Public Preview - Azure AD & Intune join for AVD - Session host unavailable

%3CLINGO-SUB%20id%3D%22lingo-sub-2553138%22%20slang%3D%22en-US%22%3EPublic%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2553138%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%20-%20I%20am%20using%20a%20public%20preview%20feature%20on%20Azure%20Virtual%20Desktop%20to%20join%20AAD%20and%20Intune%20(Pls%20see%20below%20article)%2C%20although%20the%20VM%20was%20AAD%20registered%20and%20Intune%20enrolled%2C%20the%20session%20host%20was%20unavailable%20(%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3ESessionHost%26nbsp%3Bunhealthy%3A%26nbsp%3BSessionHost%26nbsp%3Bis%26nbsp%3Bnot%26nbsp%3Bjoined%26nbsp%3Bto%26nbsp%3Ba%26nbsp%3Bdomain).%20This%20is%20because%20of%20the%20fact%20that%20there%20was%20no%20AD%20join%20details%20available%20on%20the%20AVD%20deployment%20interface%2FUI.%26nbsp%3B%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EDoes%20AVD%20need%20to%20be%20Domain%20joined%20as%20well%20for%20the%20session%20host%20to%20be%20available%3F%20A%20VM%20can%20either%20be%20joined%20to%20AAD%20or%20AD%20and%20hence%20i%20am%20bit%20stuck%20with%20the%20preview%20feature.%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fblog%2Fazure-virtual-desktop-the-desktop-and-app-virtualization-platform-for-the-hybrid-workplace%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fblog%2Fazure-virtual-desktop-the-desktop-and-app-virtualization-platform-for-the-hybrid-workplace%2F%3C%2FA%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%23AzureVirtualDesktop%20%23AADJoin%20%23Intune%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2558319%22%20slang%3D%22en-US%22%3ERe%3A%20Public%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2558319%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F883446%22%20target%3D%22_blank%22%3E%40Nikonline%3C%2FA%3E%2C%3CBR%20%2F%3EDid%20you%20put%20the%20Validation%20Environment%20to%20Yes%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2561701%22%20slang%3D%22en-US%22%3ERe%3A%20Public%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2561701%22%20slang%3D%22en-US%22%3EHi%20Johan%2C%20thanks%20for%20responding.%20well%20it%20did%20make%20the%20machine%20available%2C%20was%20able%20to%20login%20locally%2C%20however%20i%20am%20till%20unable%20to%20login%20with%20my%20AAD%20creds.%20When%20i%20checked%20locally%20i%20could%20see%20my%20AAD%20user%20account%20has%20rights%20to%20login%20remotely%20so%20not%20sure%20why%20the%20Authentication%20is%20failing.%20Does%20this%20machine%20need%20to%20be%20Azure%20ADDS%20joined%20(we%20dont%20have%20on%20prem%20AD)%3F%3CBR%20%2F%3EError%20message%20-%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20couldn't%20connect%20to%20the%20remote%20PC%20because%20your%20credentials%20did%20not%20work.%20The%20remote%20machine%20is%20AAD%20joined.%20If%20you%20are%20using%20your%20work%20account%20you%20must%20disable%20Network%20Level%20Authentication%20on%20the%20remote%20machine.%20If%20you%20are%20using%20a%20local%20account%2C%20verify%20your%20username%20and%20password.%3CBR%20%2F%3E%3CBR%20%2F%3EError%20code%3A%200x2607%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2561721%22%20slang%3D%22en-US%22%3ERe%3A%20Public%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2561721%22%20slang%3D%22en-US%22%3EDid%20you%20assign%20the%20user%20the%20virtual%20machine%20user%20login%20role%20on%20the%20resource%20group%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2561750%22%20slang%3D%22en-US%22%3ERe%3A%20Public%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2561750%22%20slang%3D%22en-US%22%3Eyes%2C%20assigned%20the%20role%20despite%20being%20Owner%20on%20the%20RG.%20Still%20the%20same%20error.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2563603%22%20slang%3D%22en-US%22%3ERe%3A%20Public%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2563603%22%20slang%3D%22en-US%22%3EIs%20you%20local%20security%20policy%20disabled%20to%20allow%20cloud%20accounts%20to%20logon%20to%20the%20machine%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2567416%22%20slang%3D%22en-US%22%3ERe%3A%20Public%20Preview%20-%20Azure%20AD%20%26amp%3B%20Intune%20join%20for%20AVD%20-%20Session%20host%20unavailable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2567416%22%20slang%3D%22en-US%22%3EAble%20to%20login%20to%20standalone%20VM%20using%20Azure%20AD%20user%20account%20(after%20disabling%20CAPs)%20however%20still%20unable%20to%20login%20to%20the%20AVD%20session%20host.%20After%20checking%20the%20connection%20logs%20i%20see%20this%20error%3CBR%20%2F%3E%3CBR%20%2F%3EAuthenticationLogonFailedAAD%20(9735)%20-%20User%20credentials%20did%20not%20work.%20Remote%20machine%20is%20AAD%20joined.%20If%20you%20are%20signing%20in%20to%20your%20work%20account%2C%20try%20using%20your%20work%20email%20address.%3CBR%20%2F%3E23%3CBR%20%2F%3E%3CBR%20%2F%3EChecked%20on%20the%20host%20VM%20it%20does%20have%20remote%20login%20permission%20for%20the%20user%20however%20still%20failing%20to%20Authenticate.%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi All - I am using a public preview feature on Azure Virtual Desktop to join AAD and Intune (Pls see below article), although the VM was AAD registered and Intune enrolled, the session host was unavailable (

SessionHost unhealthy: SessionHost is not joined to a domain). This is because of the fact that there was no AD join details available on the AVD deployment interface/UI. 
Does AVD need to be Domain joined as well for the session host to be available? A VM can either be joined to AAD or AD and hence i am bit stuck with the preview feature.
 

 

#AzureVirtualDesktop #AADJoin #Intune

7 Replies
Hi @Nikonline,
Did you put the Validation Environment to Yes?
Hi Johan, thanks for responding. well it did make the machine available, was able to login locally, however i am till unable to login with my AAD creds. When i checked locally i could see my AAD user account has rights to login remotely so not sure why the Authentication is failing. Does this machine need to be Azure ADDS joined (we dont have on prem AD)?
Error message -

We couldn't connect to the remote PC because your credentials did not work. The remote machine is AAD joined. If you are using your work account you must disable Network Level Authentication on the remote machine. If you are using a local account, verify your username and password.

Error code: 0x2607
Did you assign the user the virtual machine user login role on the resource group?
yes, assigned the role despite being Owner on the RG. Still the same error.
Is you local security policy disabled to allow cloud accounts to logon to the machine?
Able to login to standalone VM using Azure AD user account (after disabling CAPs) however still unable to login to the AVD session host. After checking the connection logs i see this error

AuthenticationLogonFailedAAD (9735) - User credentials did not work. Remote machine is AAD joined. If you are signing in to your work account, try using your work email address.
23

Checked on the host VM it does have remote login permission for the user however still failing to Authenticate.
Was able to login, good starting point https://docs.microsoft.com/en-us/azure/virtual-desktop/deploy-azure-ad-joined-vm
Summary - Enabled Validation environment, Disabled MFA, CAPs, RDP setting changes at hostpool level.
So now that makes me feel nervous and in search of securing AVD access... phew!