010%20VM%20and%20just%20try%20and%20join%20the%20domain%20first%2C%20fix%20that%20and%20your%20WVD%20deployment%20should%20work%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1561346%22%20slang%3D%22en-US%22%3ERe%3A%20Domian%20jonin%20failed%20when%20add%20VM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1561346%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20you%20create%20a%20host%20pool%2C%20you%20must%20specify%20the%20name%20of%20the%20domain%20that%20you%20use%20with%20your%20%22local%22%20Active%20Directory.%20For%20example%3A%20contoso.pri%3CBR%20%2F%3EImportant%2C%20you%20must%20also%20specify%20an%20account%20which%20has%20sufficient%20rights%20to%20perform%20the%20join.%3C%2FP%3E%3CP%3ERegards%2C%20Tom%20Wechsler%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F747196%22%20target%3D%22_blank%22%3E%40xuzhang3%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1561252%22%20slang%3D%22en-US%22%3ERe%3A%20Domian%20jonin%20failed%20when%20add%20VM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1561252%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20creating%20the%20host%20pool%2C%20you%20must%20specify%20your%20domain%20from%20your%20%22local%22%20Active%20Directory.%20For%20example%2C%20contoso.pri.%20Important%20you%20must%20also%20specify%20an%20account%20that%20has%20sufficient%20rights%20to%20perform%20the%20join%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F747196%22%20target%3D%22_blank%22%3E%40xuzhang3%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor
Hi, I'm new to azure, I try create virtual desktop on azure. I create a new AD domain servcie and network, when I create host pool and new new VM, I get error with joindomain failed. Can someone help me here?
 
[
    {
        "code""ComponentStatus/JoinDomainException for Option 3 meaning 'User Specified'/failed/1",
        "level""Error",
        "displayStatus""Provisioning failed",
        "message""ERROR - Failed to join domain='xxxx.onmicrosoft.com', ou='', user='xxxx@xx.com', option='NetSetupJoinDomain, NetSetupAcctCreate' (#3 meaning 'User Specified'). Error code 1909"
    },
    {
        "code""ComponentStatus/JoinDomainException for Option 1 meaning 'User Specified without NetSetupAcctCreate'/failed/1",
        "level""Error",
        "displayStatus""Provisioning failed",
        "message""ERROR - Failed to join domain='xxx.onmicrosoft.com', ou='', user='xxxx@xxxxx.com', option='NetSetupJoinDomain' (#1 meaning 'User Specified without NetSetupAcctCreate'). Error code 1909"
    }
]
5 Replies

When creating the host pool, you must specify your domain from your "local" Active Directory. For example, contoso.pri. Important you must also specify an account that has sufficient rights to perform the join

@xuzhang3 

When you create a host pool, you must specify the name of the domain that you use with your "local" Active Directory. For example: contoso.pri
Important, you must also specify an account which has sufficient rights to perform the join.

Regards, Tom Wechsler

@xuzhang3 

When you create a host pool, you must specify the name of the domain that you use with your "local" Active Directory. For example: contoso.priImportant, you must also specify an account which has sufficient rights to perform the join. Regards Tom Wechsler@xuzhang3 

@xuzhang3 Is it possible the account you are using is locked? The error 1909 usually means

"The referenced account is currently locked out and may not be logged on to" https://docs.microsoft.com/en-us/windows/win32/debug/system-error-codes--1700-3999-

 

@xuzhang3 Are you using a traditional domain controller in Azure AD?  If so, did you modify the VNET DNS settings to point to your domain controller.

 

If you are trying to join Azure AD Domain Services with accounts synced from on premise you need to apply the DNS settings to the VNET for Azure ad Domain services (so that VNET is servicing that vnet) although its recommended that you do not deploy WVD directly to the same VNET that is hosting Azure AD DS.  But rather create another peered network and use that.


If you are using Azure AD DS, then you need to make sure you have legacy password has synchronisation or you will get the account is locked message.

 

https://docs.microsoft.com/en-us/azure/active-directory-domain-services/tutorial-configure-password-...

 

You will likely need to change the password for the specific account you want to use to join the domain first after the step above.

 

I find its easier to deploy a windows 10 VM and just try and join the domain first, fix that and your WVD deployment should work