OneDrive AutoSign-In Not Working WVD Desktop

%3CLINGO-SUB%20id%3D%22lingo-sub-1941333%22%20slang%3D%22en-US%22%3EOneDrive%20AutoSign-In%20Not%20Working%20WVD%20Desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1941333%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EHaving%20an%20issue%20with%20the%20OD%20client%20not%20auto-signing%20in%20on%20WVD.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3ELayout%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EOnPrem-ADDS%20sync'd%20to%20AAD%20via%20AADC%2C%20password%20hash%20sync%20with%20SSO%20enabled%2C%20devices%20are%20sync'd%3CBR%20%2F%3E2x%20Additional%20DCs%20VMs%20in%20Azure%3CBR%20%2F%3ES2S%20VPN%20between%20the%20two.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EWVD%20in%20Pooled%20Desktop%20Mode%3CBR%20%2F%3ESingle%20Session%20Host%20(Its%20only%20a%20test!)%3CBR%20%2F%3EFSLogix%20using%20AzureFiles%20for%20profile%20storage.%3CBR%20%2F%3EWVD%20Session%20host%20is%20HybridAzureJoined%3CBR%20%2F%3EOneDrive%20client%20installed%20with%20%2Fallusers%20switch%3CBR%20%2F%3EGPO%20linked%20to%20the%20OU%20with%20the%20WVD%20SH%20VM%20in%20it%20which%20switches%20on%20FilesOnDemand%2C%20and%20AutoSign%20in%20user%20with%20primary%20domain%20creds%20enabled.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EAll%20so%20far%20so%20good%2C%20apart%20from%20the%20OD%20aspect.%3CBR%20%2F%3EIt%20starts%20but%20doesn't%20login%2C%20I%20can%20see%20the%20policy%20is%20applied%20-%20the%20keys%20are%20in%20the%20registry%3CBR%20%2F%3EIf%20I%20attempt%20to%20manually%20sign%20in%2C%20it%20does%20so%20without%20prompting%20for%20a%20password%2C%20so%20SSO%20looks%20OK.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%3CBR%20%2F%3EAnything%20I've%20missed%20here%3F%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%3CBR%20%2F%3EEdit%3A%3CBR%20%2F%3EI%20forgot%20to%20say%2C%20same%20GPO%20applied%20to%20my%20on-prem%20RDS%20which%20is%20configured%20in%20the%20same%20way%2C%20connected%20to%20the%20same%20domain%20and%20is%20HybridADJoined%20(via%20the%20same%20HybridJoinPolicy)%20works%20just%20fine.%3CBR%20%2F%3EUser%20logs%20in%20and%20onedrive%20hooks%20itself%20up.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Having an issue with the OD client not auto-signing in on WVD.

Layout

OnPrem-ADDS sync'd to AAD via AADC, password hash sync with SSO enabled, devices are sync'd
2x Additional DCs VMs in Azure
S2S VPN between the two.

WVD in Pooled Desktop Mode
Single Session Host (Its only a test!)
FSLogix using AzureFiles for profile storage.
WVD Session host is HybridAzureJoined
OneDrive client installed with /allusers switch
GPO linked to the OU with the WVD SH VM in it which switches on FilesOnDemand, and AutoSign in user with primary domain creds enabled.

 

All so far so good, apart from the OD aspect.
It starts but doesn't login, I can see the policy is applied - the keys are in the registry
If I attempt to manually sign in, it does so without prompting for a password, so SSO looks OK.


Anything I've missed here?


Edit:
I forgot to say, same GPO applied to my on-prem RDS which is configured in the same way, connected to the same domain and is HybridADJoined (via the same HybridJoinPolicy) works just fine.
User logs in and onedrive hooks itself up.

3 Replies

@ChrisH0701 I'm having a similar issue. Have you ever resolved this? I can't get my virtual desktop to auto sign in to onedrive. Other apps work fine. I don't have an exclusion as a trusted location to bypass MFA yet but could add one if required.

My Setup

Windows Virtual Desktop Pooled Multi Session windows 10

Domain Controllers on Prem and in Cloud

AD Connect with password hash, single sign on, and Hybrid Azure AD Join

Group Policies for

  • OneDrive to silently move users to one drive sync app, move know folders
  • Seemless sign on
  • Azure AD Join (I don't think this works with multi session hosts though)

OneDrive auto starts and was installed with allusers switch but does not sign in.

MFA is enabled on my accounts too and not sure if that will require MFA or not.

 

@Adam Cochran 
I did, and to be honest I can't recall what I did or what it was, but it wasn't anything complex in the end.

Check that the WVD units are Hybrid joined (dsregcmd)
Check in AzureAD's logging to see if you can see the attempts getting bounced
Check that AzureADConnect SSO is actually working
No Folder Redirection policies in place?

I do still have most of the test setup around I think, so I can have a look at the GPOs applied to my WVD hosts if you need me to.

@ChrisH0701 

 

So the machines were not hybrid joining. Once I got that fixed it seems to work.