AVD – User-specific GPO intermittently not applying + Outlook/OneDrive credentials not persisting

Cleon Russell 110 Reputation points
2026-08-12T18:48:41.4066667+00:00

Hi,

I'm troubleshooting an issue with a user on Azure Virtual Desktop (AVD) and would appreciate some guidance.

Environment:

  • Azure Virtual Desktop
  • Pooled AVD host pools
  • FSLogix profiles
  • Microsoft 365 Apps
  • Outlook + OneDrive

GPO issue:

  • three users are affected.
  • Other users logging into the same AVD host receive the GPO correctly.
  • The affected user works correctly when using another host pool.
  • gpresult and gpupdate /force have been used.
  • I compared the user's AD group membership with a working user.
  • I added the affected user to an additional group as a test.
  • The GPO applied successfully on one test, but when the test was repeated it did not apply.
  • This makes the GPO application appear intermittent/inconsistent for this user.

Microsoft 365 authentication issue:

  • users are repeatedly prompted to sign into Outlook and OneDrive.
  • After logging out of AVD and logging back in, the user can be prompted again.
  • I'm investigating whether this could be related to FSLogix profile/token persistence.

What I'm looking to establish:

  1. What would be the best way to troubleshoot why a user-specific GPO is applying inconsistently?
  2. Could AD replication, GPO processing/security filtering or token/group membership caching cause this behaviour?
  3. What FSLogix settings/logs should I check for Outlook/OneDrive authentication persistence?
  4. Could WAM/Entra authentication tokens or PRT be failing to persist between AVD sessions?
  5. Would testing with a fresh FSLogix profile be a good way to confirm whether the existing user profile is the cause?

Any advice on the best next steps or relevant logs/settings to check would be appreciated.

Azure Virtual Desktop
Azure Virtual Desktop

A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.


1 answer

Sort by: Most helpful
  1. Cleon Russell 110 Reputation points
    2026-08-13T20:18:04.9733333+00:00

    Tested with a newly created test account using the same group memberships as an affected user. GPOs applied successfully. However, after logging out and signing back in, Outlook prompted for credentials again and OneDrive did not automatically sign in. The same behaviour was reproduced when testing the account on another AVD desktop host pool FSLogix profile mounting has also been checked and completes without errors. This suggests the Microsoft 365 authentication issue is not isolated to an existing user's FSLogix profile and may be related to AVD SSO/Entra device authentication.

    I don't believe. SSO is enabled on the Host Pool, so users would be prompted?

    https://learn.microsoft.com/en-us/azure/virtual-desktop/configure-single-sign-on?utm_source=chatgpt.com&tabs=portal

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.