Multiple forests with AD DS and Microsoft Entra ID

Azure Virtual Desktop
Microsoft Entra ID
Microsoft Entra
Azure ExpressRoute
Azure Storage

Many organizations want to take advantage of Azure Virtual Desktop to create environments that have multiple on-premises Active Directory forests.

This article expands on the architecture that's described in the Azure Virtual Desktop at enterprise scale article. It's intended to help you understand how to integrate multiple domains and Azure Virtual Desktop by using Microsoft Entra Connect to sync users from on-premises Active Directory Domain Services (AD DS) to Microsoft Entra ID.


Diagram that shows Azure Virtual Desktop integration with Active Directory Domain Services.

Download a Visio file of this architecture.


In this architecture, the identity flow works as follows:

  1. Microsoft Entra Connect syncs users from both and to a Microsoft Entra tenant (
  2. Host pools, workspaces, and app groups are created in separate subscriptions and spoke virtual networks.
  3. Users are assigned to the app groups.
  4. Azure Virtual Desktop session hosts in the host pools join the domains and by using the domain controllers (DCs) in Azure.
  5. Users sign in by using either the Azure Virtual Desktop application or the web client with a User Principal Name (UPN) in the following format:,, or, depending on their configured UPN suffix.
  6. Users are presented with their respective virtual desktops or applications. For example, users in CompanyA are presented with a virtual desktop or application in Workspace A, host pool 1 or 2.
  7. FSLogix user profiles are created in Azure Files shares on the corresponding storage accounts.
  8. Group Policy Objects (GPOs) that are synced from on-premises are applied to users and Azure Virtual Desktop session hosts.


This architecture uses the same components as those listed in Azure Virtual Desktop at enterprise scale architecture.

Additionally, this architecture uses the following components:

  • Microsoft Entra Connect in staging mode: The Staging server for Microsoft Entra Connect topologies provides additional redundancy for the Microsoft Entra Connect instance.

  • Azure subscriptions, Azure Virtual Desktop workspaces, and host pools: You can use multiple subscriptions, Azure Virtual Desktop workspaces, and host pools for administration boundaries and business requirements.

Scenario details

This architecture diagram represents a typical scenario that contains the following elements:

  • The Microsoft Entra tenant is available for a new company named
  • Microsoft Entra Connect syncs users from on-premises AD DS to Microsoft Entra ID.
  • Company A and Company B have separate Azure subscriptions. They also have a shared services subscription, referred to as the Subscription 1 in the diagram.
  • An Azure hub-spoke architecture is implemented with a shared services hub virtual network.
  • Complex hybrid on-premises Active Directory environments are present with two or more Active Directory forests. Domains live in separate forests, each with a different UPN suffix. For example, CompanyA.local with the UPN suffix, CompanyB.local with the UPN suffix, and an additional UPN suffix,
  • Domain controllers for both forests are located on-premises and in Azure.
  • Verified domains are present in Azure for,, and
  • GPO and legacy authentication, such as Kerberos, NTLM (Windows New Technology LAN Manager), and LDAP (Lightweight Directory Access Protocol), is used.
  • For Azure environments that still have dependency on-premises infrastructure, private connectivity (Site-to-site VPN or Azure ExpressRoute) is set up between on-premises and Azure.
  • The Azure Virtual Desktop environment consists of an Azure Virtual Desktop workspace for each business unit and two host pools per workspace.
  • The Azure Virtual Desktop session hosts are joined to domain controllers in Azure. That is, CompanyA session hosts join the CompanyA.local domain, and CompanyB session hosts join the CompanyB.local domain.
  • Azure storage accounts can use Azure Files for FSLogix profiles. One account is created per company domain (that is, CompanyA.local and CompanyB.local), and the account is joined to the corresponding domain.


Active Directory Domain Services is a self-managed, on-premises component in many hybrid environments, and Microsoft Entra Domain Services provides managed domain services with a subset of fully compatible, traditional AD DS features such as domain join, group policy, LDAP, and Kerberos/NTLM authentication. For a detailed comparison of these components, see Compare self-managed AD DS, Microsoft Entra ID, and managed Microsoft Entra Domain Services.

The solution idea Multiple Azure Virtual Desktop forests using Microsoft Entra Domain Services discusses architecture that uses cloud-managed Microsoft Entra Domain Services.

Potential use cases

Here are a few relevant use cases for this architecture:


When you're designing your workload based on this architecture, keep the following ideas in mind.

Group Policy Objects

  • To extend GPO infrastructure for Azure Virtual Desktop, the on-premises domain controllers should sync to the Azure infrastructure as a service (IaaS) domain controllers.

  • Extending GPO infrastructure to Azure IaaS domain controllers requires private connectivity.

Network and connectivity

  • The domain controllers are shared components, so they need to be deployed in a shared services hub virtual network in this hub-spoke architecture.

  • Azure Virtual Desktop session hosts join the domain controller in Azure over their respective hub-spoke virtual network peering.

Azure Storage

The following design considerations apply to user profile containers, cloud cache containers, and MSIX packages:

  • You can use both Azure Files and Azure NetApp Files in this scenario. You choose the right solution based on factors such as expected performance, cost, and so on.

  • Both Azure storage accounts and Azure NetApp Files are limited to joining to one single AD DS at a time. In these cases, multiple Azure storage accounts or Azure NetApp Files instances are required.

Microsoft Entra ID

In scenarios with users in multiple on-premises Active Directory forests, only one Microsoft Entra Connect Sync server is connected to the Microsoft Entra tenant. An exception to this is a Microsoft Entra Connect server that's used in staging mode.

Diagram that shows design variations for multiple Active Directory forests for Azure Virtual Desktop.

The following identity topologies are supported:

  • Multiple on-premises Active Directory forests.
  • One or more resource forests trust all account forests.
  • A full mesh topology allows users and resources to be in any forest. Commonly, there are two-way trusts between the forests.

For more details, see the Staging server section of Microsoft Entra Connect topologies.


This article is maintained by Microsoft. It was originally written by the following contributors.

Principal author:

  • Tom Maher | Senior Security and Identity Engineer

Next steps

For more information, see the following articles: