AVD with FSLogix with no On-prem AD.

Michael Novak 81 Reputation points
2024-01-29T13:21:48.9033333+00:00

Hi all, I have a client which does not have ANY on-prem AD (only local users on workgroup devices). They wish to implement Azure Virtual Desktop (AVD) with FSLogix functionality. According to this article, Clients must be Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra Kerberos isn’t supported on clients joined to Microsoft Entra Domain Services or joined to AD only.

This feature doesn't currently support user accounts that you create and manage solely in Microsoft Entra ID. User accounts must be hybrid user identities, which means you'll also need AD DS and either Microsoft Entra Connect or Microsoft Entra Connect cloud sync.

I have understood that it is not possible to use Azure AD DS (Entra ID DS) without hybrid joined for FSLogix due to missing Entra Kerberos support.

I would like to understand if I can implement a cloud-only AVD with FSLogix with any combination of cloud services (i.e. Active Directory AD in Azure VM, Azure AD DS, Azure AD joined...) to achieve FSLogix functionality, or is there a hard requirement to have an on-prem hybrid joined devices and hybrid users to employ this functionality ? I am aware of the "hacks" with Fslogix cloud cache or storing storage account credentials in Windows clients, but I want solely an official supported route.

Would it be possible to build a new AD domain solely in Azure VM and then AD Connect sync the users to Azure AD? is this even supported? Many thanks.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
8,007 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,655 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,161 questions
{count} votes

Accepted answer
  1. Andreas Baumgarten 111.4K Reputation points MVP
    2024-01-29T13:30:37.7733333+00:00

    Hi @Michael Novak , Azure AVD and FSLogix are supporting an Azure Entra ID cloud-only environment:

    FSLogix profile containers for Azure AD cloud only identities

    Set up FSLogix Profile Container with Azure Files and Active Directory Domain Services or Microsoft Entra Domain Services


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

    Regards

    Andreas Baumgarten

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. vipullag-MSFT 26,391 Reputation points
    2024-02-02T03:31:16.5833333+00:00

    Hello Michael Novak

    Welcome to Microsoft Q&A Platform, thanks for posting your query here.

    I checked with internal team on this, feature to bring cloud identity support to FSLogix profile containers is planned and there is not ETA on this that can be shared now.

    As you mentioned the alternative is with a hybrid identity as documented, or the workarounds you referred. 

    Hope that clarifies.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.