Pro User
Zeitspanne
explore our new search
​
AVD: Break Free From Active Directory
Microsoft Entra
12. Dez 2025 00:09

AVD: Break Free From Active Directory

AVD goes fully cloud native with FSLogix and Azure Files via Microsoft Entra Kerberos, freeing it from Active Directory

Key insights

  • Azure Virtual Desktop (AVD) can now run as a true cloud-only service by joining session hosts directly to Microsoft Entra ID, removing the previous requirement for on‑premises Active Directory or Azure AD Domain Services.
  • FSLogix profile containers and Azure Files shares support Microsoft Entra Kerberos authentication, which lets you store and mount user profiles in the cloud without domain controllers or on‑prem Kerberos dependencies.
  • This change simplifies deployment and management: you can create and manage session hosts in the Azure portal, enable automatic enrollment in Microsoft Intune, and use conditional access and modern authentication for better security and user experience.
  • Note key requirements and limits: session hosts must join the same Entra tenant as users; Single Sign-On (SSO) works for Entra‑joined or hybrid‑joined hosts; some legacy integrations or third‑party tools may still require traditional AD support.
  • To adopt the new model, configure FSLogix to use Entra Kerberos for Azure Files, then verify profile mounting and authentication with logs and connection tests before broad rollout.
  • Operational guidance: define your identity strategy, run pilot migrations, update backup and monitoring plans, and review security policies to ensure a smooth move to a cloud‑native AVD environment.

Video Summary: AVD Goes Cloud-Only

Video Summary: AVD Goes Cloud-Only

The YouTube video from Azure Academy announces a major evolution for Azure Virtual Desktop (AVD): session hosts and profile storage can now authenticate using Microsoft Entra Kerberos without relying on traditional Active Directory. The presenter demonstrates how FSLogix profile containers and Azure Files can accept Kerberos tickets issued by Microsoft Entra ID, effectively enabling a fully cloud-native AVD deployment. Consequently, organizations that have hesitated to move away from on-premises domain controllers may now reconsider cloud-only architectures. The video frames the change as the removal of the "last chain" tying AVD to legacy AD infrastructure, and it explains the configuration steps and verification checks in a practical walkthrough.

Technical Breakthrough: Entra Kerberos for FSLogix

In the demonstration, the author shows how Entra Kerberos integrates with FSLogix so profile containers on Azure Files can be accessed using cloud identities instead of on-premises service accounts. The video outlines the necessary configuration: enabling Entra Kerberos for a tenant, preparing host pools with Microsoft Entra-joined session hosts, and adjusting FSLogix settings to use Entra-issued Kerberos tickets for file share authentication. The presenter also runs a verification sequence so administrators can confirm successful Kerberos delegation and profile mount operations. This step-by-step approach helps teams evaluate whether their current estate can adopt the new authentication flow with minimal disruption.

Moreover, the walkthrough clarifies that session hosts must be joined to the same Microsoft Entra ID tenant as user identities to achieve single sign-on and seamless FSLogix access. While the video uses scripts and sample commands to speed setup, it emphasizes that administrators should validate SPN-like mappings and access controls specific to their storage setup. As a result, organizations get a concrete playbook to reduce on-premises dependency while maintaining profile integrity and performance. The presenter also notes where built-in portal options and Intune enrollment simplify ongoing lifecycle management for Entra-joined VMs.

Tradeoffs and Operational Challenges

Despite the clear benefits, the video also highlights important tradeoffs teams must consider before abandoning Active Directory entirely. For example, classic Group Policy and some legacy management workflows do not have direct equivalents in a pure Entra environment, so IT teams may need to rework policies using Intune or other endpoint management tools. Additionally, certain enterprise features and third-party applications still expect domain-joined machines or on-premises authentication, which means a hybrid approach could remain necessary for a subset of workloads. Therefore, organizations should assess application compatibility and migration effort rather than assuming a one-size-fits-all cutover.

Operationally, the video warns of configuration complexity during the initial rollout: setting up Entra Kerberos, ensuring proper device join state, and verifying file-share access can be unfamiliar to teams used to AD-centric workflows. These steps introduce a short-term increase in administrative effort and testing, though they promise long-term reduction in infrastructure to manage. The presenter also suggests developing rollback plans and retaining an AD-connected environment in parallel until all critical use cases pass validation. This pragmatic stance balances the excitement about cloud-native AVD with the realities of enterprise migration.

Security and Identity Considerations

From a security perspective, the video underscores advantages of relying on Microsoft Entra ID for authentication, such as native conditional access, modern multifactor policies, and centralized identity protection. By using Entra-based Kerberos and cloud-native profiles, administrators can apply zero-trust controls more consistently and reduce exposure associated with on-premises domain controllers. However, the presenter also cautions that identity boundaries become concentrated in the tenant, so robust monitoring, conditional access policies, and safe key management are essential to maintain a strong posture. Thus, while security features improve, they demand disciplined identity governance and operational maturity.

What This Means for IT Teams and Next Steps

The video from Azure Academy positions this update as a turning point that allows many organizations to run AVD as a truly cloud-only service, thereby simplifying estate management and reducing infrastructure costs over time. Yet the presenter recommends a phased migration: pilot Entra-joined host pools, validate FSLogix behavior under load, and confirm application compatibility before decommissioning domain controllers. This cautious approach helps teams balance innovation with continuity and reduces business risk during the transition. Ultimately, the new capability opens opportunities for cloud-first desktop strategies, but successful adoption depends on planning, testing, and aligning identity controls with organizational requirements.

Microsoft Entra - AVD: Break Free From Active Directory

Keywords

Azure Virtual Desktop without Active Directory,AVD without Active Directory,Azure Virtual Desktop Azure AD Join,AVD domainless deployment,AVD Azure AD Join vs Hybrid,Azure AD Domain Services for AVD,migrate AVD from AD to Azure AD,AVD join to Azure AD only