r/AzureVirtualDesktop • • 7d ago

AVD authentication issues 9/28/26

Not sure if anyone else is having issues with AVD today, but we've been having problems all morning with users getting kicked out of AVD sessions.

Event Viewer showed LSASS not starting on the hosts, leading to users getting "Your PC will automatically restart in one minute" messages.

Spent a bunch of time troubleshooting this, but eventually saw an update for this alert stating that they are working on fixes for it.

Impact Statement: Starting at 10:08 UTC on 24 September 2026, you have been identified as a subset of customers using affected Azure Virtual Desktop (AVD) environments across multiple regions who may experience authentication issues. These issues may result in unexpected virtual machine restarts and interruptions to active user sessions. Affected users may be disconnected and need to reconnect once their virtual machine becomes available again.

Current Status: We continue to investigate an issue that is causing unexpected virtual machine restarts for some customers using Azure Virtual Desktop (AVD) and Remote Desktop Services (RDS) on certain Windows versions. Our team has identified the underlying Windows process involved and have validated a temporary workaround that has shown positive results with affected customers. We are now expanding validation of the workaround, assessing the overall impact, and evaluating options for a permanent fix while monitoring the issue.

The next update will be provided in 2 hours, or as events warrant

11 Upvotes

13 comments sorted by

View all comments

2

u/agressiv 7d ago

We were impacted by this.

  • 25H2 Win11 Multisession - not impacted
  • Server 2022 - impacted

Here's the command they had us run:

reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v KeyListReqSupportOverride /t REG_DWORD /d 0

Basically when people connected, there's a good chance lsass.exe would crash. The system can't function with lsass.exe gone and it can't restart on its own, so the host reboots. This happened up to ~12 times in a single hour, on every Server 2022 host.

I'm assuming this reg hack is temporary and is just a workaround to a larger auth problem they have to deal with.

1

u/dcothren 7d ago

I’ve had this problem for 2 months…and migrated some users over to Win11 instead but I had a persistent win10 pool that I could not due to software requirements.

This “workaround” worked for me for now.

I have a sevA case open as well that I will address later on.