403 Error in Windows/Azure Virtual Desktop

Christopher Kowalski 5 Reputation points
2023-04-04T13:09:54.2233333+00:00

I have a website that employees on Windows 10 in WVD need to access, and it comes up 403 forbidden, yet users on a PC have no issue accessing it, so I need to know how to allow this in Windows Virtual Desktop, as it is obviously something in the settings in Azure that are blocking this site. Any help is appreciated.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
8,512 questions
{count} vote

3 answers

Sort by: Most helpful
  1. Matheus Lima Barbosa 10 Reputation points
    2023-06-09T18:34:32.2166667+00:00

    The issue occurs on any machine with internet output to Azure. Test with machines in different regions and the problem is the same

    1 person found this answer helpful.
    0 comments No comments

  2. kobulloc-MSFT 26,431 Reputation points Microsoft Employee
    2023-04-04T16:03:51.4166667+00:00

    Hello, @Christopher Kowalski ! Why can I access a website locally but not from Azure Virtual Desktop?

    Both AVD and Azure allow outbound internet access to everything by default so this would be a setting on the website itself that would need to be investigated (perhaps a security setting that is blocking access to the session host VMs).

    Edit: It may be worth checking whether the DNS resolution of the site is different between the 2 locations. This would more likely impact your own site hosting where it may be resolved differently based on the DNS server doing the lookup, which could lead to the 403 error if you were hitting a different web service coming from the AVD host.

    I hope this helps!

    Edit 2: In cases that we've investigated there haven't been any causes on the Azure side for a 403 error. Some websites may block traffic that comes from the default Azure standard IP ranges.

    • One workaround is to use a fixed outbound IP for internet traffic like Azure Firewall or a proxy server.

    Additionally two other workarounds have been tested and reported (thank you, Joaquín!):

    • Replace the user agent that the browser sends in the GET request with a custom one.
    • Use VPN, although this doesn't work 100% of the time.

  3. Alistair Carr 0 Reputation points
    2023-07-11T07:46:05.92+00:00

    Hi, I have the same issue. I work for a company who do Azure installs for lots of different customers and I have tested VM's and AVD's in UK region and US.

    Mine is https://www.dahuasecurity.com/uk site but if it was some FCC ruling I don't understand as I can get to HIK and others similar companies.

    If anyone else has had this issue let me know or feel free to test site on their Azure infrastucture.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.