Тёмный

AzureFiles AD Auth & FSLogix | Windows Virtual Desktop - #02 

Azure Academy
Подписаться 58 тыс.
Просмотров 45 тыс.
50% 1

#TheAzureAcademy #WindowsVirtualDesktop #FSLogix
Learn how to use the new Azure Files with AD Authentication with FSLogix & Windows Virtual Desktop today at The Azure Academy
Azure Files supports identity-based authentication over Server Message Block (SMB) through two types of Domain Services: Azure Active Directory Domain Services (Azure AD DS) (GA) and Active Directory (AD) (preview).
When you enable AD for Azure file shares over SMB, your AD domain joined machines can mount Azure file shares using your existing AD credentials.
AzureFiles AD Auth Doc - 2:25
Create AzureFiles - 3:35
Enable AD Auth on Files - 5:34
Assign RBAC/NTFS Perm - 8:47
DFS with AzureFiles - 12:47
Setup FSLogix - 13:55
Test Azure Files & WVD - 16:07
► Download FSLogix - aka.ms/fslogix_download
► FSLogix Docs - aka.ms/FSLogix
► WVD Docs - docs.microsoft.com/en-us/azur...
► AzureFiles Doc - docs.microsoft.com/en-us/azur...
📲 Follow Azure Academy
►Twitter: / msazureacademy
►LinkedIn: / dean-cefola-2902934b
►Facebook: / azure-academy-87979521...
💰 Support Azure Academy
►Patreon: / azureacademy
📡 Contact Azure Academy
►Email: Dean.Cefola@Microsoft.com
►MAIN Channel: / azureacademy
🤣Playlists
►Azure Governance: aka.ms/AzureAcademy-Governance
►Azure Fundamentals: aka.ms/AzureAcademy-Fundamentals
►Azure Blueprints: aka.ms/AzureAcademy-Blueprints
►Azure AD Series: aka.ms/AzureAcademy-AzureAD
►Azure ARM Templates: aka.ms/AzureAcademy-ARMTemplates
►Azure Automation: aka.ms/AzureAcademy-Automation
►Azure Networking: aka.ms/AzureAcademy-Networking
►Azure Migrations: aka.ms/AzureAcademy-Migrations
►Azure Backup: aka.ms/AzureAcademy-Backups
►Azure New Features: aka.ms/AzureAcademy-NewFeatures
►Windows Virtual Desktop: aka.ms/AzureAcademy-WVD
►Cloud Adoption Framework:aka.ms/AzureAcademy-CAF

Наука

Опубликовано:

 

29 фев 2020

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 243   
@cornishpastie
@cornishpastie 4 года назад
Brilliant channel with awesome content! Thanks for all your hard work! 👍
@AzureAcademy
@AzureAcademy 4 года назад
Thanks for the feedback!
@thiagofborn
@thiagofborn 3 года назад
On 2:40 The documentation had a little update in the menu structure. So, to follow from the 2:40 pick this path: "How-to guides"-> "Authenticate"-> "Enable on-premises AD DS authentication and authorization". Your videos are the best. You are a great communicator. Overview - On-premises AD DS authentication to Azure file shares | Microsoft Docs
@AzureAcademy
@AzureAcademy 3 года назад
Ok...what’s your question Thiago?
@hexx.hockey
@hexx.hockey 3 года назад
Thank you very much for this video. It was a life saver!
@AzureAcademy
@AzureAcademy 3 года назад
Awesome, thanks for letting me know Alex! Please share The Azure Academy with others
@heivio
@heivio 2 года назад
Excellent video
@AzureAcademy
@AzureAcademy 2 года назад
Thank you, glad it helped
@GirthBrooks775
@GirthBrooks775 4 года назад
So good! Thank you!
@AzureAcademy
@AzureAcademy 4 года назад
Glad you like it! Please Share The Azure Academy with others!
@GirthBrooks775
@GirthBrooks775 4 года назад
@@AzureAcademy it's my go to when I need to catch up my colleagues on WVD.
@AzureAcademy
@AzureAcademy 4 года назад
that is great feedback Jay! But what about all the other things in Azure...where do you go for that content...Azure Academy or somewhere else? I want to keep improving what The Azure Academy offers...so I am working with a few other Microsoft folks to make videos. Today we released the first on Azure Traffic Manager...ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-pKuDPkTECdU.html Next week with be a very special on on Containers.
@GirthBrooks775
@GirthBrooks775 4 года назад
@@AzureAcademy Happy to help! I typically point them towards MS Docs and Learn for most things because leadership is able to track progress on those things. I'm in K12 so things are hectic right now but I've been kicking around the idea of starting a Team for Internal Training and Mentorship. Once I get to that point, this channel would definitely be added to those resources.
@AzureAcademy
@AzureAcademy 4 года назад
awesome! That is how I started The Azure Academy as well. 😁😎👍😉
@dcvander
@dcvander 4 года назад
Great video. This has been a big win this feature set, as using Azure NetApp Files has been a bit of a struggle for profiles. The issue i have been having with Azure Files is the private endpoints. I know that the ADDS functionality depends on a CNAME being created to mirror the connection string, rather than just popping an A record in. I have noticed that if i create a CNAME for the privatelink and host the privatelink DNS for Azure Files, WVD can't authenticate to the endpoint over the private endpoint, but it can if i create a CNAME of the public endpoint (and traverses public). What are the differences between how the AD auth works over the public and private links?
@AzureAcademy
@AzureAcademy 4 года назад
Thanks foir the feedback David. I ran into this issue as well. FSLogix / Windows can't authenticate against the CName, that is why I showed DFS doing basically the same thing in the video. So if you want to use your own friendly name...DFS is the answer!
@yvesleduc
@yvesleduc 4 года назад
Hi. Do you have a video using AADDS auth instead of AD auth on prem since I don't have any AD on prem? I'm looking forward to implement everything in Azure (only Azure environment)?
@AzureAcademy
@AzureAcademy 4 года назад
Yes we do have a video on implementing WVD with Azure AD Domain Services. This video will walk you through setting up AzureADDS, and Azure Files with AzureADDS Authentication, along with FSLogix for WVD. ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-Uayv69FZlyI.html
@anthonyscrivener217
@anthonyscrivener217 3 года назад
This was a great walk through but I do have a question about the security. If we are setting the Storage Pool for Contributer access, does FSLogix change the individual profile folders to that individual user access? What I don’t want is other users roaming and modifying/reading other users profiles.
@AzureAcademy
@AzureAcademy 3 года назад
That was covered in the windows File permissions...that will allow users to write to their own profiles but not to someone elses
@NGranero
@NGranero 4 года назад
Hi Dean! What do you recommend for an environment where I wish to implement FsLogix with Azure AD and AD Onpremise with ADConnect but not AADDS? Azure Files, NetAppFiles, HostPool File Share...? Thanks!
@AzureAcademy
@AzureAcademy 4 года назад
depends on several things. number of users, performance requirements, ease of management...if FSLogix and WVD the ONLY use case, or are there others...size of the shares, number of shares etc.
@reneels6582
@reneels6582 3 года назад
Hey Dean. What's best practice to protect your AzureFile share. Let's assume you have soft delete enabled and also the regular backups which is essentially snapshots to the same storage account how do you protect these shares? If a zone goes down or if the share gets wiped?
@AzureAcademy
@AzureAcademy 3 года назад
Great question Rene! I would use soft delete for 1 day protection. Then use Azure backup for standard protection after that. As for the entire zone going down...all data in Azure is written 3 times on different storage so Microsoft can recover the data in the event of an outage. To my knowledge...thankfully this kind of outage has never happened at a zonal or regional level.
@jakovokah
@jakovokah 3 года назад
Hello. Thank you for your videos, very helpful and understandable. i am new in vwd so sorry about the next questions. I have to install fslogix installer and map the share (apps , vhds) on each VM in my host pool, right ?
@AzureAcademy
@AzureAcademy 3 года назад
Correct Klaus. Each session host need FSLogix installed. But you can manage the settings centrally with GPO
@ramisohail
@ramisohail 3 года назад
Hi Dean, if we want to install the DFS Management, on which server should we install it? do we need a dedicated server for that or we can use the AD or some other vm or is it not recommended?
@AzureAcademy
@AzureAcademy 3 года назад
Depends on your situation...in my small lab My domain controllers are both DFS Servers In a corporation where things are done more “properly” or segmented You would have 1 role per server...so you may have a dedicated DFS Server There is no official recommendation other then to follow your general standard
@guido7269
@guido7269 4 года назад
Very helpful video. I ran into an issue where fslogix created the profile disk on Azure Files initially, but existing profile disk on Azure Files didnt get mounted. I solved that by switching to Cloud Cache instead of VHDLocation. - Still need to do some additional testing...
@AzureAcademy
@AzureAcademy 4 года назад
Glad you got it working. I do not think simply changing from VHDlocations to CCDLocations This just points at a location for the profile. My guess is either permissions or one of the parameters for FSLogix
@abhishekacharyaofficial
@abhishekacharyaofficial 3 года назад
Hi Dean, If a profile is already attached to a session host in Hostpool A and user is using some apps ....will it be able to attach it to a session host on Hostpool B while the user is already on a the first DAG from Hostpool A? if yes, how does it work that way?
@AzureAcademy
@AzureAcademy 3 года назад
Yes you can...but it can get complex. Check out this video on FSLogix advanced features - ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-nDLKlFIAOc8.html
@nephilimcrt
@nephilimcrt 4 года назад
Any idea when this will be available in the West Europe region? I'm implementing WVD for a customer for whom AADDS is not an option. This functionality would allow us to still use Azure Files to store FSLogix profiles instead of bulky file clusters.
@AzureAcademy
@AzureAcademy 4 года назад
Good questions nephilimcrt. I am honestly not sure. That is something that is up to the storage product group. Generally a product is released to public preview, and then by either the next major conference or 6 months later, depending on the feature and the feedback they receive the product will go GA. During the time between public preview and GA is when they roll out to other regions. So while I can't give an exact time frame I would suggest to use the closest region to you for testing today, and keep an eye on the docs, blogs etc...or AzureCharts.com for the latest info
@lifeiss0t0ugh
@lifeiss0t0ugh 3 года назад
Great video Dean.. Does Azure files or Azure Netapp files support configuring user quota? ...if not, any ideas on addressing it?
@AzureAcademy
@AzureAcademy 3 года назад
no, not like windows storage server, where you can give john 3GB and sally 3GB and if they run out of space...that is too bad. The Azure PaaS services don't do that.
@StefanoLardieri
@StefanoLardieri 3 года назад
Grazie.
@AzureAcademy
@AzureAcademy 3 года назад
Prego!
@lourensmeek
@lourensmeek Год назад
Nice video! I have a question, why would you create a new resource group and not using the existing wvd resource group?
@AzureAcademy
@AzureAcademy Год назад
You could put it in the WVD resource group if you want to. In my case I was going to use this storage account for several applications
@hanifaz
@hanifaz 4 года назад
Which one you think is better for FSLogix Roaming containers, Azure NetApp Files or this new Azure Files shares (Storage account)?
@AzureAcademy
@AzureAcademy 4 года назад
Great questions...and I hate to say it Hani Z, but it depends. Depends on your requirements as well as the cost. Azure Files standard is a VERY low cost solution and each share and storage account will have their own max IOPS limits. Premium Azure Files gives you a lot more performance, but the cost is also higher...just like NetApp Files. In terms of management, the easiest path in my opinion is Azure Files, but you may need the level of control that NetApp files will give you...so it does depend. For me, since this is my lab and I need to watch costs...I will use Azure Files.
@kooloolimpah
@kooloolimpah 3 года назад
Dean, thank you for these brilliant videos. A question please: 12:22 in the video. All WVD users get modify perms on the file share. From an administrator standpoint, is there any way to avoid this? It seems as if any user, if they know the UNC path, can access and move around the files there from their desktop session. From my past, as an RDS Admin, used to assign the computer account (session hosts) access to the UPD storage to write to and read from the File Share.
@AzureAcademy
@AzureAcademy 3 года назад
Look more carefully at the permissions. The FSLOGIX doc clearly shows that the users modify permissions are in each users folder. docs.microsoft.com/en-us/fslogix/fslogix-storage-config-ht
@kooloolimpah
@kooloolimpah 3 года назад
@@AzureAcademy Thank you. Interesting. I am wondering how to assign each user rights only to their folder when those folders don't exist yet for a new setup. I am sorry if I am getting confused by the modify perms for all DOMAIN users in the video.
@AzureAcademy
@AzureAcademy 3 года назад
Not a problem. If you are the permissions as the doc shows…and I show in the video that means that each user has permissions through FSLogix to create their own profile folder When they do, they get modify access on that folder and the files inside it…but they don’t have any permissions on anyone else’s folder
@kooloolimpah
@kooloolimpah 3 года назад
@@AzureAcademy I would like to sincerely thank you for clearing this for me. It makes sense now. I had setup the folders but under another parent folder (to separate profiles out per hostpool). Not using "this folder only" option for user writes/reads and to TEST the perms, of course I was able to make changes within that parent folder. The "This folder only" option for WVD users should be the folder that you are putting in the VHD/CCD Location. I redid the test with the proper folder structure with the perms in the doc (only those, and not the domain ones). Tested opening other directories and wasn't able to. This channel has been a life saver for me. Thanks for all your hard work.
@AzureAcademy
@AzureAcademy 3 года назад
Thanks F M happy to help…please share The Azure Academy with your social media so we can continue to help more folks…and let me know what other videos I can create for you!
@girishk2422
@girishk2422 3 года назад
In our environment, I am noticing the fslogix folder is created but not the vdhx file for the first time login. Only the local profile is created. And it doesn't get removed from c:\users after first log off. When the user login the second time, the vhdx file is created and fslogix starts storing the data. Any idea what is missing here that is making fslogix not to store data at first login ?
@AzureAcademy
@AzureAcademy 3 года назад
check your reg keys or GPOs for your FSLogix settings. The default is to not delete existing user profiles, but you can change that. I would delete the user profile, assuming it doesn't have any data, then create a new one and see if it works.
@UnderworldGrim
@UnderworldGrim 3 года назад
I used this video to set this up about 2 months ago. I set the Azure Files object in AD as a computer object, and I found today that I cannot map to the drive anymore. I suspect the password expiration has something to do with it but I'm confused as to how to fix this. I right-clicked the computer object in AD and chose "reset account" to see if this fixed it but no luck. Any suggestions on a fix? How can I set this up in the future so this never happens again? Should I just use a user account in the future and select "password never expire"? Is there a way to prevent the computer account password from expiring other than making a separate password policy GPO just for this computer account?
@AzureAcademy
@AzureAcademy 3 года назад
Here is the doc to reset the password...it is a PowerShell script docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-ad-ds-update-password
@AKSoapy29
@AKSoapy29 3 года назад
FYI, neither "Identity-based access for file shares" or "Active Directory (AD)" are available under Configuration. Did they move to a different area? Edit: It looks like it is only available when you select Standard and not Premium.
@AzureAcademy
@AzureAcademy 3 года назад
Not sure where you are looking...after you build the storage account On the left go to configuration The AD Auth stuff is at the bottom
@user-vc4fw2bk7i
@user-vc4fw2bk7i 2 года назад
Hello Dean, Is there any solution in case user device identity are cloud only? Currently FSLogix doesn't support cloud user identity is there any suggestion or experience in such deployments.
@AzureAcademy
@AzureAcademy 2 года назад
YES…watch this 👉 ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-suvDH-yNL88.html
@JayminJingar
@JayminJingar 2 года назад
Hi Dean, could please create video to configure Private endpoint for storage account ? Thanks
@AzureAcademy
@AzureAcademy 2 года назад
I have covered private link with storage in this video - ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE--GEHbrvEQdY.html
@eliotmansfield
@eliotmansfield 4 года назад
Any thoughts on Disaster recovery? If you build out a 2nd site in another region - how can i have the profiles replicated to a similar file share in the DR site. (I dont particularly want to rely on Microsoft failing over the blob storage when they consider irreparable in the current region nor does it support the need to test/prove that your DR environment works) DFS replication would be nice?
@AzureAcademy
@AzureAcademy 4 года назад
you can do this in a few ways. 1. Azure Storage replication. Set your storage account type to be GRS or ZRS 2. Use a script or robocopy type solution 3. use FSLogix. FSLogix can replicate the data to multiple storage shares and keep them in sync
@eliotmansfield
@eliotmansfield 4 года назад
Azure Academy option 1 doesn’t work because you are subservient to when microsoft decide a disaster is a disaster. Will look into option 3 though. thanks
@AzureAcademy
@AzureAcademy 4 года назад
anytime...Here is the info to help you get started. docs.microsoft.com/en-us/fslogix/configure-cloud-cache-tutorial
@SvenAelterman
@SvenAelterman 4 года назад
It seems like the permissions set on the file share are quite liberal. Does FSLogix manage the permissions more tightly on the individual folders it creates?
@AzureAcademy
@AzureAcademy 4 года назад
Users log in and need to create a folder for themselves...then they need to populate that folder with the profile disk. we also want to ONLY allow users to write to their own folders and not someone else's and finally Admins should be able to do anything. can you provide more detail Sven how how this is too liberal, and how you suggest we secure it further?
@UnderworldGrim
@UnderworldGrim 3 года назад
@@AzureAcademy I believe what Sven is trying to ask is whether the "WVD Users" group having Modify permissions on the root of the Azure Files SMB share is too much. I don't have any experience with this as I'm still trying to get this set up in a lab for myself, but I guess the question comes down to... When an FSLogix container is created for the first time, does that use the user's permissions, thus requiring Modify permissions to the Azure Files SMB share? Or is the container created using some sort of SYSTEM account? If FSLogix container creation doesn't rely on the user's personal permissions, then couldn't we be more strict with their permissions on the root Azure Files folder instead of giving them Modify?
@AzureAcademy
@AzureAcademy 3 года назад
Good question. FSLogix uses the Users permissions to create the profile disk. So yes you need the permissions this way to create everything as well as isolate permissions for each user.
@tharagz08
@tharagz08 4 года назад
I had another question regarding the computer account created in AD. Could you set the computer object's password to never expire to avoid an issue there?
@AzureAcademy
@AzureAcademy 4 года назад
You can but that would be done through AD Group Policy
@tharagz08
@tharagz08 4 года назад
@@AzureAcademy from my reading it's not that the comouter object password expires, but that the default configuration is to cause client computers to initiate the password change every 30 days. From your video it would lead me to believe that it does indeed expire, and that I would need to utilize some setting, such as the GPO setting "Domain member: Disable machine account password changes" to remove this requirement Referencing this article adsecurity.org/?p=280 I'm not sure that any configuration change is required on the computer object that is created when making these shares. Unless there is some policy in place for that particular domain that disables computer objects based on their last login or last pwd set dates, I dont think this would cause issues. With this information do you still think issues would arise if further action is not taken to change default AD behavior in regards to computer objects and Azure file shares using AD auth? Unfortunately this is hard for me to replicate in a lab in a timely manner.
@AzureAcademy
@AzureAcademy 4 года назад
If we take a step back here...the reason for having computer account passwords is to know which computer accounts are healthy and communicating with the domain. If they are not then they get tombstone'd. In this case the computer account for AD Auth with Azure files will never be logged on to, it is being used as a service account. So if you were to set the password on that computer to not expire...if that is possible, or have a VERY large number of days before expiring that would be better for the service...however, The other reason for computer account passwords is security. by having a password that will not expire for a long time can become a security risk. So the answer here is about finding the right balance in your environment.
@UnderworldGrim
@UnderworldGrim 3 года назад
What is the difference between doing it this way vs storing the FSLogix profiles in Azure Blob Storage? Honestly, this seems like more work to have to link it up with Windows AD, add to DFS (optionally) vs simply making a Blob storage account and telling FSLogix to point it there.
@AzureAcademy
@AzureAcademy 3 года назад
You can certainly use blob if you like...but Blob is no where near as performant as Files. Files with AD Auth are more secure then Blob, SMB is also the direction of the product overall, and new updates will focus on that...not blob.
@UnderworldGrim
@UnderworldGrim 3 года назад
@@AzureAcademy This reasoning was exactly what I was looking for, thank you! It was difficult to find any resources comparing the two options.
@AzureAcademy
@AzureAcademy 3 года назад
Happy to help Steve!
@sohrab8668
@sohrab8668 2 года назад
How do we transfer folder shared permission from on prem server to Azure file share without using RBAC, we do it on prem thru MMC, Does Azure have a solution ?
@AzureAcademy
@AzureAcademy 2 года назад
RoboCopy is a tool I have done this with in the past for file server migrations. Another tool would be Azure Files Sync
@ctxshekhar7979
@ctxshekhar7979 Год назад
Hi Dean, in DFS, we dont need the DFS replication for fslogix ?
@AzureAcademy
@AzureAcademy Год назад
Correct DFS-N will give you the same space DFS-R is the replication function And it is NOT needed in FSLogix because it will take care of that natively
@ctxshekhar7979
@ctxshekhar7979 Год назад
@@AzureAcademy Hi Dean, can you please create a complete video on deploying AVD with Azure AD DS ?
@AzureAcademy
@AzureAcademy Год назад
First off…I would not recommend it! Watch this video first 👉 ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-OWGVoJMdIRc.html After that if you STILL want it Watch this one 👉 ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-Uayv69FZlyI.html
@danjackson2208
@danjackson2208 4 года назад
Hi Dean. In this deployment have you seen an issue where once all setup with correct config/permissions etc. a user can browse to the shared UNC path (if they become aware of it) and are then able to list every folder/item and even have full control over the items. It is not only possible to download and mount a VHD/delete it etc, but you can (if it then made any other difference) modify the permissions on any item within the share. They do need to be authenticated with their domain at the time, so external users cannot do this.
@AzureAcademy
@AzureAcademy 4 года назад
you need to change the NTFS folder permissions according to this FSLogix doc - docs.microsoft.com/en-us/fslogix/fslogix-storage-config-ht
@danjackson2208
@danjackson2208 4 года назад
Azure Academy thanks Dean, this was followed. We raised a case with Microsoft and being told this is a current bug/known issue. I was just interested to understand if you had noticed/seen?
@AzureAcademy
@AzureAcademy 4 года назад
I had not run into this myself...but will check again
@danjackson2208
@danjackson2208 4 года назад
Azure Academy thanks, appreciated 👍
@AzureAcademy
@AzureAcademy 4 года назад
anytime!
@ajdinzutic
@ajdinzutic 4 года назад
Is there a Windows Desktop client Insider program available?
@AzureAcademy
@AzureAcademy 4 года назад
Not that I know of
@PaulShadwell
@PaulShadwell 4 года назад
Have you done a video using FSLogix with blob storage? I had a look but couldn't find it in your library.
@AzureAcademy
@AzureAcademy 4 года назад
Hey Paul, No I have not done a video focused on that...yet. I do have a video on FXLogix I am planning that will show in the next month or so that will take a deep dive on FSLogix and upcoming features and scenarios...stay tuned!
@mg5596
@mg5596 3 года назад
@@AzureAcademy Was the new FSLogix video released? I can't find it anywhere. I second a desire for FSLogix with blob video. Thanks!
@AzureAcademy
@AzureAcademy 3 года назад
I have NOT done a blob video...honestly, Blob is NOT the hero solution in FSLogix...SMB however is. It also gives a lot better performance.
@PaulShadwell
@PaulShadwell 3 года назад
@@AzureAcademy but since you can create an SMB share in blob now, what is the solution you recommend? SMB in blob or SMB on a dedicated VM?
@AzureAcademy
@AzureAcademy 3 года назад
hey @Paul So just to be clear...you cannot create an SMB share in Azure blob storage, you have to use Azure Files for this. Azure files are included in a standard Azure storage account along with blob, tables and queues. I would always recommend the Azure Files over a VM running a file share. Cheaper cost, less management and better scale and performance.
@cloudpachehra1113
@cloudpachehra1113 2 года назад
Hey Dean.... waiting for AKS series like AVD ..... 🤟🤟🙂
@AzureAcademy
@AzureAcademy 2 года назад
AKS is very cool…trying to figure out how to do it in a great way that you all deserve
@cloudpachehra1113
@cloudpachehra1113 2 года назад
@@AzureAcademy so true ... but yeah would be amazing series like AVD 😍
@AzureAcademy
@AzureAcademy 2 года назад
True…True
@reneels6582
@reneels6582 4 года назад
Hi. Say I have a small WVD deployment for 6-8 users running only 1 host vm in the pool, instead of using Azure Files or spinning up a vm as a file share I was going to attached a 256GB Premium SSD to that host vm and create the share in there and then setup FSLogix and store the profiles in there. It's not likely this deployment will go past the 6-8 users. Can you see any issues?
@AzureAcademy
@AzureAcademy 4 года назад
At the moment in a small POC perhaps not...however in terms of best practice and how things "should be" setup yes... Cost, High availability, Backup of the profiles, and Performance to name a few 🤔 you have all the profile data on a single disk...which is a single point of failure. I would have multiple disks in a storage spaces array also have Azure Backup protect those profiles. Also this means that you are using a VM to do a job...which costs more than Azure storage to do the same job. also using a VM means that you are dependent on that single VM to be working So when it is down so are the profiles. Profiles contain peoples personal information...they should be protected with backup. Performance depends on a lot of things...like the SKU of the VM, SKU of the disk, network configuration of the VM, in Azure storage at the scale you are talking about you should never hit a performance limit on your profiles...when you get to 50+ then Azure Files standard might have performance issue...maybe. hope this helps. 👍😉
@reneels6582
@reneels6582 4 года назад
@@AzureAcademy thanks for your reply. I would definitely back the VM up, but understand the the other associated risks/issues 👍. Thanks for all the content by the way. It's super helpful!
@AzureAcademy
@AzureAcademy 4 года назад
Anytime...and let me know if you have suggestions for future videos 👍
@AzureAcademy
@AzureAcademy 2 года назад
+Rene Els you cannot store FSLogix profiles on a local disk, they MUST be on a SMB file share of some kind
@AzureAcademy
@AzureAcademy 2 года назад
+Rene Els won’t work at scale. Also, the FSLogix location must be a SMB file share, Azure files will also cost less then additional disks on VMs
@duker741
@duker741 4 года назад
Hi Dean, Once I followed the steps to join the storage account to AD my AD Joined VMs are not passing their logins to the storage account. When I attempt to access the storage account via file explorer I get access denied. During the step of adding the NTFS permissions the proper domain shows up but I am now not sure why its not passing my AD permissions in my VMs under WVD.
@AzureAcademy
@AzureAcademy 4 года назад
+Jesus Duque 1. first thing you have to do is verify that the PowerShell script successfully created the AD user/computer object and has a connection to the storage account. 2. You need to map a drive to a VM that is a member of that same AD domain using the storage account Key 3. Assign the permissions in the Azure storage account for the SMB share contributor and the Elevated contributor for the admin role for step 4 4. Assign the NTFS share permissions for the SAME users or groups you setup for the Azure share contributors role and the elevated contributors role 5. Test the connection from another VM going to the share with that admin user
@duker741
@duker741 4 года назад
Thanks for your reply. Yes followed the steps. AD object created and shows up. As well as those other steps. Opened a case with MS. Lets see what they say.
@AzureAcademy
@AzureAcademy 4 года назад
sounds good
@mcloudwork8395
@mcloudwork8395 3 года назад
@@duker741 I'm experiencing the exact same issue. Did you get the solution from MS support?
@AzureAcademy
@AzureAcademy 3 года назад
Don’t forget what I said about the AD computer object and password resets. If the password lifetime expires then you need to run the password reset commands. You also need to do that if the storage account key has been changed.
@rinaldochristy
@rinaldochristy 4 года назад
Hi Dean, I noticed something strange happening today. I have assigned the required access permissions/roles and the NTFS permissions correctly for my users, however, a test user that I created is unable to access the network share while he is logged into one of my session hosts. It asks for username and password (which i believe it shouldnt be doing) and when I provide the username and password, it says access is denied. Have you come across a situation like this one? Would appreciate your feedback!
@AzureAcademy
@AzureAcademy 4 года назад
Only for 1 specific user...and only when logged on to 1 specific VM? Never seen that. Can you please verify that the test user...when logged onto a different VM...that you KNOW works for other users still fails?
@rinaldochristy
@rinaldochristy 4 года назад
@@AzureAcademy Hi Dean, First of all, thanks a lot for getting back. Actually this was happening to all users except me (The admin), I figured that I also had a custom read-write role for all the WVD Users on the same Storage account. (Such Custom roles dont appear in the Access Control/IAM pane in Azure, and hence I didnt know that until I ran the "az role definition list" cmdlet) I deleted that custom role yesterday, tried again it didnt work, got brain fried and just shut down all my systems as I just didnt know what else to do to get that working. But here is the good news, when I logged in as the test user today, I simply tried to access the network drive again without doing anything at all and ta-da, I was able to reach the network share. So my guess is that - it was that custom role which I previously had that was conflicting with the "Storage File Data SMB Contrbutor" role. Could this be the issue? I dont know for sure. And may be these azure roles take sometime to provision. May be also the NTFS permissions take sometime to actually work.
@rinaldochristy
@rinaldochristy 4 года назад
It doesnt work on only 1 VM of mine somehow! which is ODD !!!! works on every other VM!
@rinaldochristy
@rinaldochristy 4 года назад
Ok now its not working on the other VM's too. This is crazy. Is this a bug or am I doing something wrong? Would appreciate your advise!
@AzureAcademy
@AzureAcademy 4 года назад
custom permissions are very, very difficult to troubleshoot...I generally tell people to never use them. Even if you wrote them perfectly today...Microsoft might change something on the back end of how a resource works to fix an issue and now your permissions don't work correctly anymore...Microsoft also writes the documentation against the built-in roles in Azure. So when we come out with a feature we say you need VM Contributor access...we don't always get into the particular functions of that role...so you need to try and figure it out...it just isn't worth it.
@vishalkalal
@vishalkalal 4 года назад
Can you please have a video on the WVD Licensing?
@AzureAcademy
@AzureAcademy 4 года назад
Thanks for the suggestion Vishal, however I don't think there is enough here for a video. This link has all the info docs.microsoft.com/en-us/azure/virtual-desktop/overview#requirements basically if you have the licensing that is in that doc you can use it...if you don't, then you can't If you can think of other things in the WVD licensing topic that we still need to make clear I am happy to do a video on it. Thanks!
@vishalkalal
@vishalkalal 4 года назад
@@AzureAcademy I have seen the article already but its confusing when you already have the licenses, as an example if you have Office 365 different SKUs which Licenses to buy.
@AzureAcademy
@AzureAcademy 4 года назад
yeah...I don't have more info than that. I focus on the tech side not the $$$ side so I suggest reaching out to a Microsoft licensing expert, Technical account manager or who ever else from Microsoft is assigned to work with your company for help on this.
@ivanrizzuto9404
@ivanrizzuto9404 4 года назад
does it also work with azure ad?
@AzureAcademy
@AzureAcademy 4 года назад
Not at this time Ivan. You can use Azure AD Domain Services, or your own Active Directory. But, who knows...a lot of services are leveraging Azure AD Directly, down the road Azure Files may be able to do that...we will have to see.
@ajdinzutic
@ajdinzutic 4 года назад
hi can you please create a video for MFA? So the WVD Users can Login with Windows Hello.
@AzureAcademy
@AzureAcademy 4 года назад
I just did a video on MFA and co sit-up all access for WVD - ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-31DQ8JuLQes.html
@tharagz08
@tharagz08 4 года назад
Seeing how FSLogix works it had me thinking. For larger WVD environments would a VM's "Max Data Disks" limit affect the number of FSLogix user profile VHD's that could be attached? For example a B2MS can only have 4 data disks
@AzureAcademy
@AzureAcademy 4 года назад
That is a great point Michael. When it comes to your labs...I would say you have the freedom to make what ever choices and configurations you want...but in Production, you always want to use a supported configuration. you can check the doc for the officially supported configurations. docs.microsoft.com/en-us/azure/virtual-desktop/store-fslogix-profile With that said, yes the storage IOPS and throughput you will need for 1000 users will be different than 100 users and you will need to scale the VM SKU and the number of disks, disk size and SKU accordingly.
@tharagz08
@tharagz08 4 года назад
@@AzureAcademy That wasn't quite what I was asking but it did help me evaluate some other design decisions we needed to make for our WVD environment. For the FSLogix profile container, I've opted to go with a Premium Storage Account with the File Share type. My deployment will have about 425 users so I think this will be acceptable. What I am still confused on is how the VM's IOPS limits and Max Data Disks limits come into effect when looking at WVD and FSLogix Profiles. When your user profiles are being stored as FSLogix profiles, does that mean that the IOPS hit is being transferred from the VM and to the Storage Account/File Share? Does a VM's Max Data Disks limit come into play with the amount of FSLogix Profile Containers (the VHDs) that can be attached to a VM? Meaning could a B2MS VM that only has a single OS disk and no additional data disks accept more than 4 logins from users with FSLogix profile containers? A B2ms VM has a 4 data disks limit. I might need to lab up to test some of these questions rather than waiting until a production go-live event for a wide scale test. These might be questions with straight forward answers but for me there is still lots to learn on the ins and outs of efficiently deploying this type of an environment in Azure.
@AzureAcademy
@AzureAcademy 4 года назад
another great question Michael. When setting up any VM there are few things that go into the max storage performance you can get. All of these factors can impact FSLogix performance so finding the right combination of solution and SKU to your performance and value per dollar is going to be based on your requirements and user experience. You are correct that the max number of users you can support will be perportional to the number of disks you have behind that share as well as the SKU of the VM...Here are some things to think about. VM File Server solution 1. The VM SKU will have a max IOPS limit 2. The disk size will determine the max throughput 3. The Disk SKU, HDD, SSD, Premium SSD, Ultra will also impact potential performance You can also link disks together using windows storage spaces or storage spaces direct to get more performance, well beyond a single disk, but you will always be limited by the VM SKU you pick, so find the right size for you. Here is the doc link for the VM disk performance tables docs.microsoft.com/en-us/azure/azure-resource-manager/management/azure-subscription-service-limits#managed-virtual-machine-disks Dealing Azure Files is totally different. Every standard Azure storage account has a max IOPS of 20,000 Each standard Azure Files Share has 1,000 IOPS limit Large Azure Files Shares can go to 10,000 IOPS Premium Azure Files can go up to 100,000 IOPS Here is the doc link for this - docs.microsoft.com/en-us/azure/azure-resource-manager/management/azure-subscription-service-limits#azure-files-limits
@tharagz08
@tharagz08 4 года назад
@@AzureAcademy perfect, that helps a lot. If it would benefit anyone else in a similar position I will respond back in two weeks after our go-live to report my findings in a production environment. You are one of the only channels I have notify all enabled for, your videos have helped me tremendously in our Azure adoption (and in turn my family) so thank you very much!
@AzureAcademy
@AzureAcademy 4 года назад
That is great feedback Michael, I appreciate it!
@denprashlk1618
@denprashlk1618 3 года назад
Hi, I have followed up each of the steps and my storage account successfully joined to on premise AD.Provided RBAC permissions as suggested.However, i cannot map the azure file share as a drive from my domain joined computer.it gives error 86.The specified network password is not correct" error.It only works when i use storage key to mount as a drive.
@AzureAcademy
@AzureAcademy 3 года назад
The order of operations is 1. Create share 2. Add permissions in AFS 3. Map drive with storage key 4. AD Auth join share with PowerShell 5. Set NTFS permissions exactly matching AFS Unmap drive Log in with a user who was granted AFS share contributor access It should use AD Auth If this has not worked for you...try to update the storage account key then reset the AD Computer object password with the PowerShell commands
@denprashlk1618
@denprashlk1618 3 года назад
@@AzureAcademy I'm new to Azure files.What powershell commands i can use to update AD computer object password.Is storage key update is necessary?
@AzureAcademy
@AzureAcademy 3 года назад
Look at the same PowerShell code you used to setup the AD Auth The update code is at the bottom
@denprashlk1618
@denprashlk1618 3 года назад
@@AzureAcademy Thanks ! Followed up each step.Everything works fine now :-)
@AzureAcademy
@AzureAcademy 3 года назад
Awesome, thanks for letting me know!
@ajdinzutic
@ajdinzutic 3 года назад
how can we create a GPO with the connect Setting? I do currently with FileShare on my DC. So everytime, we set new VMs for WVD, they should get the Fileshare. Also be hidden on for WVD users.
@AzureAcademy
@AzureAcademy 3 года назад
For FSLogix the VMs need the FSLogix software installed and configured to use your file share. The computer doesn’t need rights on the share, but the user does. FSLogix does not...and should not be a mapped drive for the users in windows. You configure the path to storage in the registry or in GPO. But I do have other shares that I want on all my session hosts that I do with a GPO and a DFS name space
@ajdinzutic
@ajdinzutic 3 года назад
@@AzureAcademy yeah but how can i add the registry in the gpo? Also can i share the azure file share via gpo? Or do i need custom exenstion to each vm?
@AzureAcademy
@AzureAcademy 3 года назад
YES you can use GPO. Watch this for the entire GPO process. ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-ffZZGVTYHFk.html
@ajdinzutic
@ajdinzutic 3 года назад
@@AzureAcademy thanks i will try that. and what is your best practise for afs? So azure files share and share the FSlogix Profiles, Datadrive in it? because i want also to share AFS over GPO. Is there an easy way for that?
@AzureAcademy
@AzureAcademy 3 года назад
By AFS I think you mean Azure Files Sync Yes you can share this very easily with a GPO...and you can setup a DFS namespace in front of it as well. Check out my video on it all here ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-f-gBzo6Mslk.html
@ajdinzutic
@ajdinzutic 3 года назад
When using the new win10 20h2 images, how can i add the fslogix registry?
@AzureAcademy
@AzureAcademy 3 года назад
if you mean when you deploy the VM you want to add the FSLogix Reg keys...simple. Check out this video clip - ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-jW0e25o-JDo.html
@ajdinzutic
@ajdinzutic 3 года назад
@@AzureAcademy hi thanks for the link. But i dont know how to write the ps script for that. Im searching for docs and cant find any.
@AzureAcademy
@AzureAcademy 3 года назад
Use my PowerShell as an example. github.com/DeanCefola/Azure-WVD/blob/master/PowerShell/New-WVDSessionHost.ps1
@ajdinzutic
@ajdinzutic 3 года назад
@@AzureAcademy Hi Dean thanks for that :) So if i create a new VM i must have a Custom Extension for "Azure File Share" PS, so that it has access to the FS for FS Logix. And after that the Registry PS. Right?
@AzureAcademy
@AzureAcademy 3 года назад
No...the azure files share is something you setup once. And because it is AD Authenticated all users who have access to the share will already have access. SO you just need to build new VMs and put the right UNC to the share location
@PaulShadwell
@PaulShadwell 4 года назад
I have set this up and have it working, however, I have some users working heavily in Outlook in a WVD session complaining about performance. When I look at the VM I don't see any visible bottlenecks. My only conclusion is that it could be the performance of Azure Files that is causing it, since heavy Outlook usage (moving emails between inbox folders) will most likely be using the profile's copy of the OST file. Do you think I will see an improvement if I change the storage account performance to premium? And it looks like I can't change this on an active storage account, so will need to create a new one, if so, can I just copy the existing profiles to the new storage account, anything I should be aware of when migrating profiles? Thanks for all the hard work creating these videos.
@AzureAcademy
@AzureAcademy 4 года назад
First off do you separate user profiles and office profiles? Second are you using cached exchange mode? What is the size of the .ost files? How many users in WVD are there? Finally what is the backend storage...standard or premium?
@PaulShadwell
@PaulShadwell 4 года назад
@@AzureAcademy Thanks for responding Dean. I have not separated user and office profiles as far as I'm aware. There are 2 sets of FSLogix group policy settings for Office and user and I have them both enabled, does that count? As for migrating, I created a new Storage Account using Premium, when you do this you have to select File Shares as the type otherwise it doesn't show up (caught me out the first time when I selected Storage V2). After getting the storage account created in the local AD I then copied the existing profile folders to the new location and changed the group policy to pint to the new location for both office ad user. It all works. I also upgraded the machine again to a high through put VM. So far so good. Tell me more about separating Office and User profiles. OST size for the heavy user seems small at 2GB since his mailbox is well over 60GB. At the moment I only have 2 users, myself and the CIO (heavy outlook user) .
@AzureAcademy
@AzureAcademy 4 года назад
To know for sure if you are separating office and user profile containers...check the share. Does a user have 1 or 2 .vhd(x) files? If you have 2 then you are separating. 😉 For Migrating...sounds like you have that under control The .OST files are based on your Exchange Mode. Depending on the settings of Exchange mode you setup FSLogix. read here for more info - docs.microsoft.com/en-us/fslogix/office-container-configuration-reference#outlookcachedmode
@richardlphillips
@richardlphillips 4 года назад
We have been running WVD with Azure files for around a week now, but have had some issues with users not able to open outlook / excel / word. Hosts seemingly slowing and performance deteriorating. Rebooted the hosts and all seems well, however i also noticed that delete it the office container seem to resolve problems with excel , word and outlook not opening. All very odd. Latency reports as quite low during most the day, slowing to 10ms at peak period in the morning. Hard to know whether premium azure files would be better. We are restricting outlook cache to 3 months I believe. Interested to see what other experiences people are having
@AzureAcademy
@AzureAcademy 4 года назад
several things to check 1. How many users are in your environment FSLogix configurations: 2. are you separating office and user profiles. 3. are those profiles on separate storage account or separate shares 4. what applications are you including in the office profiles? 5. What other things are you enabling in FSLogix Concurrent users Profile types Dynamic disks Profile Sizes
@ajnikurtaj2782
@ajnikurtaj2782 4 года назад
How does the storage account authorize us if it cannot reach ad? Through adfs?
@AzureAcademy
@AzureAcademy 4 года назад
Great Question! 👍 It creates an Active Directory Computer or a Service Account object...which ever you select. This object is used almost like a proxy to allow authentication from AD to the Azure Storage account. The credentials are stored in Your AD...not in Azure. and not stored by Microsoft.
@ajnikurtaj2782
@ajnikurtaj2782 4 года назад
@@AzureAcademy Thanks! Another question... I tried using Azure Private Link so that I have a private IP address instead of going through the internet. Does a custom DNS name from the internal DNS servers work? Like for example share.company.net instead of share.file.core.windows.net. I tried adding cifs/share.company.net to the ServicePrincipalName of the computer account, but it does not authenticate. Any ideas? Is that supported?
@AzureAcademy
@AzureAcademy 4 года назад
by default a new private DNS Zone gets created when you build a private endpoint. usually it is something like .privatelink.file.core.windows.net This is only going to give you a DNS resolver to the private IP. You should be able to use the private IP, or private DNS zone record to get to the storage account.
@ajnikurtaj2782
@ajnikurtaj2782 4 года назад
@@AzureAcademy Resolution of the name from my private dns works without issues. Transparent authentication does not work, I have to insert my credentials again.
@AzureAcademy
@AzureAcademy 4 года назад
When that happens there are a few possibilities Ajni. if it has been more than 30 days the computer account password may have changed and you need to authenticate again docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-active-directory-enable#5-update-the-password-of-your-storage-account-identity-in-ad-ds how exactly are you connecting to the storage? \\.privatelink.file.core.windows.net\ \\.file.core.windows.net\ \\IPAddress\ have you setup the Azure and NTFS Permissions to grant at least 1 user Elevated contributor and full control? Are you being prompted for credentials when you use that use account?
@fardeenkudsi4705
@fardeenkudsi4705 3 года назад
Hello sir, Done like 100 lab's on WVD but struct in Log analytes please help me.
@AzureAcademy
@AzureAcademy 3 года назад
What do you mean stuck on Log Analytics? Which part of Log Analytics? Also have you seen my last video on WVD & Azure Monitor Insights? It does all the WVD Log Analytics work for you! - ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-DQal-x5yHpM.html
@fardeenkudsi4705
@fardeenkudsi4705 3 года назад
@@AzureAcademy thanks for your reply, structed in the query part, in not giving any report, for example top 5 users login logout report, and not able to see disk usage, in workbook
@AzureAcademy
@AzureAcademy 3 года назад
Have you validated that all the components of the workbook have been setup? Also have you configured Diagnostic settings on all the WVD components yet?
@fardeenkudsi4705
@fardeenkudsi4705 3 года назад
@@AzureAcademy thanks for reply, all the components of work book have been set up and diagnostic setting is also correct, if needed I will share some screen shots
@AzureAcademy
@AzureAcademy 3 года назад
😎 cool! 👍👍
@michaeldfulton
@michaeldfulton 3 года назад
It is a challenge to follow your video directions when Microsoft keeps renaming things. You say click on "File Storage". Microsoft renamed it to "Azure Files". Why do they have to put the word Azure in front of everything? Do they think we are going to confuse it with AWS somehow? Anyhow thanks for the video. I may have to do some hunting to find things but it is worth it.
@AzureAcademy
@AzureAcademy 3 года назад
Thanks for the feedback…I will pass it on to the product teams.
Далее
AZ-140 ep07 | Plan FSLogix Storage
14:30
Просмотров 13 тыс.
Image Management | Windows Virtual Desktop - #03
25:05
Бмв сгорела , это нормально?
01:01
ЗЕНИТ - РОСТОВ: обзор матча
01:03
Просмотров 191 тыс.
Azure Files AD Authentication Integration
22:35
Просмотров 33 тыс.
3 Biggest Mistakes AVD Admins Make (Easy, Simple Fix)
16:07
Disable These 3 Windows Settings Now! (For Security)
12:26
How to run Azure Virtual Desktop on-premises
10:23
Просмотров 34 тыс.
FSLogix SECRETS Every AVD Admin Should LEARN
9:50
Просмотров 9 тыс.
Azure Files SMB Access with Windows AD
25:17
Просмотров 73 тыс.
New AVD Admin Portal | Azure Virtual Desktop - #01
21:26