Solution - if you can't connect to WVD desktop and got a message about Gateway error

%3CLINGO-SUB%20id%3D%22lingo-sub-1249407%22%20slang%3D%22en-US%22%3ESolution%20-%20if%20you%20can't%20connect%20to%20WVD%20desktop%20and%20got%20a%20message%20about%20Gateway%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1249407%22%20slang%3D%22en-US%22%3E%3CP%3EI%20got%20a%20message%20%22We%20couldn't%20connect%20to%20the%20gateway%20because%20of%20an%20error.%20If%20this%20keeps%20happening%2C%20ask%20your%20admin%20or%20tech%20support%20for%20help.%22%3C%2FP%3E%3CP%3EAfter%20reinstalled%20twice%20some%20Hosts%20pools%20and%20WVD%20tenants%20I%20have%20found%20a%20reason.%3C%2FP%3E%3CP%3EI%20tried%20to%20connect%20with%20a%20user%20that%20was%20account%20only%20in%20Azure%20AD.%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20account%20wasn't%20synced%20with%20local%20(on-premise)%20AD%20DS.%3C%2FP%3E%3CP%3EWhen%20I%20login%20with%20user%20synced%20through%20AD%20Connect%20with%20both%20Azure%20AD%20and%20on-premise%20AD%20DS%20I%20could%20login%20in%20remote%20desktop.%3C%2FP%3E%3CP%3ESo%20should%20be%20attentive%20and%20see%20the%20requirements%20for%20WVD%20%3A%3C%2FP%3E%3CUL%3E%3CLI%3EAn%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20Active%20Directory%3C%2FA%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3EA%20Windows%20Server%20Active%20Directory%20in%20sync%20with%20Azure%20Active%20Directory.%20You%20can%20configure%20this%20with%20one%20of%20the%20following%3A%3C%2FSTRONG%3E%3CUL%3E%3CLI%3E%3CSTRONG%3EAzure%20AD%20Connect%20(for%20hybrid%20organizations)%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3EAzure%20AD%20Domain%20Services%20(for%20hybrid%20or%20cloud%20organizations)%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3CLI%3EAn%20Azure%20subscription%20that%20contains%20a%20virtual%20network%20that%20either%20contains%20or%20is%20connected%20to%20the%20Windows%20Server%20Active%20Directory%3C%2FLI%3E%3C%2FUL%3E%3CP%3ESee%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Foverview%23requirements%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Foverview%23requirements%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1249810%22%20slang%3D%22en-US%22%3ERe%3A%20Solution%20-%20if%20you%20can't%20connect%20to%20WVD%20desktop%20and%20got%20a%20message%20about%20Gateway%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1249810%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F57619%22%20target%3D%22_blank%22%3E%40Sergey%20Osherov%3C%2FA%3E%26nbsp%3Bit%20should%20also%20work%20with%20Cloud-Only%20(Azure%20AD%20plus%20Azure%20AD%20Domain%20Services)%20users.%20But%20the%20user%20has%20to%20change%20their%20password%20themselves%20in%20Azure%20AD%2FOffice%20365%20first.%20If%20you%20go%20with%20the%20initial%20password%20there%20is%20no%20legacy%20password%20hash%20transferred%20from%20Azure%20AD%20to%20Azure%20AD%20Domain%20Services.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I got a message "We couldn't connect to the gateway because of an error. If this keeps happening, ask your admin or tech support for help."

After reinstalled twice of some Hosts Pools and WVD tenants I have found a reason.

I tried to connect with a user that was account only in Azure AD. 

This account wasn't synced with local (on-premise) AD DS.

When I log in with user synced through AD Connect with both Azure AD and on-premise AD DS I could login in remote desktop.

So should be attentive and see the requirements for WVD :

  • An Azure Active Directory
  • A Windows Server Active Directory in sync with Azure Active Directory. You can configure this with one of the following:
    • Azure AD Connect (for hybrid organizations)
    • Azure AD Domain Services (for hybrid or cloud organizations)
  • An Azure subscription that contains a virtual network that either contains or is connected to the Windows Server Active Directory

See https://docs.microsoft.com/en-us/azure/virtual-desktop/overview#requirements

 

1 Reply
Highlighted

@Sergey Osherov it should also work with Cloud-Only (Azure AD plus Azure AD Domain Services) users. But the user has to change their password themselves in Azure AD/Office 365 first. If you go with the initial password there is no legacy password hash transferred from Azure AD to Azure AD Domain Services.