Hi,
I'm troubleshooting an issue with a user on Azure Virtual Desktop (AVD) and would appreciate some guidance.
Environment:
- Azure Virtual Desktop
- Pooled AVD host pools
- FSLogix profiles
- Microsoft 365 Apps
- Outlook + OneDrive
GPO issue:
- three users are affected.
- Other users logging into the same AVD host receive the GPO correctly.
- The affected user works correctly when using another host pool.
-
gpresult and gpupdate /force have been used.
- I compared the user's AD group membership with a working user.
- I added the affected user to an additional group as a test.
- The GPO applied successfully on one test, but when the test was repeated it did not apply.
- This makes the GPO application appear intermittent/inconsistent for this user.
Microsoft 365 authentication issue:
- users are repeatedly prompted to sign into Outlook and OneDrive.
- After logging out of AVD and logging back in, the user can be prompted again.
- I'm investigating whether this could be related to FSLogix profile/token persistence.
What I'm looking to establish:
- What would be the best way to troubleshoot why a user-specific GPO is applying inconsistently?
- Could AD replication, GPO processing/security filtering or token/group membership caching cause this behaviour?
- What FSLogix settings/logs should I check for Outlook/OneDrive authentication persistence?
- Could WAM/Entra authentication tokens or PRT be failing to persist between AVD sessions?
- Would testing with a fresh FSLogix profile be a good way to confirm whether the existing user profile is the cause?
Any advice on the best next steps or relevant logs/settings to check would be appreciated.