Forum Discussion

Sriselvam92's avatar
Sriselvam92
Copper Contributor
Sep 09, 2026

Storage accounts needs to be exclude in sign in frequency CA policies in Mulit session environment

We have stroage accounts file share where the users profile will store and we are using for fslogix in multi session hosts users are reporting facing disconnect after sometimes loggedin to the vdi while checking signin logs we can failure for signin frequency ca policies,do we need to completely exclude the storage account from the ca policies

3 Replies

  • In a multi‑session Azure Virtual Desktop (AVD) environment using FSLogix profile containers, Conditional Access (CA) policies that enforce sign‑in frequency can interrupt the session because the storage account hosting the FSLogix file share performs background authentication using service tokens. When those tokens expire or are re‑challenged by CA, the session loses access to the profile container, causing disconnects or profile unload failures.

     

    https://learn.microsoft.com/en-us/fslogix/how-to-configure-profile-container-azure-files-active-directory?tabs=adds

     

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-session-lifetime

     

  • I would not exclude your storage accounts from every Conditional Access policy based only on the disconnections. First identify the failed sign-in's resource, error code, and applied policy, and confirm whether the Azure Files share uses Microsoft Entra Kerberos or another authentication method. Microsoft documents an MFA limitation for Azure Files with Entra Kerberos: its storage-account application must be excluded from policies requiring MFA because that SMB authentication flow cannot satisfy MFA. That is not a blanket recommendation to remove all storage-related Conditional Access controls, nor proof that sign-in frequency caused these session drops. Correlate the failed sign-in with the AVD disconnect and FSLogix logs. Determine whether the affected resource is the storage application, Azure Virtual Desktop, or Windows Cloud Login. Have your identity administrator test only the relevant policy change on a pilot group, retaining AVD authentication protections and file permissions.

    • Sriselvam92's avatar
      Sriselvam92
      Copper Contributor

      Yes we are configured with entra kerbros and we noted the signin logs failure for the storage accounts and see error related to refresh token.so we need to keep the session timelimit 8 hours and exclude the storage accounts from this signin frequency ca policy