AVD sign-in fails with "A domain controller cannot be found" error on Entra ID joined VM

Sorin Verdes 0 Баллы репутации
2025-06-18T07:35:37.4733333+00:00

Hello Support Team, I am unable to get FSLogix working in a pure Microsoft Entra ID-joined AVD environment. My goal is to use FSLogix profile containers on an Azure Files share. SYMPTOM: When a user tries to connect to an AVD session, the login gets stuck. A manual test from inside the AVD session using the command "net use Z: \stfslogixmaurt.file.core.windows.net\profiles" fails. It prompts for a password and then gives the error: "A domain controller cannot be found to verify that user name." (see attached screenshot). This definitively proves a Kerberos authentication failure. ENVIRONMENT: - Identity: Pure Microsoft Entra ID. No on-premises AD DS. No hybrid setup. - Session Host VM: Windows 11 multi-session, Entra ID-joined. - Storage Account: Premium Azure Files (stfslogixmaurt) with Microsoft Entra Kerberos enabled. EXTENSIVE TROUBLESHOOTING PERFORMED: We have methodically performed every documented troubleshooting step without success: 1. Created a new AVD environment (Host Pool, Workspace, App Group) from scratch. 2. Created a new session host VM from scratch to ensure a clean state. 3. Set the custom RDP property "targetisaadjoined:i:1;" on the Host Pool. 4. Assigned the "Storage File Data SMB Share Contributor" IAM role directly to the test user (******@maurt.md) on the file share. 5. Granted Admin Consent in Entra ID for the Storage Account's service principal. 6. "Rebooted" the Kerberos configuration by disabling and re-enabling it on the storage account. 7. Verified network connectivity with Test-NetConnection on port 445 (it was successful). Even after all these steps on a completely clean environment, the "A domain controller cannot be found" error persists. This points to a platform-level issue. Please advise.

Центр сообщества обсудил вопрос о начале работы с сайтом Q&A
Комментариев: 0 Без комментариев
Голосов: {count}

Ваш ответ

Автор вопроса может помечать ответы как принятые. Это позволяет пользователям узнать, что ответ помог решить проблему автора.