Guide: Fix FS Logix Profile fail to attach for Local Admins and un-synched domain admin accounts

Further to the information presented here: Unable to log in to session host VMs as local administrator – Nerdio Help Center

We found that it would be useful to add the local admin and domain admin accounts, which are not synched using Azure AD Sync into the local exclude groups - we don't want our on-premise domain admin account synched to Azure AD, and teh Local Admin account never will be as it belongs to the individual computer along.

 

We chose to modify the group policy that applies computer settings, so that it will put both of those accounts into the exclude group, that way we can more easily administer the servers.

  1. Open Group Policy Management Console
  2. Create a new GPO or edit an existing one
  3. Go to Computer Configuration --> Policies --->Windows Settings-->Security Settings-->Restricted Groups
  4. Right click over Restricted Group and select Add Group
  5. Type the Group you you want to add or remove members, we copied the name of the group from a host server:  FSLogix Profile Exclude List
  6. In the Members of this Group, chose Add, we added our domain\domainadmin account using the browse button, and entered LocalAdmin manually (without domain\)

I hope someone finds this useful, let me know.

A

0

Comments (2 comments)

Avatar
Carl Long

Matt!  Thank you for the kind words.  We appreciate the feedback and will continue to strive for excellent documentation.

 

Have a great weekend!

0
Avatar
Matt Estell

holy cow, thank you!  After doing a test restore of a session host server, I found I couldn't login to it locally.

I created an account so I could express my gratitude.

-Matt

Please sign in to leave a comment.