Modernize VDI with Azure Information and Entra Cloud-Native Identities


Whats up People!

When you have ever run a Digital Desktop Infrastructure (VDI) property, you understand the recurring riddle. The session hosts are designed to be stateless and pooled, but each person expects a persistent Outlook profile, their OneDrive cache, their pinned apps, and a sub-ten-second logon. On this session on the Microsoft Azure Infrastructure Summit 2026, Adam Groves and Priyanka Gangal from the Azure Information workforce confirmed how Azure Information plus Microsoft Entra ID lastly allow you to ship that have with out dragging area controllers alongside for the experience.

📺 Watch the session:

 

VDI has all the time been a balancing act between elasticity and continuity. The compute layer desires to be ephemeral. The person desires to be at house. Bridging these two worlds used to imply a stack of id plumbing that quietly grew till it turned its personal platform. This session modifications that math.

Here’s what jumped out for me:

  • Cloud-only id for SMB. Azure Information now authenticates pure Microsoft Entra ID customers and teams, together with B2B friends, instantly over SMB Kerberos. No on-premises Lively Listing required, no Entra Join required, no line of sight to a website controller.
  • NTFS ACLs and Kerberos preserved. You retain the safety mannequin your apps already perceive. Permissions nonetheless stay on the file system, tickets nonetheless come over SMB, and FSLogix doesn’t care that the id stack beneath is totally different.
  • Efficiency constructed for the spike. Metadata caching is usually obtainable and rolling out by default. Concurrent file handles per share are transferring from 2,000 immediately to 10,000, with a roadmap towards 30,000 to 50,000. Meaning fewer storage accounts to shard throughout when 9 AM hits.
  • Zonal placement and smarter alerts. Premium LRS now enables you to co-locate the share with its session hosts inside the identical availability zone, and new percentage-based metrics lastly make alert thresholds moveable throughout shares of any measurement.

In brief, the boring id and storage plumbing that propped up VDI for a decade is being collapsed into one thing you’ll be able to really run as a cloud-native service.

Let’s set the desk. VDI on Azure (whether or not you run Azure Digital Desktop, Citrix on Azure, or Omnissa Horizon) makes use of pooled session hosts. These hosts are deliberately stateless to allow them to be patched, scaled, and recycled with out ceremony. The person’s id is “Connie Cloud” immediately, and on a distinct host tomorrow.

FSLogix solves the continuity half of the puzzle. It packages the person’s profile and Workplace information containers (the profile container and the ODFC, the Workplace Information Folder Container) as VHDX recordsdata that get dynamically hooked up when Connie logs on and indifferent when she indicators out. These VHDX recordsdata have to stay someplace sturdy, quick, and reachable over SMB from any host within the pool.

That’s exactly what Azure Information delivers. It’s a totally managed SMB file share service that integrates cleanly with FSLogix profile containers and App Connect picture shops for AVD. The reference structure and sizing steerage are documented on Microsoft Be taught for anybody who desires the official map.

The historic friction was id. Till just lately, SMB authentication to Azure Information required both on-premises AD DS joined to the storage account or hybrid identities synced by means of Entra Join. That meant preserving area controllers (and the community paths to achieve them) alive purely to fulfill storage authentication. As of this 12 months, Azure Information helps pure Microsoft Entra ID identities for SMB Kerberos, which closes that loop.

Right here is the simplified movement Adam and Priyanka walked by means of throughout the demo.

  1. The person (an Entra-only account, no on-prem footprint) indicators into an Entra-joined AVD session host with single sign-on.
  2. The session host must mount the person’s FSLogix profile container from an Azure Information share.
  3. The host requests a Kerberos service ticket. As a result of the share has Microsoft Entra Kerberos authentication enabled, Entra ID points that ticket instantly, no on-prem KDC concerned.
  4. The SMB connection is established, the share-level RBAC function (for instance Storage File Information SMB Share Contributor) is checked, after which the listing and file ACLs (commonplace NTFS) are evaluated.
  5. FSLogix attaches the VHDX, the profile hundreds, Outlook is pleased, OneDrive is pleased, and Connie’s pinned taskbar reveals up precisely the best way she left it.

A number of particulars value submitting away:

  • Two layers of authorization. Share-level entry makes use of Azure RBAC roles. Merchandise-level entry makes use of NTFS ACLs. Each nonetheless apply, which is why your current permissions mannequin carries over cleanly.
  • B2B visitor assist. Vendor and contractor accounts that are available as friends in your tenant may be granted entry to file shares without having a synced shadow account.
  • Metadata caching is the unlock. VDI is metadata-heavy: listing enumerations, file opens, renames, and closes hammer the share at logon. Metadata caching reduces P50 latency on these operations by roughly 80 to 90% and roughly doubles metadata transaction throughput, which is what makes the upper concurrent deal with limits real looking. The total SMB efficiency reference on Microsoft Be taught lays out the knobs.
  • Zonal placement. Premium LRS enables you to pin the share to the identical availability zone as your session host pool, so the SMB visitors doesn’t bounce throughout zones.

The place does this present up in your operations assessment?

  • Retire orphan area controllers. Loads of outlets have a few DCs in Azure that exist solely so Azure Information can authenticate. Cloud-native Entra ID enables you to flip these off and shrink the id assault floor.
  • Less complicated M&A and vendor onboarding. Including a associate group or a brand new acquisition not requires forest trusts or a sync venture. Invite friends, assign them to a gaggle, grant the group entry to the share.
  • Fewer storage accounts and shares to handle. Larger concurrent deal with limits imply you’ll be able to consolidate customers that you simply beforehand needed to unfold throughout many accounts simply to dodge the two,000-handle ceiling. Much less sprawl, much less monitoring, fewer naming conventions to recollect.
  • Predictable logon occasions at scale. Metadata caching is the type of function you solely discover when it’s lacking. With it on by default, giant host swimming pools see flatter logon latency curves throughout the morning rush.
  • Operational consistency. Share-based metrics allow you to set a single rule like “alert at 10% remaining capability” and apply it cleanly to a 5 TiB share and a 100 TiB share with out bespoke thresholds.

In brief, the ROI dialog strikes from “how can we hold VDI operating” to “how a lot of the supporting forged can we delete.”

If you wish to kick the tires this week, here’s a sensible beginning path.

  1. Stock your VDI id story. Are you operating hybrid as a result of the apps want it, or as a result of Azure Information used to wish it? If it’s the second, you will have a candidate workload for cloud-only id.
  2. Spin up a pilot Premium SSD Azure Information share in the identical area (and ideally the identical availability zone) as a small AVD host pool.
  3. Allow Microsoft Entra Kerberos authentication on the storage account. The configuration is now in the usual Azure portal, no extra facet journeys to the fileperms portal.
  4. Assign Azure RBAC roles on the share degree (Storage File Information SMB Share Reader, Contributor, or Elevated Contributor as applicable) to your Entra teams.
  5. Set NTFS ACLs on the directories that may host FSLogix containers, and level FSLogix on the share’s UNC path.
  6. Check with a cloud-only person (no on-prem id in any respect) to substantiate the end-to-end movement.
  7. Activate metadata caching and the brand new metrics and set percentage-based alerts so you discover the boundaries earlier than your customers do.

Catch the complete Microsoft Azure Infra Summit 2026 session playlist right here: https://www.youtube.com/playlist?listing=PLjt5SKzX1iI8con7FJDB56G6hHqxGm7ki

Cheers!

Pierre Roman

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles