SOLVED

not able to connect to WVD from win64 client (latest)

%3CLINGO-SUB%20id%3D%22lingo-sub-1457606%22%20slang%3D%22en-US%22%3Enot%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1457606%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%3C%2FP%3E%3CP%3EJust%20finished%20my%20first%20WVD%20test-deployment%20based%20on%20ADDS.%20Everything%20is%20running%20fine%20except%20connections%20from%20windows%20x64%20based%20devices.%20HTML5%20web%20client%20and%20IOS%20Remote%20Desktop%20App%20work%20without%20issues.%20Installed%20Client%20version%201.2.1026.0%20using%20URL%26nbsp%3B%3CEM%3E%3CA%20href%3D%22https%3A%2F%2Frdweb.wvd.microsoft.com%2Fapi%2Farm%2Ffeeddiscovery%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Frdweb.wvd.microsoft.com%2Fapi%2Farm%2Ffeeddiscovery%3C%2FA%3E%3CA%20href%3D%22https%3A%2F%2Frdweb.wvd.microsoft.com%2Fapi%2Farm%2Ffeeddiscovery%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E.%3C%2FA%3E%3C%2FEM%3E%3C%2FP%3E%3CP%3ELogin%20is%20accepted%20and%20Workspace%20is%20visible.%20But%20when%20I%20try%20to%20connect%20to%20a%20published%20SessionDesktop%20the%20connection%20fails%20with%20a%20generic%20%22Remote%20Desktop%20can't%20connect%20to%20the%20remote%20computer%20for%20one%20of%20these%20reasons...%22%20(Error%20code%200x204).%3C%2FP%3E%3CP%3EI%20have%20and%20showcase%20tomorrow%20with%20the%20customer%20-%20any%20hints%3F%20Thanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458083%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458083%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F696999%22%20target%3D%22_blank%22%3E%40benjaminfrei%3C%2FA%3E%26nbsp%3BHi%2C%20it%20maybe%20a%20firewall%2Fantivirus%20issue%3F%3F%3F%20Try%20temporarily%20disabling%20your%20windows%20firewall%20or%20any%20antivirus%2Fmalware%20software%20you%20have%20on%20the%20windows%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20do%20you%20have%20another%20windows%20device%20you%20can%20test%20from%3F%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458090%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458090%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F235785%22%20target%3D%22_blank%22%3E%40Neil%20McLoughlin%3C%2FA%3E%26nbsp%3BGood%20morning!%20I%20tested%20the%20connection%20on%20three%20different%20devices%20and%20also%20disabled%20security%20modules%20like%20webfilter.%20all%20of%20them%20have%20managed%20bitdefender%20installer.%20I%20will%20do%20another%20test%20with%20disabled%2Funinstalled%20bitdefender%20and%20let%20you%20know.%20So%20my%20interpretation%20is%20correct%20that%20no%20pinholes%20on%20the%20azure%20side%20is%20required%20because%20all%20the%20traffic%20flows%20between%20the%20client%20-%20the%20azure%20frontdoor%20and%20then%20internally%20to%20the%20vm's%20via%20443%2Ftcp%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458102%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458102%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F235785%22%20target%3D%22_blank%22%3E%40Neil%20McLoughlin%3C%2FA%3E%26nbsp%3Bquestion%3A%20my%20ADDS%20setup%20(cloud%20only%20tennant%2C%20no%20on-prem%20AD)%20was%20build%20with%20the%20same%20top-leveld-domain%20as%20the%20public%20tenant%20has%20(split%20brain%20dns).%20In%20my%20understanding%20this%20should%20not%20be%20a%20problem%2C%20also%20when%20using%20azure%20connected%20enddevices.%20do%20you%20agree%20or%20could%20that%20be%20an%20issue%3F%20(nameresolution%20fails)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458142%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458142%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F696999%22%20target%3D%22_blank%22%3E%40benjaminfrei%3C%2FA%3E%26nbsp%3BIf%20it%20was%20a%20name%20resolution%20problem%20the%20web%20client%20and%20the%20IOS%20would%20fail%20also.%20Has%20to%20be%20something%20local%20on%20the%20windows%20device%20which%20is%20blocking%20the%20connection%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458152%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458152%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F235785%22%20target%3D%22_blank%22%3E%40Neil%20McLoughlin%3C%2FA%3E%26nbsp%3BStrange%20thing!%20Tested%20on%20two%20other%20clients%20joined%20to%20a%20(separate)%20On-Premise%20AD%20(previous%20tests%20were%20all%20conducted%20on%20Azure-joined%20Clients).%20Same%20security%20features%20in%20place%20(Webfilter%20and%20Bitdefender%20AV)%20and%20it%20works!%20So%20must%20be%20kind%20of%20name%20resolution%20issue%20but%20I%5Em%20a%20little%20bit%20confused%20because%20according%20the%20flow%20diagrams%20name%20resolution%20also%20for%20the%20target%20VM%20(session%20host)%20is%20done%20azure%20internally%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458161%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458161%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F696999%22%20target%3D%22_blank%22%3E%40benjaminfrei%3C%2FA%3E%26nbsp%3BHere%20is%20how%20it%20works%20-%26nbsp%3B%3CA%20href%3D%22http%3A%2F%2Fxenithit.blogspot.com%2F2020%2F05%2Factive-directory-topologies-support-for.html%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fxenithit.blogspot.com%2F2020%2F05%2Factive-directory-topologies-support-for.html%3C%2FA%3E%26nbsp%3B%20Make%20sure%20your%20Azure%20VMs%20have%20connectivity%20to%20your%20Domain%20controllers%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CSPAN%3E%26nbsp%3BThe%20WVD%20agent%20asks%20the%20Domain%20Controller%20to%20do%20a%20reverse%20lookup%20on%20the%20users%20on-prem%20SID.%20If%20this%20matches%20then%20the%20user%20object%20is%20added%20to%20the%20local%20Remote%20Desktop%20Users%20group%20and%20access%20is%20granted%20onto%20the%20Session%20Host.%22%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458820%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458820%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F235785%22%20target%3D%22_blank%22%3E%40Neil%20McLoughlin%3C%2FA%3E%26nbsp%3BIt%20seems%20that%20the%20issue%20occurs%20on%20azure-joined%20machines%20only.%26nbsp%3B%20AD%20or%20WORKGROUP%20machines%20are%20not%20affected.%20I%20setup%20another%20tenant%20using%20AzureAD%20domain%20equal%20ADDS%20Domain.%20Same%20issues%20also%20when%20trying%20to%20connect%20on%20a%20machine%20connected%20to%20tenant%20A%20but%20using%20a%20Remote%20Desktop%20connection%20to%20tenant%20B!%20Can%20someone%20clarify%20this%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1459697%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1459697%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F235785%22%20target%3D%22_blank%22%3E%40Neil%20McLoughlin%3C%2FA%3E%26nbsp%3BAzure%20VMS%20have%20full%20connectivity%20to%20the%20DC%20(ADDS%20based).%20The%20problem%20seems%20to%20be%20more%20like%20name%20resolution%20based.%20Not%20the%20credentials%20are%20the%20problem!%20Anyone%20else%20any%20idea%3F%20Very%20appreciated!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462076%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462076%22%20slang%3D%22en-US%22%3E%3CP%3EFound%20a%20solution%20to%20the%20problem%2C%20great%20work%20done%20by%20Micha%20Wets!%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.cloud-architect.be%2F2020%2F04%2F19%2Fsolution-for-the-0x204-error-when-connecting-to-windows-virtual-desktop-wvd%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.cloud-architect.be%2F2020%2F04%2F19%2Fsolution-for-the-0x204-error-when-connecting-to-windows-virtual-desktop-wvd%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1641074%22%20slang%3D%22en-US%22%3ERe%3A%20not%20able%20to%20connect%20to%20WVD%20from%20win64%20client%20(latest)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1641074%22%20slang%3D%22en-US%22%3E%3CP%3Eis%20this%20issue%20resolved%3F%20I%20have%20the%20same%20issue%20now%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F235785%22%20target%3D%22_blank%22%3E%40Neil%20McLoughlin%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi everyone

Just finished my first WVD test-deployment based on ADDS. Everything is running fine except connections from windows x64 based devices. HTML5 web client and IOS Remote Desktop App work without issues. Installed Client version 1.2.1026.0 using URL https://rdweb.wvd.microsoft.com/api/arm/feeddiscovery.

Login is accepted and Workspace is visible. But when I try to connect to a published SessionDesktop the connection fails with a generic "Remote Desktop can't connect to the remote computer for one of these reasons..." (Error code 0x204).

I have and showcase tomorrow with the customer - any hints? Thanks!

10 Replies
Highlighted

@benjaminfrei Hi, it maybe a firewall/antivirus issue??? Try temporarily disabling your windows firewall or any antivirus/malware software you have on the windows device.

 

Also do you have another windows device you can test from??

Highlighted

@Neil McLoughlin Good morning! I tested the connection on three different devices and also disabled security modules like webfilter. all of them have managed bitdefender installer. I will do another test with disabled/uninstalled bitdefender and let you know. So my interpretation is correct that no pinholes on the azure side is required because all the traffic flows between the client - the azure frontdoor and then internally to the vm's via 443/tcp?

Highlighted

@Neil McLoughlin question: my ADDS setup (cloud only tennant, no on-prem AD) was build with the same top-leveld-domain as the public tenant has (split brain dns). In my understanding this should not be a problem, also when using azure connected enddevices. do you agree or could that be an issue? (nameresolution fails)

Highlighted

@benjaminfrei If it was a name resolution problem the web client and the IOS would fail also. Has to be something local on the windows device which is blocking the connection

Highlighted

@Neil McLoughlin Strange thing! Tested on two other clients joined to a (separate) On-Premise AD (previous tests were all conducted on Azure-joined Clients). Same security features in place (Webfilter and Bitdefender AV) and it works! So must be kind of name resolution issue but I^m a little bit confused because according the flow diagrams name resolution also for the target VM (session host) is done azure internally?

Highlighted

@benjaminfrei Here is how it works - http://xenithit.blogspot.com/2020/05/active-directory-topologies-support-for.html  Make sure your Azure VMs have connectivity to your Domain controllers

 

" The WVD agent asks the Domain Controller to do a reverse lookup on the users on-prem SID. If this matches then the user object is added to the local Remote Desktop Users group and access is granted onto the Session Host."

Highlighted

@Neil McLoughlin It seems that the issue occurs on azure-joined machines only.  AD or WORKGROUP machines are not affected. I setup another tenant using AzureAD domain equal ADDS Domain. Same issues also when trying to connect on a machine connected to tenant A but using a Remote Desktop connection to tenant B! Can someone clarify this?

Highlighted

@Neil McLoughlin Azure VMS have full connectivity to the DC (ADDS based). The problem seems to be more like name resolution based. Not the credentials are the problem! Anyone else any idea? Very appreciated!

Highlighted
Best Response confirmed by benjaminfrei (Occasional Contributor)
Highlighted

is this issue resolved? I have the same issue now@Neil McLoughlin