100% Cloud Is Almost Here!!!

  Рет қаралды 11,158

Azure Academy

Azure Academy

Күн бұрын

Azure AD supports a Native Kerberos Realm in the Cloud!!! This raises several important questions, like Why is an Authentication Protocol named after a dog? Why would Azure Active Directory want a Native Kerberos Realm? How can I move to a 100% cloud experience and no longer need to depend on traditional domain controllers? Finally, how will this impact Azure Virtual Desktop and my FSLogix user profiles? Let's Discuss!
▬▬▬▬▬▬ C H A P T E R S 📲 ▬▬▬▬▬▬
0:00 Why is Authentication Named After a Dog?
1:40 Azure AD Kerberos Requirements
2:38 Part 1: Azure AD Kerberos Application
4:42 Part 2: File Share Permissions
8:20 Part 3: Configure AVD Session Hosts
9:30 Azure AD Kerberos Works!
10:45 Check Out Going All Cloud Playlist
▬▬▬▬▬▬ R E S O U R C E S 📡 ▬▬▬▬▬▬
► Azure AD Kerberos Setup: learn.microsoft.com/en-gb/azu...
► FSLogix Permissions: docs.microsoft.com/en-us/fslo...
▬▬▬▬▬▬ S U P P O R T 💰 ▬▬▬▬▬▬
► Become a Learner TODAY: tinyurl.com/AzureAcademy-Subs...
► Twitter: / msazureacademy
► LinkedIn: / dean-cefola-2902934b
#TheAzureAcademy #AzureVirtualDesktop #AzureAD

Пікірлер: 84
@brianplaster344
@brianplaster344 2 жыл бұрын
Your videos are packed with perfectly-paced presentations of practical tasks. Thank you for saving me from the eyestrain brought on by researching, reading, and re-reading Docs pages. I learn so much more, more quickly, watching your videos. Awesome work!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks Brian! Appreciate the feedback ☺️
@kunalkapila3994
@kunalkapila3994 2 жыл бұрын
Dean you are the Star...I always learn so much from your videos
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks Kunal
@sanderscorp670
@sanderscorp670 Жыл бұрын
As always great video Dean ❤
@AzureAcademy
@AzureAcademy Жыл бұрын
Thanks!
@jimparsons8485
@jimparsons8485 2 жыл бұрын
Wow - FINALLY! This is FANTASTIC. I'm very excited to get this information. I passed my AZ-104 today and now this. I think this is going to be a very good year! All this is a treasure of information I'm going to have to get it into my lab and test it straight away.. As always, I appreciate the information!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Congratulations Jim!!! 👍☺️🎈🎉🍰🙌👏🎊👍 Thanks for letting me know!
@deo-max9229
@deo-max9229 2 жыл бұрын
Congrats!🥳 I plan to take the exam in mid February, myself.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Awesome, DM me when you pass!
@deo-max9229
@deo-max9229 2 жыл бұрын
@@AzureAcademy Just passed it today! I messaged you on Patreon!
@AzureAcademy
@AzureAcademy 10 ай бұрын
Congratulations!!!
@maziarrezaei2624
@maziarrezaei2624 2 жыл бұрын
Awesome video and feature!! looking forward to attend "Azure Virtual Desktop Master Class" on January 25.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks Maziar! I’ll see you at the Master Class
@jlou65535
@jlou65535 2 жыл бұрын
Great feature ! Thanks Dean
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Happy to help
@gulczas2005
@gulczas2005 2 жыл бұрын
Amazing video. Thanks a lot. Keep up the good work. Greetings from Poland
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thank you Pawel…Hello Poland! ☺️
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks +Pawel G and HELLOOOO Poland ☺️
@anirudhit
@anirudhit 2 жыл бұрын
Amazing - You are the Best. Always life saver for knowledge seeker.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Anytime Anirudh! What other knowledge are you seeking ☺️
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks!
@deo-max9229
@deo-max9229 2 жыл бұрын
Very, very, very cool!!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
🤣😂😄😊
@Arte-MMN
@Arte-MMN 10 ай бұрын
Insanne video, thanks!
@AzureAcademy
@AzureAcademy 10 ай бұрын
😎 anytime!
@canahmetbe
@canahmetbe Жыл бұрын
Thanks Dean
@AzureAcademy
@AzureAcademy Жыл бұрын
Anytime
@BuggageandGlitchage
@BuggageandGlitchage 2 жыл бұрын
I’ve been waiting eagerly for this video and you didn’t disappoint. Who do I have to charm to get one of those cool t-shirts? :)
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Those are new, I got one for the 2022 AVD Master class that I am key noting with Kam VedBrat sign up for all the fun and prides! - lnkd.in/ef-_rvcE
@BuggageandGlitchage
@BuggageandGlitchage 2 жыл бұрын
@@AzureAcademy already signed up, I hope you’re taking your light sabre. :)
@AzureAcademy
@AzureAcademy 2 жыл бұрын
LOL I always have my LightSaber with my…”This weapon is your life!”
@BindasBadshah
@BindasBadshah 2 жыл бұрын
What a welcome addition. And thanks for very to-the-point video. Quick question related to Kerberos and SmartCard auth. If our AD auth store also trust 3rd party SmartCard i.e Entrust ; any thoughts how will that work?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks Juned, great question…however we don’t know yet. Azure AD Kerberos doesn’t support anything yet other then Azure Files
@bane-dt2ve
@bane-dt2ve 2 жыл бұрын
Hi Dean, amazing videos as always, I’ve followed all the steps and was able to start the fslogix services but i can’t seem to create the vhfx in the storage account that i have created, I’ve notice that your regkey profiles, the content is way different from mine which was emptied at first
@AzureAcademy
@AzureAcademy 2 жыл бұрын
I helped write this FSLogix for the enterprise doc…there is a best practice section - docs.microsoft.com/en-us/azure/architecture/example-scenario/wvd/windows-virtual-desktop-fslogix#best-practice-settings-for-enterprises
@michaelpietrzak2067
@michaelpietrzak2067 2 жыл бұрын
Hope you can do a video on using this feature but with Azure files and using it with the MSIX app attach feature.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
I haven’t tried app attach yet…I believe it should because the VMs are Azure AD Joined and MSIX needs VM level permissions on the storage
@saikuricheti
@saikuricheti 2 жыл бұрын
Great Video Dean. I have to say that your video has lot of hidden elements that has helped me through the process and i was able to successfully configure it. At one point i misconfigured the FSlogix reg keys and couldnt get on to the AADJ computer, even with admin account. I couldnt access the eventviewer or Registry remotely and i had to configure a new VM again. Are there any methods that Microsoft is developing to enable this?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Yes…once everything is done I am hoping that enabling this will be a check box and maybe even setting the FSLogix configuration inside the Azure Portal…stay tuned!
@tabaniz
@tabaniz 2 жыл бұрын
Awesome Great video as always Thanks for sharing this, much appreciated. On a separate note I would like to know what are the differences between your wvdadmin group and wvduser group. What permissions have you set for wvdadmin group? I have been asked if there is a way to have separate logon for administrators so they can perform some admin tasks on WVD. Thank you and I look forward to hearing from you soon. Cheers
@AzureAcademy
@AzureAcademy 2 жыл бұрын
For me the WVD admins own the resources and have all the permissions to do anything. Inside the session host VM they have Admin rights. The WVDUsers group only gets access to the application groups so they can open a remote app or desktop. Inside the session host VM they are ordinary users.
@tabaniz
@tabaniz 2 жыл бұрын
@@AzureAcademy Thank you for your swift reply and kind assistance. Have a great day. Ciao
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Anytime Faddy!
@ketankamble9128
@ketankamble9128 Жыл бұрын
Hi Dean We already have one Storage account and File share which is having the Fslogix profiles , by following the above steps is it possible to use the same existing storage account with enterprise application and RBAC settings ?
@AzureAcademy
@AzureAcademy Жыл бұрын
I’m not sure what you mean? Are you asking if you can set up Azure AD Kerberos on existing storage accounts and file shares…YES you can
@dominicsimonit-professiona770
@dominicsimonit-professiona770 2 жыл бұрын
This sounds great. Will it work with Azure Domain Services as there is no AD Connect?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
No, Azure ADDS is NOT supported yet
@TheInfoVerseHub
@TheInfoVerseHub 2 ай бұрын
Quick question, i got AVD setup, what do you recommend for User profiles, FSlogix? also I should need AADDS for this purpose?
@AzureAcademy
@AzureAcademy 2 ай бұрын
Yes FSLOGIX is AVDs profile management solution. FSLogix does NOT require AADDS. The way you set up FSLogix depends on the join type of your VMs. Watch this for all the answers kzfaq.info/get/bejne/otxynK-bnNWld2g.htmlsi=dwHhMoPDcBrw_XaC
@kimlindell8406
@kimlindell8406 2 жыл бұрын
Thx for a great video! I have one question do you have to have the user password synced to Azure AD for this to work or does it work via Pass-through Authentication?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Great questions Kim, Yes, password hash sync is a minimum requirement for the authentication to work. Reason is that Pass through auth redirects the auth request to a domain controller…and DCs are not part of this experience
@benjamindill7495
@benjamindill7495 2 жыл бұрын
Hello Dean, I have a question on this topic: FSLogix has a registry key called "AccessNetworkAsComputerObject". Is it a bad idea to use this one for Azure Files? Are there specific use-cases when this is needed?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
The default behavior is to attach user profile VHD files to the session host as the user account. AccessNetworkAsComputerObject changes this to attach using the computer instead In Azure files we grant the permissions to the user, so this would not work, because we aren’t giving the computer any permissions today. If the way we permission Azure Files changes, then you could use this feature
@benjamindill7495
@benjamindill7495 2 жыл бұрын
Thanks for the explanation! I tried it saving the storage account key in the credential store of the SYSTEM account of the session host, and it works: users can successfully log on with their containers stored in the Azure Files share. But I guess this is not a valid way to set it up?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
What is your reason for wanting to NOT use the default user authentication?
@moritzknorr-aventa
@moritzknorr-aventa Жыл бұрын
Wow, this tutorial was incredibly helpful! I genuinely appreciate the time and effort you put into creating this high-quality content. I've just donated 5USD to support your channel and help you continue to create more excellent tutorials like this one. However, I have a query regarding something you mentioned in the video. At approximately 00:02:27, you stated that this setup is not limited to utilizing Azure cloud components alone. Is this information still accurate today? I'd be grateful for any updates or alterations on this subject, if there are any. Again, thank you so much for your guidance and dedication to educating others. Your channel has become an invaluable resource for me, and I'm sure many others feel the same way. Keep up the fantastic work!
@AzureAcademy
@AzureAcademy Жыл бұрын
Thanks for your support. As for the cloud only experience…Watch this follow up video kzfaq.info/get/bejne/Z9OjerR2v8W3m4k.html
@moritzknorr-aventa
@moritzknorr-aventa Жыл бұрын
@@AzureAcademy Oh, I somehow didn't see/find that. Thank you very much! I'll have a look at it straight away!
@AzureAcademy
@AzureAcademy Жыл бұрын
No worries! Let me know what your think!
@moritzknorr-aventa
@moritzknorr-aventa Жыл бұрын
@@AzureAcademy Great, thank you very much! Is it possible to manage the rights on the file share? I have now included the file share thanks to the video. But every user has access to every file.
@AzureAcademy
@AzureAcademy Жыл бұрын
That was one of the drawbacks i mentioned in the video with the storage account key option, there is no further granular control. Which means all local admin‘s have access to the file share. As far as user access goes, there is no concern because the users don’t actually have access, the VM system account does.
@alozborne
@alozborne 2 жыл бұрын
I'm currently working with a client to migrate a hosted app of theirs to Azure. They do not need traditional AD and obviously they don't use AD Connect either. I'm using Nerdio NMM to on-board them and I've chosen the pure Azure AD option in NMM when adding the customer account. As you know, that means that I can't use fslogix nor Azure Files as things stand right now. My question is when will we have the ability to go 100% Cloud (Azure AD join + Azure Files + fslogix) for AVD, for my client's use case scenario? Using local profiles only is likely going to present some challenges, but right now this is a proof of concept so I'd love to be able to tell my client that, when we go to production, it will all work with pure Azure AD join + Azure Files + fslogix...
@AzureAcademy
@AzureAcademy 2 жыл бұрын
I know how you feel…I am waiting for it too, not to mention all the customers I work with who are waiting. The Azure AD Kerberos feature is a dependency for the AVD side to move forward, so support and feature advancement on this side has to wait for the feature and support on the Azure AD side. I don’t have any specifics that I can share at this time…all I can say is stay tuned!
@LThibx
@LThibx 4 ай бұрын
@@AzureAcademyHi Dean, great content...gives me a headache though🙃So much info to absorb. I am replying in this comment thread as I am deploying similar to the original commentor and am also using Nerdio...it's 2 years later (now March 2024). I have started on an instance where I will have AVD and a file server to run Quickbooks & Lacerte (tax prep software)....database services need to run on a file server. Cloud only. At this point I haven't yet gotten to the AVD part. Just currently dealing with the file server VM. It is Entra joined with a managed disk. I just can't seem to understand what I need to configure the file shares on that server so that they will be available to AVD users. Hope you can shed some light in the right direction. Thanks for all your efforts in attempt to educate us.
@AzureAcademy
@AzureAcademy 4 ай бұрын
If you have a VM running a file server function then you share it like any other file share Set the NTFS permissions and the share permissions on the share for the AVD users to access it If it is an Azure Files share…then you have to pick if you want to use Active Directory Auth or Entra ID Kerberos Auth, like I showed in this video Then you set those permissions for the AVD Users and you are done
@LThibx
@LThibx 4 ай бұрын
@@AzureAcademyHi Dean, thanks for the reply. When I try to select the security principal, the Entra domain does not show up, only the machine domain itself (local), and the machine is Entra Joined. I checked with dsregcmd /status. Is this because this is a managed disk and not a storage account with a file share? Also I haven't run the powershell code you refer to. Is that still necessary now being Entra in 2024? Thanks in advance. One other thing...I am reading thru all the other comments here...especially the set started by @rg75293...seems to indicate this regular AD & hybrid sync is still needed...still today in 2024? I know you have some videos that talk about 100% cloud only...but this is not very clear at all. Perhaps another video is necessary to clear up the confusion (I am glad to see that I am not the only one...this is VERY confusing). And you can see with my question here, it's not just about AVD & FSLogix, but about typical file servers & file shares as well. We need true Cloud Only Identity, Authentication & Access. Smaller companies don't have DCs. And again much appreciated and thanks for your patience with all of us. 🙃
@AzureAcademy
@AzureAcademy 4 ай бұрын
If you want to use Entra ID Kerberos Auth, then YES even in 2024, you need synced users and a domain controller running the PowerShell script. This is because the PowerShell sets up a type of Domain Trust between Entra and your AD Domain
@rg75293
@rg75293 2 жыл бұрын
If I am going through all these hoops, do I still need hybrid users?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
As of TODAY in the preview…YES. But the goal is to NOT have hybrid users…so we can be 100% cloud and not need active directory at all
@paulmanot7153
@paulmanot7153 Жыл бұрын
@@AzureAcademy What is the reason behind that? I am looking all over the internet and cannot find a straight answer... Does it have to do with the fact that the Kerberos auth needs the user to be registered to a given domain comming through AD Connect? Thanks!
@AzureAcademy
@AzureAcademy Жыл бұрын
Nothing to do with Azure AD Connect directly… Azure AD Kerberos realm presents a Kerberos ticket to the user so they can authenticate back to a domain controller to validate permissions… To do that the domain controller needs a user account to authenticate against…hence Hybrid users - make sense now?
@paulmanot7153
@paulmanot7153 Жыл бұрын
@@AzureAcademy Thanks for the answer Dean ! The kindness and promptness are much appreciated. To be honest it's still a bit fuzzy. what DC are we talking about exactly? My understanding is that Azure AD is not a DC but acts as a KDC. Also we don't have a line of sight on the On Prem DC, just identities syncing. Therefore I don't understand what role the On Prem DC could have here. I ended up reading that the hybrid identities were needed because the SMB share level permission is configured against the identity represented in Azure AD while the directory/file level permission is enforced with that in AD DS. So the principal has to have both attributes and can only retrieve the second from the On Prem id... Is this relevant here or am I completely off topic?
@AzureAcademy
@AzureAcademy Жыл бұрын
There are 2 different implementations for file services Paul. #1 basic auth #2 auth+NTFS PERMISSIONS In basic auth, Azure AD is the KDC and storage is the service and the user is what’s authenticated…no domain controller needed Users will get basically full control In #2 We want granular permissions in the file share Azure AD is still the KDC Your Active Directory name and GUID are needed to locate your domain controller Permissions need to be assign fin the storage account/file share for SMB share contributor and SMB share elevated contributor for ADMIN rights Then you setup windows NTFS permissions Hybrid users are needed here to find the user in the domain and assign NTFS permissions. Does that help
The AVD Admins Super Power!!!
10:00
Azure Academy
Рет қаралды 12 М.
Lets Get One Thing Straight | Azure AD Domain Services
16:22
Azure Academy
Рет қаралды 45 М.
A teacher captured the cutest moment at the nursery #shorts
00:33
Fabiosa Stories
Рет қаралды 47 МЛН
Я обещал подарить ему самокат!
01:00
Vlad Samokatchik
Рет қаралды 7 МЛН
Why Is He Unhappy…?
00:26
Alan Chikin Chow
Рет қаралды 38 МЛН
FSLogix SECRETS Every AVD Admin Should LEARN
9:50
Azure Academy
Рет қаралды 8 М.
3 Biggest Mistakes AVD Admins Make (Easy, Simple Fix)
16:07
Azure Academy
Рет қаралды 17 М.
Azure AD Joined SSO Access to AD Joined Resources!
20:41
John Savill's Technical Training
Рет қаралды 22 М.
How To PREVENT Being HACKED | Azure Firewall Premium 👨‍💻
11:37
"STRANGE" Ways To Deploy AVD People ALWAYS Ask About
11:32
Azure Academy
Рет қаралды 2,8 М.
Azure AD App Registrations, Enterprise Apps and Service Principals
33:44
John Savill's Technical Training
Рет қаралды 215 М.
Deploy Azure AD Domain Service and Join a Server to the Domain
26:57
Travis Roberts
Рет қаралды 113 М.
AzureFiles AD Auth & FSLogix | Windows Virtual Desktop - #02
18:40
Azure Academy
Рет қаралды 45 М.
Hybrid cloud Kerberos trust deployment - Say NO to Hybrid Azure AD Join!!
10:48
CloudManagement.Community
Рет қаралды 19 М.
ОБСЛУЖИЛИ САМЫЙ ГРЯЗНЫЙ ПК
1:00
VA-PC
Рет қаралды 2,5 МЛН
Какой ноутбук взять для учёбы? #msi #rtx4090 #laptop #юмор #игровой #apple #shorts
0:18
iPhone 16 с инновационным аккумулятором
0:45
ÉЖИ АКСЁНОВ
Рет қаралды 10 МЛН