User profile failed to attach - WVD

%3CLINGO-SUB%20id%3D%22lingo-sub-1236741%22%20slang%3D%22en-US%22%3EUser%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1236741%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20successfull%20deployed%20WVD%20and%20was%20working%20perfect.%3C%2FP%3E%3CP%3ENow%20when%20few%20users%20are%20getting%20the%20attached%20error%20when%20they%20try%20to%20login.%3C%2FP%3E%3CP%3E%22The%20user%20profile%20failed%20to%20attach.%20Please%20contact%20support%22%3C%2FP%3E%3CP%3EWorst%20part%20is%20even%20my%20id%20is%20throwing%20the%20same%20error%2C%20which%20is%20a%20admin%20account.%3C%2FP%3E%3CP%3EWe%20are%20using%20Azure%20File%20Shar%20to%20store%20the%20user%20profile%20through%20FSLogix.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETried%20to%20remote%20all%20session%20hosts%20to%20check%20if%20my%20session%20is%20stuck%20%2C%20but%20no%20luck%2C%20got%20the%20same%20error%20on%20all.%3C%2FP%3E%3CP%3EFound%20no%20solution%20and%20hence%20posting%20here%20for%20help!!.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Login%20Error.png%22%20style%3D%22width%3A%20777px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F177938i9DB1AC64A39FC057%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Login%20Error.png%22%20alt%3D%22Login%20Error.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1237243%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1237243%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203010%22%20target%3D%22_blank%22%3E%40Nandish%20Mahadevappa%3C%2FA%3Ea%20lot%20of%20things%20can%20cause%20this%20problem.%20You%20didn't%20change%20anything%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Did%20you%20change%20the%20%3CEM%3Efirewall%20%26amp%3B%20networking%3C%2FEM%3E%20on%20the%20storage%20account%3F%3C%2FP%3E%3CP%3E-%20Did%20you%20change%20the%20permissions%20on%20the%20%3CEM%3EAzure%20File%3C%2FEM%3E%20%3CEM%3EShare%3C%2FEM%3E%20(I%20think%20it%20should%20be%20Storage%20File%20Data%20SMB%20Share%20Contributor)%3C%2FP%3E%3CP%3E-%20Are%20you%20able%20to%20logon%20with%20a%20local%20account%3F%3C%2FP%3E%3CP%3E-%20Did%20you%20(or%20someone)%20regenerated%20your%20storage%20account%20keys%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20how%20did%20you%20configure%20the%20FSLogix%20settings%3F%20Directly%20in%20the%20register%20or%20with%20GPO's%3F%20Multiple%20hosts%20or%20a%20single%20host%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1240198%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1240198%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F530025%22%20target%3D%22_blank%22%3E%40Jente_V%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20comments%20below.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Did%20you%20change%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CEM%3Efirewall%20%26amp%3B%20networking%3C%2FEM%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eon%20the%20storage%20account%3F%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%230000FF%22%3ENope%2C%20no%20changes%20done%20to%20firewall%20%26amp%3B%20networking%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Did%20you%20change%20the%20permissions%20on%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CEM%3EAzure%20File%3C%2FEM%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CEM%3EShare%3C%2FEM%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E(I%20think%20it%20should%20be%20Storage%20File%20Data%20SMB%20Share%20Contributor)%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%230000FF%22%3EI%20have%20contributor%20access%20to%20whole%20resourse%20group%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Are%20you%20able%20to%20logon%20with%20a%20local%20account%3F%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%230000FF%22%3EInterestingly%20even%20the%20local%20admin%20has%20the%20same%20issue%2C%20but%20there%20are%20other%20production%20users%20who%20can%20login.%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Did%20you%20(or%20someone)%20regenerated%20your%20storage%20account%20keys%3F%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%230000FF%22%3ENo%2C%20if%20we%20had%20done%2C%20everyone%20who%20would%20failed%20to%20login%20right%3F%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1240398%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1240398%22%20slang%3D%22en-US%22%3E%3CP%3E%40Jenet_V%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFound%20the%20below%20error%20in%20FSlogix%20events%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Eventvwr.png%22%20style%3D%22width%3A%20922px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F178314i8E1495DD75FDA2E6%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Eventvwr.png%22%20alt%3D%22Eventvwr.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20policy%20is%20set%20to%20delete%20local%20profile%20if%20found%20during%20logon%20as%20per%20the%20below%20link.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Ffslogix%2Fprofile-container-configuration-reference%23deletelocalprofilewhenvhdshouldapply%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Ffslogix%2Fprofile-container-configuration-reference%23deletelocalprofilewhenvhdshouldapply%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20i%20logged%20into%20WVD%20using%20another%20account%20i%20could%20find%20a%20user%20profile%20in%20my%20name%20under%20Users%20folder%2C%20tried%20deleting%20it%2C%20but%20NTUSer.dat%20file%20doesn't%20get%20deleted%2C%20I%20cannot%20restart%20the%20VM%20as%20other%20users%20are%20connected%20to%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1240806%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1240806%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203010%22%20target%3D%22_blank%22%3E%40Nandish%20Mahadevappa%3C%2FA%3Eare%20you%20running%20the%20latest%20version%20of%20FSLogix%3F%20Do%20you%20see%20a%20.lock%20file%20on%20your%20VHD(x)%20storage%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1733886%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1733886%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F203010%22%20target%3D%22_blank%22%3E%40Nandish%20Mahadevappa%3C%2FA%3E%26nbsp%3Bhave%20you%20solved%20this%3F%20I%20have%20the%20same%20issue.%20I%20tried%20deleting%20the%20VHD%20file%20and%20the%20directory%20it%20was%20in%20on%20my%20azure%20VHD%20volume%20but%20that%20didn't%20help%20either.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1824800%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1824800%22%20slang%3D%22en-US%22%3E%3CP%3EI%20had%20the%20same%20issue%20and%20got%20it%20figured%20out%20finally.%20It%20felt%20like%20a%20permissions%20issue%20and%20it%20is.%3C%2FP%3E%3CP%3EIn%20this%20article%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fcreate-file-share%23assign-azure-rbac-permissions-to-windows-virtual-desktop-users%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fcreate-file-share%23assign-azure-rbac-permissions-to-windows-virtual-desktop-users%3C%2FA%3E%3C%2FP%3E%3CP%3EIt%20shows%20how%20to%20set%20the%20NTFS%20perms%20up.%20It%20doesn't%20really%20say%20that%20you%20need%20to%20do%20the%20ICACLS%20part%20for%20every%20user...beforehand.%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20you%20create%20the%20mapped%20drives%2C%20you%20need%20to%20run%20a%20set%20of%20icacls%20commands%20for%20the%20main%20profile%20and%20the%20Office%20profiles...The%20following%20commands%20for%20both%20drive%20letters.%3C%2FP%3E%3CP%3E%3CSPAN%3Eicacls%20%3CMOUNTED-DRIVE-LETTER%3E%3A%20%2Fgrant%20%3CUSER-EMAIL%3E%3A(M)%20%3C%2FUSER-EMAIL%3E%3C%2FMOUNTED-DRIVE-LETTER%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3Eicacls%20%3CMOUNTED-DRIVE-LETTER%3E%3A%20%2Fgrant%20%22Creator%20Owner%22%3A(OI)(CI)(IO)(M)%20%3C%2FMOUNTED-DRIVE-LETTER%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3Eicacls%20%3CMOUNTED-DRIVE-LETTER%3E%3A%20%2Fremove%20%22Authenticated%20Users%22%20%3C%2FMOUNTED-DRIVE-LETTER%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3Eicacls%20%3CMOUNTED-DRIVE-LETTER%3E%3A%20%2Fremove%20%22Builtin%5CUsers%22%3C%2FMOUNTED-DRIVE-LETTER%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20need%20to%20run%20the%20first%20line%20for%20EVERY%20user%20that%20is%20going%20to%20log%20in!%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3Eicacls%20%3CMOUNTED-DRIVE-LETTER%3E%3A%20%2Fgrant%20%3CUSER-EMAIL%3E%3A(M)%3C%2FUSER-EMAIL%3E%3C%2FMOUNTED-DRIVE-LETTER%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EHope%20that%20helps!%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1825102%22%20slang%3D%22en-US%22%3ERe%3A%20User%20profile%20failed%20to%20attach%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1825102%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F88556%22%20target%3D%22_blank%22%3E%40Mark%20Plantenberg%3C%2FA%3E%26nbsp%3BYou%20can%20use%20a%20group%20instead%20of%20each%20individual%20email%20address.%26nbsp%3B%20Example%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eicacls%20%3CDRIVE%3E%3A%20%2Fgrant%20%22%3CGROUP%20name%3D%22%22%3E%22%3A(M)%3C%2FGROUP%3E%3C%2FDRIVE%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Have successfull deployed WVD and was working perfect.

Now when few users are getting the attached error when they try to login.

"The user profile failed to attach. Please contact support"

Worst part is even my id is throwing the same error, which is a admin account.

We are using Azure File Shar to store the user profile through FSLogix.

 

Tried to remote all session hosts to check if my session is stuck , but no luck, got the same error on all.

Found no solution and hence posting here for help!!.Login Error.png

 

 

 

7 Replies

@Nandish Mahadevappaa lot of things can cause this problem. You didn't change anything?

 

- Did you change the firewall & networking on the storage account?

- Did you change the permissions on the Azure File Share (I think it should be Storage File Data SMB Share Contributor)

- Are you able to logon with a local account?

- Did you (or someone) regenerated your storage account keys?

 

Also, how did you configure the FSLogix settings? Directly in the register or with GPO's? Multiple hosts or a single host?

 

Thank you,

 

@Jente_V 

My comments below.

 

- Did you change the firewall & networking on the storage account?

Nope, no changes done to firewall & networking

 

- Did you change the permissions on the Azure File Share (I think it should be Storage File Data SMB Share Contributor)

I have contributor access to whole resourse group

 

- Are you able to logon with a local account?

Interestingly even the local admin has the same issue, but there are other production users who can login.

 

- Did you (or someone) regenerated your storage account keys?

No, if we had done, everyone who would failed to login right?

@Jenet_V

 

Found the below error in FSlogix events:

 

 

Eventvwr.png

 

A policy is set to delete local profile if found during logon as per the below link.

https://docs.microsoft.com/en-us/fslogix/profile-container-configuration-reference#deletelocalprofil...

 

When i logged into WVD using another account i could find a user profile in my name under Users folder, tried deleting it, but NTUSer.dat file doesn't get deleted, I cannot restart the VM as other users are connected to it.

@Nandish Mahadevappaare you running the latest version of FSLogix? Do you see a .lock file on your VHD(x) storage?

 

 

@Nandish Mahadevappa have you solved this? I have the same issue. I tried deleting the VHD file and the directory it was in on my azure VHD volume but that didn't help either.

I had the same issue and got it figured out finally. It felt like a permissions issue and it is.

In this article, https://docs.microsoft.com/en-us/azure/virtual-desktop/create-file-share#assign-azure-rbac-permissio...

It shows how to set the NTFS perms up. It doesn't really say that you need to do the ICACLS part for every user...beforehand. 

Once you create the mapped drives, you need to run a set of icacls commands for the main profile and the Office profiles...The following commands for both drive letters.

icacls <mounted-drive-letter>: /grant <user-email>:(M)

icacls <mounted-drive-letter>: /grant "Creator Owner":(OI)(CI)(IO)(M)

icacls <mounted-drive-letter>: /remove "Authenticated Users"

icacls <mounted-drive-letter>: /remove "Builtin\Users"

 

You need to run the first line for EVERY user that is going to log in! 

icacls <mounted-drive-letter>: /grant <user-email>:(M)

 

Hope that helps!

 

@Mark Plantenberg You can use a group instead of each individual email address.  Example:

 

icacls <drive>: /grant "<group name>":(M)