How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

Let’s check how to add Azure virtual desktop session host to Azure AD. Microsoft released a public preview for the Azure AD join scenario on 14th July 2021. I have already mentioned Azure Virtual Desktop Azure AD Join Support with Intune Management in the previous post.

Update – Microsoft announced the General Availability of Azure AD-joined VMs on 15th Sept 2021.

I have shared my AVD End-User Experience Journey with Intune Management in the previous post. You can manage and secure Azure Virtual Desktop session hosts with MEM management and pure Azure AD join. You don’t need to use the MDM group policy to enroll devices into Intune for AAD join scenario.

Patch My PC

You don’t need connectivity to on-prem AD if you are joining AVD Session hosts to Azure AD. Also, the AD DS requirement is not there if you are using pure Azure AD Join for the AVD session hosts. Microsoft released Windows 365 Cloud PC on 14th July 2021. The Cloud PC solution is also an exciting solution for Windows personal desktops in the cloud.

Prerequisite

The following are the prerequisites to join AVD session hosts to Azure AD. Also, make sure you have all covered the license and other AVD prerequisites.

  • Host pools should only contain VMs of the same domain join type.
    • AD-joined VMs should only be with other AD VMs, and vice-versa.
  • The minimum supported versions of Windows 10 – 2004 or later.
  • Default Users/Non Admin Users on virtual machine should be part of Virtual Machine User Login: Users with this role assigned can log in to an Azure virtual machine with regular user privileges.
  • Admin User on virtual desktop should be part of Virtual Machine Administrator Login: Users with this role assigned can log in to an Azure virtual machine with administrator privileges.
  • Custom RDP setting in the hostpool “targetisaadjoined:i:1” to connect Remote Desktops from non-Widnows end user devices.
Add Azure Virtual Desktop Session Host to Azure AD
Add Azure Virtual Desktop Session Host to Azure AD

Add Azure Virtual Desktop Session Host to Azure AD

Azure AD join gives you the option to automatically enroll the VM with Intune so you can easily manage Windows 10 and Windows 10 multi-session VMs. You can use the option to add Azure Virtual Desktop Session Host to Azure AD.

1E Nomad

NOTE! – The Azure AD join is the modern method of managing devices with Intune auto-enrollment. With the Azure AD join scenario, you don’t need direct connectivity to the on-prem Active Directory.

How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

You have an option to add VMs to Azure AD using add virtual machines to an existing host pool wizard from the drop-down option.

  • Domain Join – Select which directory you would like to join – Azure Active Directory.
  • Enroll VM with Intune -> Yes.
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

Enter the Virtual machine administrator account – Enter the local user name and password for Azure AD joined session hosts.

How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

RBAC Roles Required for Azure AD Join

As I mentioned in the prerequisites section, you will need to add an Azure AD user group to give them login access to Azure AD joined VMs.

  • Navigate to Resource Groups and select the resource group that you used for building Azure AD joined session hosts.
  • Click on Access Control (IAM).
  • Click +Add button to add role assignment.
  • Select the Role “Virtual Machine User Login“.
  • Select the Azure AD group where the login (AVD end-users) users are member of.

NOTE! – Repeat the above tasks to add Admin users access to AVD session host VMs using the built-in role called Virtual Machine Administrator Login.

How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

Special RD Settings for Azure AD Joined

To access Azure AD-joined VMs using the web, Android, macOS, iOS, and Microsoft Store. You will need to have an advanced RD setting for Azure AD joined AVD session hosts.

You can read the details about WVD New RDP Settings Options. Also, you can check whether RDP settings are flowing down to the base clients using the How to Download WVD Session Desktop RDP File post.

  • Navigate to Host Pool -> Select the Hostpool where Azure AD joined VMs are located.
  • Click on RDP properties.
  • Click on button and select Advanced button.
  • Enter targetisaadjoined:i:1 as the last custom properties and click Save.
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

Results

You can check the results of AVD Azure AD joined session hosts from various places.

  • Azure AD Devices node.
  • Intune MEM Portal.
  • Windows 10 or Windows 11 client.
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

Issue with Azure AD Joined VMs?

I can’t log in to Azure AD join session hosts. I was getting the following error whenever I try to connect to VM from RD client.

  • The following error 0x9735 translates to SSL_ERR_INVALID_UPN_NAME which originates from SEC_E_INVALID_UPN_NAME.
  • This means “You can’t sign in with a user ID in this format. Try using your email address instead.”
  • I’m login in to session host with [email protected]onmicrosoft.com ID. I don’t know whether this is supported or not,

NOTE! – Further troubleshooting in a later blog post. You can comment on your experience with Azure AD joined VMs in the comments section.

As promised, here is the blog post FIX: AVD Azure AD Joined VM Login Issue with Error Code 0x9735.

Error code: 0x9735 
Extended error code: 0x0 
Activity ID: {7432516d-23a3-483f-b99e-c3c321520000}
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD
How to Add Azure Virtual Desktop Session Host to Azure AD Join Guide WVD AVD

Resources

Categories AVD