Cloud & infrastructure

AVD pooled host pool with FSLogix profiles on Azure Files (Entra Kerberos)

Build an Azure Virtual Desktop pooled host pool with Microsoft Entra joined session hosts and FSLogix profile containers stored on Azure Files, using Microsoft Entra Kerberos instead of domain controllers.

13 min read
On this page

To store FSLogix profile containers for Microsoft Entra joined Azure Virtual Desktop (AVD) session hosts on Azure Files, enable Microsoft Entra Kerberos on the storage account, grant admin consent to the storage account's app, exclude that app from MFA Conditional Access policies, assign share-level and NTFS permissions, then turn on cloud Kerberos ticket retrieval and the FSLogix VHDLocations setting on every session host. Microsoft Entra ID then issues the Kerberos tickets for the SMB share, so the session hosts never need to reach a domain controller.

Who this is for and what you will have

This guide is for administrators who want pooled AVD desktops without running domain controllers or Microsoft Entra Domain Services just for profile storage. It covers hybrid users synced from Active Directory and, in the Azure public cloud, cloud-only users.

At the end you will have:

  • An Azure file share that authenticates users through Microsoft Entra Kerberos.
  • Share-level roles and Windows ACLs that let each user use only their own profile folder.
  • A pooled host pool with Microsoft Entra joined, Intune-enrolled session hosts.
  • FSLogix mounting a VHDX profile container from the share.
  • A test procedure and fixes for the common errors.

If you are deciding where AVD fits in your wider access design, the zero trust remote access architecture post covers the surrounding identity and network controls. To reduce compute cost once this is running, see AVD scaling plans and autoscale.

How the pieces fit together

User (Windows App)
   |
   v
AVD pooled host pool  --  Entra joined session hosts (Intune enrolled)
   |                        - CloudKerberosTicketRetrievalEnabled = 1
   |                        - LoadCredKeyFromProfile = 1
   |                        - FSLogix: Enabled = 1, VHDLocations = \\<account>.file.core.windows.net\<share>
   v
Microsoft Entra ID  --  issues Kerberos ticket for cifs/<account>.file.core.windows.net
   |
   v
Azure Files share  --  share-level RBAC  +  Windows ACLs (NTFS)
   |
   v
<username>_<user SID>\Profile_<username>.VHDX   (with FlipFlopProfileDirectoryName = 1)

The storage account can use only one identity source for SMB. If it is already joined to Active Directory Domain Services or Microsoft Entra Domain Services, you must disable that source before enabling Microsoft Entra Kerberos.

Prerequisites

Check these before you start:

  • Session host operating system. For hybrid identities, Microsoft lists Windows 11 Enterprise single or multi-session, Windows 10 Enterprise single or multi-session version 2004 or later with current updates, Windows Server 2022 and Windows Server 2025. Cloud-only identities need Windows 11 24H2 or 25H2 with KB5079391 or later, Windows 11 26H1 with KB5079489 or later, or Windows Server 2025. Use Windows 11 Enterprise multi-session for a pooled host pool.
  • Device join. Session hosts must be Microsoft Entra joined or Microsoft Entra hybrid joined. Hosts joined only to Active Directory or to Microsoft Entra Domain Services aren't supported for this flow. Don't mix join types in one host pool.
  • Hybrid identities. Users and the groups you use for RBAC must be synced from Active Directory with Microsoft Entra Connect Sync or Cloud Sync, and you need one machine with line of sight to a domain controller to set ACLs.
  • Windows services. The WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) and IP Helper (iphlpsvc) must be running on the clients. You may disable WPAD through the registry, but not the whole service.
  • SMB security settings. A custom SMB security profile must include Kerberos.
  • App management policies. If an application management policy blocks password addition on service principals or restricts their maximum password lifetime to less than 366 days, grant an exception for the Storage Resource Provider app (a6aa9161-5291-40bb-8c5c-923b567bee3b), otherwise enabling Entra Kerberos fails.
  • Azure roles. Desktop Virtualization Contributor and Virtual Machine Contributor on the resource group for the host pool and session hosts, plus rights to create role assignments (Owner or User Access Administrator).
  • Entra roles. Cloud Application Administrator or Application Administrator to grant consent and enable single sign-on, and rights to edit Conditional Access policies.

Step 1: Create the storage account and enable Microsoft Entra Kerberos

Create a storage account and an SMB file share for the profiles, for example a share named profiles in a storage account named contosoavdprofiles.

In the Azure portal open the storage account, select Data storage > Classic file shares, select the status next to Identity-based access (for example Not configured), select Set up under Microsoft Entra Kerberos, tick the Microsoft Entra Kerberos checkbox and select Save.

With Azure PowerShell:

Set-AzStorageAccount -ResourceGroupName rg-avd-storage -StorageAccountName contosoavdprofiles -EnableAzureActiveDirectoryKerberosForFile $true

Or with the Azure CLI:

az storage account update --name contosoavdprofiles --resource-group rg-avd-storage --enable-files-aadkerb true

For hybrid identities you can optionally supply the on-premises domain name and GUID so that you can later edit ACLs in File Explorer. Run this on a domain-joined machine and pass the values to Set-AzStorageAccount:

$domainInformation = Get-ADDomain
$domainGuid = $domainInformation.ObjectGUID.ToString()
$domainName = $domainInformation.DnsRoot
 
Set-AzStorageAccount -ResourceGroupName rg-avd-storage -StorageAccountName contosoavdprofiles -EnableAzureActiveDirectoryKerberosForFile $true -ActiveDirectoryDomainName $domainName -ActiveDirectoryDomainGuid $domainGuid

If you prefer icacls, you can skip the domain details. Editing ACLs in File Explorer isn't supported for cloud-only identities either way.

Enabling Entra Kerberos creates an app registration for the storage account. Don't edit it beyond the documented changes.

  1. In Microsoft Entra ID > App registrations > All applications, open [Storage Account] contosoavdprofiles.file.core.windows.net.
  2. Under API permissions, select Grant admin consent for your directory and confirm. This consents to openid, profile and User.Read.
  3. Exclude the same app from every Conditional Access policy that requires MFA for all resources. Microsoft Entra Kerberos doesn't support MFA for the file share, and there's no interactive prompt during sign-in to satisfy one.

Two additional changes apply in specific cases:

  • Cloud-only users. Add the kdc_enable_cloud_group_sids tag to the tags array in the app's manifest so that cloud group SIDs are included in the ticket. Kerberos tickets can carry at most 1,010 group SIDs in total.
  • Private endpoints. If clients reach the share through a private endpoint, add a <account>.privatelink.file.core.windows.net entry for every <account>.file.core.windows.net entry in the manifest's identifierUris (the api://<tenantId>/HOST/, CIFS/ and HTTP/ forms and the bare HOST/, CIFS/ and HTTP/ forms).

Don't set Assignment required on the storage account's enterprise application. Microsoft documents that this blocks ticket issuance with error AADSTS50105.

Step 3: Assign share-level permissions

Share-level permissions decide who can reach the share at all; NTFS ACLs then decide what they can do inside it. Changes usually take effect within 30 minutes.

The FSLogix storage guidance recommends a default share-level permission of Storage File Data SMB Share Contributor for all authenticated identities, and Storage File Data SMB Share Elevated Contributor for the administrators who will set ACLs.

Set the default permission with PowerShell:

$account = Set-AzStorageAccount -ResourceGroupName rg-avd-storage -AccountName contosoavdprofiles -DefaultSharePermission StorageFileDataSmbShareContributor
$account.AzureFilesIdentityBasedAuth

Then give your admin group elevated rights scoped to the share:

az role assignment create --role "Storage File Data SMB Share Elevated Contributor" --assignee admin@contoso.com --scope "/subscriptions/<subscription-id>/resourceGroups/rg-avd-storage/providers/Microsoft.Storage/storageAccounts/contosoavdprofiles/fileServices/default/fileshares/profiles"

If you'd rather not grant every authenticated identity access, skip the default permission and assign Storage File Data SMB Share Contributor to the AVD users group on the share instead. For hybrid identities that group must be synced from Active Directory.

Step 4: Set the NTFS permissions on the share root

FSLogix recommends user-based access: each user can create their own folder, only the creator owner can modify it, and an admin group keeps full control.

PrincipalAccessApplies to
CREATOR OWNERModifySubfolders and files only
Admin groupFull controlThis folder, subfolders and files
AVD users groupModifyThis folder only

For hybrid identities, run icacls from a machine with line of sight to a domain controller, signed in as a user who holds the Elevated Contributor role (or with the share mounted using the storage account key). To connect with your own identity, that machine must itself be Microsoft Entra joined or hybrid joined and have cloud Kerberos ticket retrieval enabled, as described in Step 6. Each grant string is quoted in full so that PowerShell doesn't try to evaluate the parentheses:

icacls \\contosoavdprofiles.file.core.windows.net\profiles /inheritance:r
icacls \\contosoavdprofiles.file.core.windows.net\profiles /grant:r "CREATOR OWNER:(OI)(CI)(IO)(M)"
icacls \\contosoavdprofiles.file.core.windows.net\profiles /grant:r "CONTOSO\AVD-Admins:(OI)(CI)(F)"
icacls \\contosoavdprofiles.file.core.windows.net\profiles /grant:r "CONTOSO\AVD-Users:(M)"

For cloud-only users, open the file share in the Azure portal and use Manage access to add the same entries for Entra users, groups or SIDs.

Step 5: Create the pooled host pool with Entra joined session hosts

In the Azure portal search for Azure Virtual Desktop, select Host pools > Create, and fill in the Basics tab:

  • Host pool type: Pooled.
  • Load balancing algorithm: breadth-first or depth-first.
  • Max session limit: set a real value; autoscale later depends on it.
  • Preferred app group type: Desktop.

On the Virtual machines tab, set Add virtual machines to Yes, choose a Windows 11 Enterprise multi-session image, a name prefix of up to 11 characters, Premium SSD for the OS disk, your virtual network and subnet, and No for public inbound ports. Under Domain to join, select Microsoft Entra ID and enable Intune enrollment. Finish the Workspace tab to register the desktop application group, then create the host pool.

The equivalent PowerShell for the host pool object is:

$parameters = @{
    Name                  = 'hp-avd-pooled-01'
    ResourceGroupName     = 'rg-avd'
    HostPoolType          = 'Pooled'
    LoadBalancerType      = 'BreadthFirst'
    PreferredAppGroupType = 'Desktop'
    MaxSessionLimit       = '<value>'
    Location              = '<AzureRegion>'
    IdentityType          = 'SystemAssigned'
}
New-AzWvdHostPool @parameters

Assign your users group to the desktop application group (Application groups > your group > Assignments > Add), which grants the Desktop Virtualization User role. For host pools without a session host configuration, also assign Virtual Machine User Login to the same group on the session hosts' resource group, and Virtual Machine Administrator Login to admins who need local administrator rights.

For single sign-on, open Microsoft Entra ID > Devices > Remote connection configuration, select Windows Cloud Login and enable the Microsoft Entra ID authentication protocol, then set the host pool RDP property enablerdsaadauth to 1 (Microsoft Entra single sign-on in the portal). Review Conditional Access for the Windows Cloud Login app too.

Step 6: Configure the session hosts

Every session host needs three things. Put them in your image, an Intune policy or both.

1. Cloud Kerberos ticket retrieval. In Intune, use the Settings Catalog setting Kerberos/CloudKerberosTicketRetrievalEnabled set to enabled. Microsoft notes that the OMA-URI method doesn't work on AVD multi-session hosts. The registry equivalent is:

reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v CloudKerberosTicketRetrievalEnabled /t REG_DWORD /d 1

2. Credential keys loaded from the profile. This lets the roaming profile load on any session host:

reg add HKLM\Software\Policies\Microsoft\AzureADAccount /v LoadCredKeyFromProfile /t REG_DWORD /d 1

3. FSLogix profile container settings. On session hosts created by the Azure Virtual Desktop service FSLogix should already be installed; otherwise install the current version first. Create the recommended values under HKLM\SOFTWARE\FSLogix\Profiles:

$VHDLocations = "\\contosoavdprofiles.file.core.windows.net\profiles"
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name Enabled -PropertyType dword -Value 1 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name DeleteLocalProfileWhenVHDShouldApply -PropertyType dword -Value 1 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name FlipFlopProfileDirectoryName -PropertyType dword -Value 1 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name LockedRetryCount -PropertyType dword -Value 3 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name LockedRetryInterval -PropertyType dword -Value 15 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name ProfileType -PropertyType dword -Value 0 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name ReAttachIntervalSeconds -PropertyType dword -Value 15 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name ReAttachRetryCount -PropertyType dword -Value 3 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name SizeInMBs -PropertyType dword -Value 30000 -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name VHDLocations -PropertyType string -Value $VHDLocations -Force
New-ItemProperty -Path HKLM:\SOFTWARE\FSLogix\Profiles\ -Name VolumeType -PropertyType string -Value vhdx -Force

Only Enabled and VHDLocations are required. DeleteLocalProfileWhenVHDShouldApply stops users silently landing in a local profile, and FlipFlopProfileDirectoryName makes the container folders easier to browse. Be careful about changing that last value in an existing environment, because users can end up with new, empty profiles.

The settings take effect after a policy refresh or a restart, so restart the session hosts once.

Verify the deployment

  1. Sign in through Windows App as a test user who is assigned to the application group and has never signed in to these hosts. An existing local profile would otherwise be used.
  2. In the session, open a terminal and run:
cd "C:\Program Files\FSLogix\Apps"
.\frx.exe list-redirects

You should see the user's profile path redirected to a new volume, for example \Device\HarddiskVolume4\Users\<user> => \Device\HarddiskVolume9\Profile.

  1. Confirm the session host can get a ticket for the share:
klist get cifs/contosoavdprofiles.file.core.windows.net
  1. In the Azure portal open the storage account, select File shares > profiles, and check that a folder for the user exists containing a VHDX file. With FlipFlopProfileDirectoryName set to 1 the folder is named <username>_<SID>; without it, <SID>_<username>.

For a broader check, run Debug-AzStorageAccountAuth from the AzFilesHybrid module (0.3.0 or later). For Entra Kerberos accounts it tests port 445, Entra connectivity, the registry key, admin consent, the required Windows services and the device join type.

Troubleshooting

System error 1327: "Account restrictions are preventing this user from signing in." An MFA Conditional Access policy applies to the storage account app. Exclude [Storage Account] contosoavdprofiles.file.core.windows.net from it.

Error 1326: "The username or password is incorrect" through a private endpoint. The client fell back to NTLM because the private link FQDN isn't registered on the app. Add the privatelink entries to identifierUris and point internal DNS at the private endpoint.

System error 5: Access is denied. Share-level permissions are missing or haven't propagated. Check the default share permission or the role assignment on the share and allow up to 30 minutes.

AADSTS50105. Assignment required is enabled on the storage account's enterprise app. Turn it off.

Profiles stop working after about 10 hours in one session. Microsoft Entra ID doesn't support renewing the Kerberos ticket-granting ticket, so access fails once it expires until the user signs out and back in. For hybrid joined clients, a cloud trust with Active Directory is the documented mitigation; it isn't available to Entra-only joined hosts.

Mount fails and logs show the service ticket can't be decrypted. The SupportedEncryptionTypes Kerberos policy excludes AES. Microsoft Entra Kerberos always uses AES-256, so remove the restriction or explicitly allow AES256_HMAC_SHA1, then restart.

Users get a temporary or local profile. Confirm Enabled and VHDLocations exist under HKLM\SOFTWARE\FSLogix\Profiles, that CloudKerberosTicketRetrievalEnabled is 1, and that the host has restarted since the policy applied.

Closing checklist

  • Storage account uses Microsoft Entra Kerberos as its only identity source.
  • Admin consent granted on the storage account's app; app excluded from MFA Conditional Access policies; Assignment required off.
  • kdc_enable_cloud_group_sids tag added if any users are cloud-only; privatelink identifier URIs added if you use a private endpoint.
  • Share-level roles assigned and propagated; NTFS ACLs set for CREATOR OWNER, admins and users.
  • Host pool pooled, Entra joined, with a real max session limit and users assigned to the desktop application group and to Virtual Machine User Login.
  • Session hosts have the Kerberos, credential key and FSLogix values, and have restarted.
  • A first test sign-in creates a VHDX on the share.

References

Questions people ask

Do AVD session hosts need line of sight to a domain controller for FSLogix on Azure Files?

No. With Microsoft Entra Kerberos, Microsoft Entra ID issues the Kerberos tickets for the file share, so Entra joined session hosts don't need to reach a domain controller. For hybrid identities you still need a machine with line of sight to a domain controller to set the Windows ACLs on the share with icacls or File Explorer.

Why do users get System error 1327 when mapping the Azure file share?

Microsoft Entra Kerberos doesn't support MFA for the storage account. If a Conditional Access policy that requires MFA applies to all resources, the storage account's app is included and ticket requests fail. Exclude the app named [Storage Account] storageaccount.file.core.windows.net from those policies.

Can cloud-only users use FSLogix profiles on Azure Files?

Yes, in the Azure public cloud. Cloud-only identities need supported Windows 11 or Windows Server 2025 builds, the kdc_enable_cloud_group_sids tag on the storage account's app manifest, and permissions set through the share's Manage access page, because File Explorer ACL editing isn't supported for cloud-only identities.

Which share-level role should FSLogix users get on Azure Files?

Microsoft's FSLogix guidance recommends Storage File Data SMB Share Contributor as the default share-level permission for all authenticated identities, plus Storage File Data SMB Share Elevated Contributor for the administrators who set the Windows ACLs.

Azure Virtual DesktopFSLogixAzure FilesEntra KerberosMicrosoft Entra ID
  1. AVD scaling plans: autoscale session hosts and Start VM on Connect

    Configure an Azure Virtual Desktop power management scaling plan, Start VM on Connect and disconnected-session limits so pooled session hosts are deallocated when nobody needs them.

  2. Migrate from the Remote Desktop client to Windows App with Intune

    Replace the retired Remote Desktop MSI client with Windows App on managed devices: find remaining users, deploy through Intune, control updates and remove the legacy client.

  3. Windows 365 vs Azure Virtual Desktop: licensing, cost and management

    Compare Windows 365 Cloud PCs and Azure Virtual Desktop on licensing, cost model, management, networking and user experience, and pick the right platform for each group of users.