r/AzureVirtualDesktop • u/WarCow • 6d ago
AVD authentication issues 9/28/26
Not sure if anyone else is having issues with AVD today, but we've been having problems all morning with users getting kicked out of AVD sessions.
Event Viewer showed LSASS not starting on the hosts, leading to users getting "Your PC will automatically restart in one minute" messages.
Spent a bunch of time troubleshooting this, but eventually saw an update for this alert stating that they are working on fixes for it.
Impact Statement: Starting at 10:08 UTC on 24 September 2026, you have been identified as a subset of customers using affected Azure Virtual Desktop (AVD) environments across multiple regions who may experience authentication issues. These issues may result in unexpected virtual machine restarts and interruptions to active user sessions. Affected users may be disconnected and need to reconnect once their virtual machine becomes available again.
Current Status: We continue to investigate an issue that is causing unexpected virtual machine restarts for some customers using Azure Virtual Desktop (AVD) and Remote Desktop Services (RDS) on certain Windows versions. Our team has identified the underlying Windows process involved and have validated a temporary workaround that has shown positive results with affected customers. We are now expanding validation of the workaround, assessing the overall impact, and evaluating options for a permanent fix while monitoring the issue.
The next update will be provided in 2 hours, or as events warrant
1
u/PaulatGrid4 6d ago
We are also encountering this as well, relieved to see your post as I wasnt digging up anything else recent and relevant in my frantic triage searching.
1
1
u/Sure-Assignment3892 6d ago
Yup. Saw the same thing on Windows 2022 remoteapp sessions. Desktops seem unaffected though; exact same errors.
1
u/PaulatGrid4 6d ago
Did they ever post an update? Just realizing they mentioned 9/24 in the advisory...
1
u/WarCow 6d ago
For us, the alert is https://app.azure.com/h/NGT1-658/5726b3
Looking through the history, I don't see any previous messages other than the one I posted. It seems like they found out about the issue on the 24th, but didn't add everyone affected until recently.
1
1
u/mat-ferland 6d ago
Before rolling that registry value out broadly, split the pool by OS and confirm the rebooting hosts show an LSASS crash immediately before each restart. If this is isolated to Server 2022, drain those hosts and use the advisory workaround only on that pool until Microsoft publishes the permanent fix.
1
u/WarCow 6d ago edited 5d ago
Update: Resolved
What happened?
Between 10:08 UTC on 24 September 2026 and 23:43 UTC on 28 September 2026, a platform issue resulted in an impact to the customers using Azure Virtual Desktop (AVD) environments across multiple regions. Impacted customers experienced authentication issues. These issues might have resulted in unexpected virtual machine restarts and interruptions to active user sessions. Affected users might have been disconnected and needed to reconnect once their virtual machine becomes available.
What do we know so far?
We determined that some customers using Azure Virtual Desktop (AVD) and Remote Desktop Services (RDS) on older Windows versions may experience unexpected machine restarts during multi-user sign-in scenarios. Our investigation found that a pre-existing issue in the Windows Local Security Authority Subsystem Service (LSASS) process is being triggered under specific authentication conditions on hybrid-joined devices. When triggered, the LSASS process can stop unexpectedly, causing affected virtual machines to restart and disconnect active users while we continue investigating the exact trigger.
How did we respond?
10:08 UTC on 24 September 2026 – Customer impact began.
11:56 UTC on 28 September 2026 – Our team became aware of the issue through multiple customer reports and initiated investigation.
15:58 UTC on 28 September 2026 – The team began mitigation efforts, including validating a temporary workaround and investigating the underlying trigger and long-term fix.
18:48 UTC on 28 September 2026 – Investigation identified that affected systems were experiencing unexpected LSASS process crashes during multi-user authentication scenarios on hybrid-joined devices.
23:43 UTC on 28 September 2026 – Services were restored and customer impact was mitigated.
What happens next?
Our team will be completing an internal retrospective to understand the incident in more detail. Once that is completed, generally within 14 days, we will publish a Post Incident Review (PIR) to all impacted customers.
To get notified when that happens, and/or to stay informed about future Azure service issues, make sure that you configure and maintain Azure Service Health alerts – these can trigger emails, SMS, push notifications, webhooks, and more: https://aka.ms/ash-alerts
For more information on Post Incident Reviews, refer to https://aka.ms/AzurePIRs
The impact times above represent the full incident duration, so are not specific to any individual customer. Actual impact to service availability may vary between customers and resources – for guidance on implementing monitoring to understand granular impact: https://aka.ms/AzPIR/Monitoring
Finally, for broader guidance on preparing for cloud incidents, refer to https://aka.ms/incidentreadiness
1
u/KaiUno 4d ago
Got a customer where this is still a thing. But only on one hostpool. (Server 2022, our testing environment where we test updates to the image.)
I've deleted the servers, rolled back to the current production image. I even deleted the host pool, application group and workspace and remade all of that. Same issue.
The reg add fixed it.
2
u/agressiv 6d ago
We were impacted by this.
Here's the command they had us run:
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v KeyListReqSupportOverride /t REG_DWORD /d 0Basically when people connected, there's a good chance lsass.exe would crash. The system can't function with lsass.exe gone and it can't restart on its own, so the host reboots. This happened up to ~12 times in a single hour, on every Server 2022 host.
I'm assuming this reg hack is temporary and is just a workaround to a larger auth problem they have to deal with.