To store FSLogix profile containers for Microsoft Entra joined Azure Virtual Desktop (AVD) session hosts on Azure Files, enable Microsoft Entra Kerberos on the storage account, grant admin consent to the storage account's app, exclude that app from MFA Conditional Access policies, assign share-level and NTFS permissions, then turn on cloud Kerberos ticket retrieval and the FSLogix VHDLocations setting on every session host. Microsoft Entra ID then issues the Kerberos tickets for the SMB share, so the session hosts never need to reach a domain controller.
Who this is for and what you will have
This guide is for administrators who want pooled AVD desktops without running domain controllers or Microsoft Entra Domain Services just for profile storage. It covers hybrid users synced from Active Directory and, in the Azure public cloud, cloud-only users.
At the end you will have:
- An Azure file share that authenticates users through Microsoft Entra Kerberos.
- Share-level roles and Windows ACLs that let each user use only their own profile folder.
- A pooled host pool with Microsoft Entra joined, Intune-enrolled session hosts.
- FSLogix mounting a VHDX profile container from the share.
- A test procedure and fixes for the common errors.
If you are deciding where AVD fits in your wider access design, the zero trust remote access architecture post covers the surrounding identity and network controls. To reduce compute cost once this is running, see AVD scaling plans and autoscale.
How the pieces fit together
User (Windows App)
|
v
AVD pooled host pool -- Entra joined session hosts (Intune enrolled)
| - CloudKerberosTicketRetrievalEnabled = 1
| - LoadCredKeyFromProfile = 1
| - FSLogix: Enabled = 1, VHDLocations = \\<account>.file.core.windows.net\<share>
v
Microsoft Entra ID -- issues Kerberos ticket for cifs/<account>.file.core.windows.net
|
v
Azure Files share -- share-level RBAC + Windows ACLs (NTFS)
|
v
<username>_<user SID>\Profile_<username>.VHDX (with FlipFlopProfileDirectoryName = 1)The storage account can use only one identity source for SMB. If it is already joined to Active Directory Domain Services or Microsoft Entra Domain Services, you must disable that source before enabling Microsoft Entra Kerberos.
Prerequisites
Check these before you start:
- Session host operating system. For hybrid identities, Microsoft lists Windows 11 Enterprise single or multi-session, Windows 10 Enterprise single or multi-session version 2004 or later with current updates, Windows Server 2022 and Windows Server 2025. Cloud-only identities need Windows 11 24H2 or 25H2 with KB5079391 or later, Windows 11 26H1 with KB5079489 or later, or Windows Server 2025. Use Windows 11 Enterprise multi-session for a pooled host pool.
- Device join. Session hosts must be Microsoft Entra joined or Microsoft Entra hybrid joined. Hosts joined only to Active Directory or to Microsoft Entra Domain Services aren't supported for this flow. Don't mix join types in one host pool.
- Hybrid identities. Users and the groups you use for RBAC must be synced from Active Directory with Microsoft Entra Connect Sync or Cloud Sync, and you need one machine with line of sight to a domain controller to set ACLs.
- Windows services. The WinHTTP Web Proxy Auto-Discovery Service (
WinHttpAutoProxySvc) and IP Helper (iphlpsvc) must be running on the clients. You may disable WPAD through the registry, but not the whole service. - SMB security settings. A custom SMB security profile must include Kerberos.
- App management policies. If an application management policy blocks password addition on service principals or restricts their maximum password lifetime to less than 366 days, grant an exception for the Storage Resource Provider app (
a6aa9161-5291-40bb-8c5c-923b567bee3b), otherwise enabling Entra Kerberos fails. - Azure roles. Desktop Virtualization Contributor and Virtual Machine Contributor on the resource group for the host pool and session hosts, plus rights to create role assignments (Owner or User Access Administrator).
- Entra roles. Cloud Application Administrator or Application Administrator to grant consent and enable single sign-on, and rights to edit Conditional Access policies.
Step 1: Create the storage account and enable Microsoft Entra Kerberos
Create a storage account and an SMB file share for the profiles, for example a share named profiles in a storage account named contosoavdprofiles.
In the Azure portal open the storage account, select Data storage > Classic file shares, select the status next to Identity-based access (for example Not configured), select Set up under Microsoft Entra Kerberos, tick the Microsoft Entra Kerberos checkbox and select Save.
With Azure PowerShell:
Set-AzStorageAccount -ResourceGroupName rg-avd-storage -StorageAccountName contosoavdprofiles -EnableAzureActiveDirectoryKerberosForFile $trueOr with the Azure CLI:
az storage account update --name contosoavdprofiles --resource-group rg-avd-storage --enable-files-aadkerb trueFor hybrid identities you can optionally supply the on-premises domain name and GUID so that you can later edit ACLs in File Explorer. Run this on a domain-joined machine and pass the values to Set-AzStorageAccount:
$domainInformation = Get-ADDomain
$domainGuid = $domainInformation.ObjectGUID.ToString()
$domainName = $domainInformation.DnsRoot
Set-AzStorageAccount -ResourceGroupName rg-avd-storage -StorageAccountName contosoavdprofiles -EnableAzureActiveDirectoryKerberosForFile $true -ActiveDirectoryDomainName $domainName -ActiveDirectoryDomainGuid $domainGuidIf you prefer icacls, you can skip the domain details. Editing ACLs in File Explorer isn't supported for cloud-only identities either way.
Step 2: Grant admin consent and exclude the app from MFA
Enabling Entra Kerberos creates an app registration for the storage account. Don't edit it beyond the documented changes.
- In Microsoft Entra ID > App registrations > All applications, open [Storage Account] contosoavdprofiles.file.core.windows.net.
- Under API permissions, select Grant admin consent for your directory and confirm. This consents to
openid,profileandUser.Read. - Exclude the same app from every Conditional Access policy that requires MFA for all resources. Microsoft Entra Kerberos doesn't support MFA for the file share, and there's no interactive prompt during sign-in to satisfy one.
Two additional changes apply in specific cases:
- Cloud-only users. Add the
kdc_enable_cloud_group_sidstag to thetagsarray in the app's manifest so that cloud group SIDs are included in the ticket. Kerberos tickets can carry at most 1,010 group SIDs in total. - Private endpoints. If clients reach the share through a private endpoint, add a
<account>.privatelink.file.core.windows.netentry for every<account>.file.core.windows.netentry in the manifest'sidentifierUris(theapi://<tenantId>/HOST/,CIFS/andHTTP/forms and the bareHOST/,CIFS/andHTTP/forms).
Don't set Assignment required on the storage account's enterprise application. Microsoft documents that this blocks ticket issuance with error AADSTS50105.
Step 3: Assign share-level permissions
Share-level permissions decide who can reach the share at all; NTFS ACLs then decide what they can do inside it. Changes usually take effect within 30 minutes.
The FSLogix storage guidance recommends a default share-level permission of Storage File Data SMB Share Contributor for all authenticated identities, and Storage File Data SMB Share Elevated Contributor for the administrators who will set ACLs.
Set the default permission with PowerShell:
$account = Set-AzStorageAccount -ResourceGroupName rg-avd-storage -AccountName contosoavdprofiles -DefaultSharePermission StorageFileDataSmbShareContributor
$account.AzureFilesIdentityBasedAuthThen give your admin group elevated rights scoped to the share:
az role assignment create --role "Storage File Data SMB Share Elevated Contributor" --assignee admin@contoso.com --scope "/subscriptions/<subscription-id>/resourceGroups/rg-avd-storage/providers/Microsoft.Storage/storageAccounts/contosoavdprofiles/fileServices/default/fileshares/profiles"If you'd rather not grant every authenticated identity access, skip the default permission and assign Storage File Data SMB Share Contributor to the AVD users group on the share instead. For hybrid identities that group must be synced from Active Directory.
Step 4: Set the NTFS permissions on the share root
FSLogix recommends user-based access: each user can create their own folder, only the creator owner can modify it, and an admin group keeps full control.
| Principal | Access | Applies to |
|---|---|---|
| CREATOR OWNER | Modify | Subfolders and files only |
| Admin group | Full control | This folder, subfolders and files |
| AVD users group | Modify | This folder only |
For hybrid identities, run icacls from a machine with line of sight to a domain controller, signed in as a user who holds the Elevated Contributor role (or with the share mounted using the storage account key). To connect with your own identity, that machine must itself be Microsoft Entra joined or hybrid joined and have cloud Kerberos ticket retrieval enabled, as described in Step 6. Each grant string is quoted in full so that PowerShell doesn't try to evaluate the parentheses:
icacls \\contosoavdprofiles.file.core.windows.net\profiles /inheritance:r
icacls \\contosoavdprofiles.file.core.windows.net\profiles /grant:r "CREATOR OWNER:(OI)(CI)(IO)(M)"
icacls \\contosoavdprofiles.file.core.windows.net\profiles /grant:r "CONTOSO\AVD-Admins:(OI)(CI)(F)"
icacls \\contosoavdprofiles.file.core.windows.net\profiles /grant:r "CONTOSO\AVD-Users:(M)"For cloud-only users, open the file share in the Azure portal and use Manage access to add the same entries for Entra users, groups or SIDs.
Step 5: Create the pooled host pool with Entra joined session hosts
In the Azure portal search for Azure Virtual Desktop, select Host pools > Create, and fill in the Basics tab:
- Host pool type: Pooled.
- Load balancing algorithm: breadth-first or depth-first.
- Max session limit: set a real value; autoscale later depends on it.
- Preferred app group type: Desktop.
On the Virtual machines tab, set Add virtual machines to Yes, choose a Windows 11 Enterprise multi-session image, a name prefix of up to 11 characters, Premium SSD for the OS disk, your virtual network and subnet, and No for public inbound ports. Under Domain to join, select Microsoft Entra ID and enable Intune enrollment. Finish the Workspace tab to register the desktop application group, then create the host pool.
The equivalent PowerShell for the host pool object is:
$parameters = @{
Name = 'hp-avd-pooled-01'
ResourceGroupName = 'rg-avd'
HostPoolType = 'Pooled'
LoadBalancerType = 'BreadthFirst'
PreferredAppGroupType = 'Desktop'
MaxSessionLimit = '<value>'
Location = '<AzureRegion>'
IdentityType = 'SystemAssigned'
}
New-AzWvdHostPool @parametersAssign your users group to the desktop application group (Application groups > your group > Assignments > Add), which grants the Desktop Virtualization User role. For host pools without a session host configuration, also assign Virtual Machine User Login to the same group on the session hosts' resource group, and Virtual Machine Administrator Login to admins who need local administrator rights.
For single sign-on, open Microsoft Entra ID > Devices > Remote connection configuration, select Windows Cloud Login and enable the Microsoft Entra ID authentication protocol, then set the host pool RDP property enablerdsaadauth to 1 (Microsoft Entra single sign-on in the portal). Review Conditional Access for the Windows Cloud Login app too.
Step 6: Configure the session hosts
Every session host needs three things. Put them in your image, an Intune policy or both.
1. Cloud Kerberos ticket retrieval. In Intune, use the Settings Catalog setting Kerberos/CloudKerberosTicketRetrievalEnabled set to enabled. Microsoft notes that the OMA-URI method doesn't work on AVD multi-session hosts. The registry equivalent is:
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v CloudKerberosTicketRetrievalEnabled /t REG_DWORD /d 12. Credential keys loaded from the profile. This lets the roaming profile load on any session host:
reg add HKLM\Software\Policies\Microsoft\AzureADAccount /v LoadCredKeyFromProfile /t REG_DWORD /d 13. FSLogix profile container settings. On session hosts created by the Azure Virtual Desktop service FSLogix should already be installed; otherwise install the current version first. Create the recommended values under HKLM\SOFTWARE\FSLogix\Profiles:
$VHDLocations = "\\contosoavdprofiles.file.core.windows.net\profiles"
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name Enabled -PropertyType dword -Value 1 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name DeleteLocalProfileWhenVHDShouldApply -PropertyType dword -Value 1 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name FlipFlopProfileDirectoryName -PropertyType dword -Value 1 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name LockedRetryCount -PropertyType dword -Value 3 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name LockedRetryInterval -PropertyType dword -Value 15 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name ProfileType -PropertyType dword -Value 0 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name ReAttachIntervalSeconds -PropertyType dword -Value 15 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name ReAttachRetryCount -PropertyType dword -Value 3 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name SizeInMBs -PropertyType dword -Value 30000 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name VHDLocations -PropertyType string -Value $VHDLocations -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name VolumeType -PropertyType string -Value vhdx -ForceOnly Enabled and VHDLocations are required. DeleteLocalProfileWhenVHDShouldApply stops users silently landing in a local profile, and FlipFlopProfileDirectoryName makes the container folders easier to browse. Be careful about changing that last value in an existing environment, because users can end up with new, empty profiles.
The settings take effect after a policy refresh or a restart, so restart the session hosts once.
Verify the deployment
- Sign in through Windows App as a test user who is assigned to the application group and has never signed in to these hosts. An existing local profile would otherwise be used.
- In the session, open a terminal and run:
cd "C:\Program Files\FSLogix\Apps"
.\frx.exe list-redirectsYou should see the user's profile path redirected to a new volume, for example \Device\HarddiskVolume4\Users\<user> => \Device\HarddiskVolume9\Profile.
- Confirm the session host can get a ticket for the share:
klist get cifs/contosoavdprofiles.file.core.windows.net- In the Azure portal open the storage account, select File shares >
profiles, and check that a folder for the user exists containing a VHDX file. WithFlipFlopProfileDirectoryNameset to 1 the folder is named<username>_<SID>; without it,<SID>_<username>.
For a broader check, run Debug-AzStorageAccountAuth from the AzFilesHybrid module (0.3.0 or later). For Entra Kerberos accounts it tests port 445, Entra connectivity, the registry key, admin consent, the required Windows services and the device join type.
Troubleshooting
System error 1327: "Account restrictions are preventing this user from signing in." An MFA Conditional Access policy applies to the storage account app. Exclude [Storage Account] contosoavdprofiles.file.core.windows.net from it.
Error 1326: "The username or password is incorrect" through a private endpoint. The client fell back to NTLM because the private link FQDN isn't registered on the app. Add the privatelink entries to identifierUris and point internal DNS at the private endpoint.
System error 5: Access is denied. Share-level permissions are missing or haven't propagated. Check the default share permission or the role assignment on the share and allow up to 30 minutes.
AADSTS50105. Assignment required is enabled on the storage account's enterprise app. Turn it off.
Profiles stop working after about 10 hours in one session. Microsoft Entra ID doesn't support renewing the Kerberos ticket-granting ticket, so access fails once it expires until the user signs out and back in. For hybrid joined clients, a cloud trust with Active Directory is the documented mitigation; it isn't available to Entra-only joined hosts.
Mount fails and logs show the service ticket can't be decrypted. The SupportedEncryptionTypes Kerberos policy excludes AES. Microsoft Entra Kerberos always uses AES-256, so remove the restriction or explicitly allow AES256_HMAC_SHA1, then restart.
Users get a temporary or local profile. Confirm Enabled and VHDLocations exist under HKLM\SOFTWARE\FSLogix\Profiles, that CloudKerberosTicketRetrievalEnabled is 1, and that the host has restarted since the policy applied.
Closing checklist
- Storage account uses Microsoft Entra Kerberos as its only identity source.
- Admin consent granted on the storage account's app; app excluded from MFA Conditional Access policies; Assignment required off.
kdc_enable_cloud_group_sidstag added if any users are cloud-only;privatelinkidentifier URIs added if you use a private endpoint.- Share-level roles assigned and propagated; NTFS ACLs set for CREATOR OWNER, admins and users.
- Host pool pooled, Entra joined, with a real max session limit and users assigned to the desktop application group and to Virtual Machine User Login.
- Session hosts have the Kerberos, credential key and FSLogix values, and have restarted.
- A first test sign-in creates a VHDX on the share.
References
- Store FSLogix profile containers on Azure Files using Microsoft Entra ID
- Microsoft Entra Kerberos authentication for Azure Files
- Assign share-level permissions for Azure Files
- Configure SMB storage permissions for FSLogix
- Configure profile containers with FSLogix
- Deploy Azure Virtual Desktop
- Microsoft Entra joined session hosts in Azure Virtual Desktop
- Configure single sign-on for Azure Virtual Desktop using Microsoft Entra ID
- Troubleshoot Azure Files identity-based authentication (SMB)