Does MFA Work? & Oops, we couldn't connect to "Session Desktop"

%3CLINGO-SUB%20id%3D%22lingo-sub-389011%22%20slang%3D%22en-US%22%3EDoes%20MFA%20Work%3F%20%26amp%3B%20Oops%2C%20we%20couldn't%20connect%20to%20%22Session%20Desktop%22%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389011%22%20slang%3D%22en-US%22%3E%3CP%3EI%20can't%20seem%20to%20connect%20to%20a%20WVD%20host%20after%20following%20the%20tutorial.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20my%20account%20(MFA%20enforced)%2C%20access%20via%20the%20web%20prompts%20for%20a%20password%20again%2C%20then%20gives%20the%20error%3A%20Oops%2C%20we%20couldn't%20connect%20to%20%22Session%20Desktop%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20551px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F100186iF9208689336BBD18%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Screenshot%202019-03-26%20at%203.11.34%20PM.png%22%20title%3D%22Screenshot%202019-03-26%20at%203.11.34%20PM.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAccess%20via%20the%20desktop%20client%20gets%20stuck%20in%20a%20loop%2C%20asking%20for%20my%20password%20over%20and%20over.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20Powershell%20diagnostics%20(via%20Get-RdsDiagnosticActivities)%20shows%20a%20%22Failure%22%20with%20each%20attempt%20--%20but%20no%20more%20details%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EActivityId%20%3A%20f5dfe22c-9ec7-4c49-be1e-ab5658900000%3CBR%20%2F%3EActivityType%20%3A%20Connection%3CBR%20%2F%3EStartTime%20%3A%203%2F26%2F2019%202%3A02%3A37%20PM%3CBR%20%2F%3EEndTime%20%3A%203%2F26%2F2019%202%3A02%3A56%20PM%3CBR%20%2F%3EUserName%20%3A%20***%3CBR%20%2F%3ERoleInstances%20%3A%20rdwebclient%3Bmrs-eus2r1c002-rdgateway-prod-staging%3A%3ARD0003FF459F62%3Bmrs-eus2r1c002-rdbroker-prod-stag%3CBR%20%2F%3Eing%3A%3ARD0003FF45DF76%3B%E2%89%A4ahp-0.contoso.com%E2%89%A5%3CBR%20%2F%3EOutcome%20%3A%20Failure%3CBR%20%2F%3EStatus%20%3A%20Completed%3CBR%20%2F%3EDetails%20%3A%20%7B%5BClientOS%2C%20Linux%20x86_64%20Chrome%2073.0.3683.88%5D%2C%20%5BClientVersion%2C%201.0.13-wvd%5D%2C%20%5BClientType%2C%20HTML%5D%2C%3CBR%20%2F%3E%5BPredecessorConnectionId%2C%20%5D...%7D%3CBR%20%2F%3ELastHeartbeatTime%20%3A%203%2F26%2F2019%202%3A02%3A56%20PM%3CBR%20%2F%3ECheckpoints%20%3A%20%7BLoadBalancedNewConnection%7D%3CBR%20%2F%3EErrors%20%3A%20%7BMicrosoft.RDInfra.Diagnostics.Common.DiagnosticsErrorInfo%7D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20else%20seeing%20this%3F%20I'm%20tempted%20to%20blame%20MFA%20but%20...%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-393189%22%20slang%3D%22en-US%22%3ERe%3A%20Does%20MFA%20Work%3F%20%26amp%3B%20Oops%2C%20we%20couldn't%20connect%20to%20%22Session%20Desktop%22%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-393189%22%20slang%3D%22en-US%22%3E%3CP%3EClosing%20the%20loop%20here%20--%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20were%20using%20Azure%20AD%20online%20only%20(with%20Azure%20AD%20joined%20desktops)%20%26amp%3B%20just%20added%20Azure%20AD%20Domain%20Services%20for%20WVD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EApparently%20enabling%20Azure%20AD%20Domain%20Services%20doesn't%20sync%20passwords%20to%20the%20Cloud%20DC%20on%20login%20--%20you%20have%20to%20change%20user%20passwords%20for%20hashes%20to%20sync%20to%20the%20DC%20(which%20is%20what%20caused%20this%20error).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-391082%22%20slang%3D%22en-US%22%3ERe%3A%20Does%20MFA%20Work%3F%20%26amp%3B%20Oops%2C%20we%20couldn't%20connect%20to%20%22Session%20Desktop%22%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-391082%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F54051%22%20target%3D%22_blank%22%3E%40Nicholas%20Semenkovich%3C%2FA%3E%26nbsp%3B%3A%20Can%20you%20run%20the%20same%20query%20and%20save%20the%20object%20to%20a%20variable%2C%20then%20look%20at%20the%20errors%20by%20expanding%20the%20Errors%20property%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%2C%20some%20quick%20steps%20to%20troubleshoot...does%20the%20user%20exist%20both%20in%20Azure%20AD%26nbsp%3B%3CSTRONG%3Eand%3C%2FSTRONG%3E%20your%20Windows%20Server%20AD%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

I can't seem to connect to a WVD host after following the tutorial. 

 

With my account (MFA enforced), access via the web prompts for a password again, then gives the error: Oops, we couldn't connect to "Session Desktop"

 

Screenshot 2019-03-26 at 3.11.34 PM.png

 

Access via the desktop client gets stuck in a loop, asking for my password over and over.

 

The Powershell diagnostics (via Get-RdsDiagnosticActivities) shows a "Failure" with each attempt -- but no more details:

 

ActivityId : f5dfe22c-9ec7-4c49-be1e-ab5658900000
ActivityType : Connection
StartTime : 3/26/2019 2:02:37 PM
EndTime : 3/26/2019 2:02:56 PM
UserName : ***
RoleInstances : rdwebclient;mrs-eus2r1c002-rdgateway-prod-staging::RD0003FF459F62;mrs-eus2r1c002-rdbroker-prod-stag
ing::RD0003FF45DF76;≤ahp-0.contoso.com≥
Outcome : Failure
Status : Completed
Details : {[ClientOS, Linux x86_64 Chrome 73.0.3683.88], [ClientVersion, 1.0.13-wvd], [ClientType, HTML],
[PredecessorConnectionId, ]...}
LastHeartbeatTime : 3/26/2019 2:02:56 PM
Checkpoints : {LoadBalancedNewConnection}
Errors : {Microsoft.RDInfra.Diagnostics.Common.DiagnosticsErrorInfo}

 

Anyone else seeing this? I'm tempted to blame MFA but ... ?

2 Replies
Highlighted

@Nicholas Semenkovich : Can you run the same query and save the object to a variable, then look at the errors by expanding the Errors property?

 

Also, some quick steps to troubleshoot...does the user exist both in Azure AD and your Windows Server AD?

Highlighted

Closing the loop here --

 

We were using Azure AD online only (with Azure AD joined desktops) & just added Azure AD Domain Services for WVD.

 

Apparently enabling Azure AD Domain Services doesn't sync passwords to the Cloud DC on login -- you have to change user passwords for hashes to sync to the DC (which is what caused this error).