High-Level - Choosing Entra Domain Services Over On-Prem AD for Azure Virtual Desktop

Prabhjot Singh 245 Reputation points
2025-04-18T06:28:29.95+00:00

Why is Entra Domain Services (Azure AD DS) required instead of on-premises Active Directory for Azure Virtual Desktop in a cloud-only environment, and what are the key functional differences between them in this scenario?

Another scenario - We already have an on-premises Active Directory in our environment and are currently managing Azure Virtual Desktop (AVD) operations through it. However, we would like to understand the requirements and implications of using Microsoft Entra Domain Services (Azure AD DS) instead.

Specifically:

  1. When is Azure AD DS necessary in an AVD setup?
  2. What are the differences in functionality between using on-prem AD vs. Azure AD DS related to Azure virtual desktop?
  3. Are there any limitations or considerations when choosing Azure AD DS for domain-joining AVD session hosts in a cloud-only or hybrid environment?
Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,770 questions
0 comments No comments
{count} votes

Accepted answer
  1. Nikhil Duserla 6,960 Reputation points Microsoft External Staff Moderator
    2025-04-18T06:58:06.9833333+00:00

    Hi @Prabhjot Singh,

    Entra Domain Services (Azure AD DS) plays a crucial role in Azure Virtual Desktop (AVD) deployments within cloud-only environments, as it provides managed domain services without the need for on-premises infrastructure.

    Unlike traditional Active Directory which is designed for physical data centers and requires direct infrastructure management Azure AD DS offers cloud-native capabilities and integrates seamlessly with other Azure services.

    When it comes to user management, Active Directory users are synced from on-premises devices to Microsoft Entra ID using tools like AD Sync or Entra Connect. In the case of Azure Active Directory, users can directly access AVD by being added to the appropriate assignments.

    The deployment and access process for Microsoft Entra-joined virtual machines in Azure Virtual Desktop simplifies infrastructure requirements. These VMs eliminate the need for a direct connection to an on-premises or virtualized Active Directory Domain Controller (DC), or even the need to deploy Microsoft Entra Domain Services. In some scenarios, a domain controller may not be needed at all, making the overall setup and management more straightforward.

    Azure Active Directory- Offers effortless scalability to support organizational growth, without the need for physical infrastructure expansion. Delivers comparable capabilities—such as domain join and group policy support—but is tailored for modern, cloud-centric applications and services. Handled entirely by Microsoft, easing IT workloads and enabling teams to concentrate on higher-value strategic tasks. Fully cloud-based, removing the dependency on any physical, on-premises hardware.

    On-prem Active directory- Relies on on-site servers and infrastructure, usually hosted in the organization's data center. Demands considerable administrative effort, covering hardware upkeep, software patching, and ongoing security management. Enables traditional domain to join and group policy management, which are key for controlling user access and enforcing security settings in Windows environments. Scaling involves provisioning extra hardware and careful infrastructure planning, often leading to increased time and costs.

    Please look at for more detailed information and also limitations for Microsoft Entra joined session hosts in Azure Virtual Desktop-https://learn.microsoft.com/en-us/azure/virtual-desktop/azure-ad-joined-session-hosts

    If you have any further queries, do let us know.

    If you found this informative, please consider accepting an answer as a token of appreciation. And don't forget to give it a thumbs up 👍 if it was helpful.

    User's image

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.