AVD SignIn Sign Out taking too long - FSLogix AppServices Error
While implementing AVD solution in customer environment the sign-out operation was taking too long. Because the sign-out was not graceful and subsequent sign-in operation for the same user was not happening and the black screen was getting hung up with the "Please wait for FSLogix AppServices" message as shown in the screenshot below. There was a delay in user’s sign-in and sign-out to session host and FSLogix profiles were not loaded & Inactive for few users.
In this subscription and AD tenant environment FSLogix cloud cache was implemented for all users accessing AVD and conditional access policies with MFA were heavily applied at tenant level.
Resolution: As per the Microsoft Document, Microsoft Entra Kerberos doesn't support using MFA & CA Policy to access Azure file shares configured with Microsoft Entra Kerberos.
In the conditional access policy of the customer environment "All Cloud Apps" were included in the MFA policy. The MFA policy was getting applied on all cloud application including the storage account. Storage account was being treated as a cloud app.
Storage account must be excluded from all cloud apps in the Conditional Access Policy.
Ref Link : Microsoft Entra Kerberos for hybrid identities on Azure Files | Microsoft Learn
Modify the conditional access policy as shown below for excluding Storage Account and Azure windows VM Sign-In
The black screen issue was resolved as soon as the above mentioned changes were made. There was no problem with FSLogix version or registry settings. All other configurations were fine.
Published on:
Learn moreRelated posts
Enable IP restriction for a public facing App service
In this blog article, we will cover how to control the app service deployment to support only public facing app service with IP restriction en...
Selecting the Optimal Container for Azure AI: Docker, ACI, or AKS?
Deploying Azure AI services in containers like Docker, Azure Container Instances (ACI), or Azure Kubernetes Service (...
Securing Hardware and Firmware Supply Chains
In the modern cloud data center, ensuring the authenticity, integrity, and security of hardware and firmware is paramount. Firmware is the low...
Liquid Cooling in Air Cooled Data Centers on Microsoft Azure
With the advent of artificial intelligence and machine learning (AI/ML), hyperscale datacenters are increasingly accommodating AI accelerators...
Mt Diablo - Disaggregated Power Fueling the Next Wave of AI Platforms
Authors: Jason Adrian – General Manager, Azure Platform Architecture Laurentiu Olariu – Power Architect, Azure Platform Architecture Banha Sok...
Deny inbound NSG Rule creation via Azure Policy
In this blog article, we will cover how to deny the creation of inbound Network Security Group Rules if the inbound NSG Rule contains&n...
Azure Extended Zones: Optimizing Performance, Compliance, and Accessibility
Azure Extended Zones are designed to bring the power of Azure closer to end users in specific metropolitan areas or jurisdictions, cate...
Inside Maia 100: Revolutionizing AI Workloads with Microsoft's Custom AI Accelerator
Authored by: Sherry Xu, Partner Lead SoC Architect, Azure Maia Chandru Ramakrishnan, Partner Software Engineering Manager As the advanc...
Accelerate Cloud Potential for Your SAP Workloads on Azure with these Learning Paths
Accelerate Cloud Potential for Your SAP Workloads on Azure with these Learning Paths In today's rapidly evolving digital landsc...
Azure Role Assignments Audit Report
Overview: Azure Administrators often come across challenges while tracking multiple Azure role assignments and removals. At present Azur...