Azure AD Hybrid Identity - Cloud-Only Entra ID User Can't Log Into AVD

isuru wimalasiri 0 Reputation points
2025-03-13T12:58:07.3766667+00:00

Hi,
I'm setting up Azure Virtual Desktop (AVD) with Hybrid Identity using Azure AD Connect on my on-prem Active Directory (AD). Everything works fine for on-prem AD users who are synced to Entra ID (formerly Azure AD). They can log in without issues.

However, I have an Entra ID-only user (not in on-prem AD), and they cannot log into AVD. When they try, they get this error:

"We couldn't connect to the gateway because of an error. If this keeps happening, ask your admin or tech support for help."

Here’s my setup:

✅ On-Prem AD + Azure AD Connect for hybrid identity.

✅ AVD is set up and working for synced users.

✅ Cloud-only users exist in Entra ID but are not in on-prem AD.

✅ Authentication method: Password Hash Sync (PHS) in Azure AD Connect.

✅ Cloud-only users have valid Microsoft 365 licenses assigned.

Could this be a policy restriction, licensing issue, or a limitation with AVD and cloud-only users? Do cloud-only users need to be in a specific security group for AVD access?

Any help would be greatly appreciated!

Thanks in advance!

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,708 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.