RDV GRAPHICS SERVICE

DJX995 1 Reputation point
2020-08-06T13:57:38.333+00:00

Is the "RDV GRAPHICS SERVICE" user account still needed if i have a domain that has been completely upgraded to Server 2019? I'm running into an issue with Azure AD Connect failing to synchronize this account for some reason and I'm wondering if I still need it if everything is running 2019.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,768 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,136 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,906 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Shashi Shailaj 7,601 Reputation points Microsoft Employee
    2020-08-07T16:28:27.647+00:00

    Hello @DJX995 ,
    The user account "RDV GRAPHICS SERVICE" is a local system account which is created when the RemoteFX feature was enabled on a Remote desktop Virtualization Host and it is made a member of the Users group on a normal server. You will get into this situation where AD connect is trying to sync this system account only when the Domain controller in your on-premise environment have Remote desktop virtualization host enabled and hence this account has moved to Active directory now. It is a system account and if you are not using any application which leverage RemoteFX hosted on this server 2019 , I don't think you need this. Generally it is recommended to enable the RD Virtualization host feature on a server which is not a domain controller. However it seems the server had this enabled and then it was promoted to a domain controller due to which this scenario could occur.

    I don't think it matters if you are running server 2019 because the important thing to check will be if you have any apps hosted on the Remote Desktop Virtualization leveraging RemoteFX on this server . If you have such apps then I would suggest to check with the maintainer of the applications and move it to a separate domain server rather than have this on a domain controller. Also if you are looking for an exact reason then more troubleshooting would need to be done and the ACLs on this object within the Active directory database will need to be checked to find out if the sync engine service account have read permissions on it or not .

    There is no reason for this account to be used in the Azure Active directory for any purpose as far as I know hence syncing this to the cloud is not needed unless there is any extreme corner case scenario for this. I would suggest you to go with container filtering in the AD connect setup to exclude this account as this would generally be in the Built-in or Users container. It can be at other places as well if it has been manually moved . I do not have this setup in my lab so I cannot test this exactly and confirm the location but you should be able to check .

    16483-image.png

    Hope this clarifies the query and provides a valid solution. If the information in this post is helpful , please do accept the post as answer so that its helpful for other members of the community searching for similar issues. In case you have any further query on this, please feel free to let us know and we will be happy to help .

    Thank you.

    0 comments No comments

  2. DJX995 1 Reputation point
    2020-08-10T14:34:59.443+00:00

    Got it. Makes Sense. If this is what I have on all domain controllers now, am I safe to delete that account?
    16750-capture.png

    I also found out the exact issue of the Azure sync is because that account does not have a UPN, it's blank. Even if it had one, it would be invalid to Azure because it would have spaces.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.