SOLVED
Home

Windows Virtual Desktop - is AD Domain Controller needed and where does it reside?

%3CLINGO-SUB%20id%3D%22lingo-sub-862195%22%20slang%3D%22en-US%22%3EWindows%20Virtual%20Desktop%20-%20is%20AD%20Domain%20Controller%20needed%20and%20where%20does%20it%20reside%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-862195%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EI%E2%80%99m%20having%20trouble%20finding%20a%20guide%20to%20setting%20up%20Windows%20Virtual%20Desktop%20that%20doesn%E2%80%99t%20lose%20me%20at%20the%20domain%20setup%20step.%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EI%20have%20a%20hybrid%20Azure%2FAD%2FO365%20environment.%20When%20setting%20up%20Windows%20virtual%20desktop%20it%20appears%20to%20require%20a%20new%20resource%20group%20and%20then%20proceeds%20to%20prompt%20for%20a%20DC%20account%20t%20and%20and%20password%20and%20OU%20path.%20Where%20exactly%20is%20this%20supposed%20to%20be%3F%20It%20doesn%E2%80%99t%20spin%20up%20a%20DC%20when%20it%20automatically%20creates%20all%20the%20resources%20as%20part%20of%20the%20deployment.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-862983%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Virtual%20Desktop%20-%20is%20AD%20Domain%20Controller%20needed%20and%20where%20does%20it%20reside%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-862983%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F84477%22%20target%3D%22_blank%22%3E%40John%20Quile%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20are%20correct%2C%20the%20deployment%20will%20not%20create%20a%20VM%20with%20Active%20Directory%2C%20this%20is%20a%20prerequisite%20before%20you%20start%20deploying%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Foverview%23requirements%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Foverview%23requirements%3C%2FA%3E)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20for%20the%20AD%2C%20you%20need%20a%26nbsp%3B%3CSPAN%3EWindows%20Server%20Active%20Directory%20in%20sync%20with%20Azure%20Active%20Directory.%20This%20can%20be%20enabled%20through%3A%3C%2FSPAN%3E%3C%2FP%3E%3CUL%3E%3CLI%3EAn%20Azure%20VM%20in%20your%20VNET%2C%20with%20the%20Windows%20AD%20role%20%26amp%3B%20Azure%20AD%20Connect%3C%2FLI%3E%3CLI%3EAzure%20AD%20Domain%20Services%3C%2FLI%3E%3C%2FUL%3E%3CP%3ESo%20it%20is%20important%2C%20during%20the%20deployment%2C%20that%20you%20select%20a%20VNET%20that%20has%20either%20one%20of%20these%20options%20enabled%20in%20it%20so%20the%20SessionHosts%20(WVD%20hosts)%20can%20join%20that%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-863689%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Virtual%20Desktop%20-%20is%20AD%20Domain%20Controller%20needed%20and%20where%20does%20it%20reside%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-863689%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F298270%22%20target%3D%22_blank%22%3E%40michawets%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Micha%2C%3C%2FP%3E%3CP%3EThanks%20for%20reply.%20So%20the%20AD%20info%20it's%20requiring%20in%20this%20screen%20to%20complete%20the%20provisioning%20of%20a%20Windows%20Virtual%20Desktop%2C%20must%20be%20for%20an%20AD%20account%20and%20path%2FOU%20that%20exists%20in%20an%20on-prem%20AD%20server%20in%20our%20on-prem%20environment%3F%20Or%20an%20ADDS%20DC%20in%20an%20Azure%20virtual%20machine%20that%20has%20a%20VPN%20or%20tunnel%20to%20our%20on-prem%20AD%20environment%3F%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20775px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F132666iB3F44486A206BEED%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22ConfusingADSetting.png%22%20title%3D%22ConfusingADSetting.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-869999%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Virtual%20Desktop%20-%20is%20AD%20Domain%20Controller%20needed%20and%20where%20does%20it%20reside%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-869999%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F84477%22%20target%3D%22_blank%22%3E%40John%20Quile%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20think%20you%20are%20mixing%20the%20things%20up%20a%20bit%20here%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Fhtml%2Fimages%2Femoticons%2Fsmile_40x40.gif%22%20alt%3D%22%3Asmile%3A%22%20title%3D%22%3Asmile%3A%22%20%2F%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20have%20an%20onprem%20Windows%20AD%2C%20then%20you%20should%20install%20Azure%20AD%20Connect%20on%20the%20DC.%20In%20Azure%2C%20you%20could%20create%20a%20VPN%20in%20your%20VNET%2C%20updating%20the%20VNET%20DNS%20settings%20to%20point%20to%20the%20onprem%20DC%2C%20and%20then%20join%20the%20WVD%20Sessionhosts%20to%20the%20onprem%20Domain%20using%20a%20AD%20account%20from%20that%20AD%20Forest.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20don't%20want%20to%20use%20a%20VPN%2C%20you%20could%20use%20the%20following%20setup%3A%3C%2FP%3E%3CP%3EOn%20the%20onprem%20Windows%20AD%2C%20install%20Azure%20AD%20Connect%20on%20the%20DC%20to%20sync%20to%20Azure%20AD.%3C%2FP%3E%3CP%3EIn%20Azure%2C%20add%20Azure%20AD%20DS%2C%20which%20will%20update%20the%20VNET%20for%20you%2C%20and%20then%20you%20can%20use%20that%20AD%20account%20from%20the%20local%20domain%20to%20join%20the%20WVD%20sessionhosts.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20makes%20things%20more%20clear%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Fhtml%2Fimages%2Femoticons%2Fsmile_40x40.gif%22%20alt%3D%22%3Asmile%3A%22%20title%3D%22%3Asmile%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
John Quile
Occasional Contributor

I’m having trouble finding a guide to setting up Windows Virtual Desktop that doesn’t lose me at the domain setup step.
I have a hybrid Azure/AD/O365 environment. When setting up Windows virtual desktop it appears to require a new resource group and then proceeds to prompt for a DC account t and and password and OU path. Where exactly is this supposed to be? It doesn’t spin up a DC when it automatically creates all the resources as part of the deployment.

3 Replies

Hi @John Quile ,

 

You are correct, the deployment will not create a VM with Active Directory, this is a prerequisite before you start deploying (https://docs.microsoft.com/en-us/azure/virtual-desktop/overview#requirements)

 

As for the AD, you need a Windows Server Active Directory in sync with Azure Active Directory. This can be enabled through:

  • An Azure VM in your VNET, with the Windows AD role & Azure AD Connect
  • Azure AD Domain Services

So it is important, during the deployment, that you select a VNET that has either one of these options enabled in it so the SessionHosts (WVD hosts) can join that domain.

 

Hope this helps

 

@michawets 

Hi Micha,

Thanks for reply. So the AD info it's requiring in this screen to complete the provisioning of a Windows Virtual Desktop, must be for an AD account and path/OU that exists in an on-prem AD server in our on-prem environment? Or an ADDS DC in an Azure virtual machine that has a VPN or tunnel to our on-prem AD environment?   

ConfusingADSetting.png

Solution

Hi @John Quile ,

 

I think you are mixing the things up a bit here :smile:.

 

If you have an onprem Windows AD, then you should install Azure AD Connect on the DC. In Azure, you could create a VPN in your VNET, updating the VNET DNS settings to point to the onprem DC, and then join the WVD Sessionhosts to the onprem Domain using a AD account from that AD Forest.

 

If you don't want to use a VPN, you could use the following setup:

On the onprem Windows AD, install Azure AD Connect on the DC to sync to Azure AD.

In Azure, add Azure AD DS, which will update the VNET for you, and then you can use that AD account from the local domain to join the WVD sessionhosts.

 

Hope this makes things more clear :smile: