A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
The error indicates that the PowerShell DSC VM extension on the session host VM cannot download its configuration package from the specified HTTPS URL. This is a connectivity issue from the VM to the storage endpoint, not an inbound/RDP/NSG-3389 issue.
Use these steps to troubleshoot and resolve:
- Verify the extension failure details on the VM
- From Azure CLI, list the extensions and confirm the DSC extension is in a failed state:
az vm extension list --resource-group <rg-name> --vm-name <vm-name> -o table - On the VM, check the DSC extension status and logs:
- Status file:
C:\Packages\Plugins\Microsoft.Powershell.DSC\<version>\Status\0.status - Logs:
C:\WindowsAzure\Logs\Plugins\Microsoft.Powershell.DSC\<version>
- Status file:
- The detailed error in these files will confirm that the failure is during download of the configuration ZIP from the blob URL.
- From Azure CLI, list the extensions and confirm the DSC extension is in a failed state:
- Confirm outbound connectivity from the VM
- The DSC extension requires the VM to reach:
- Azure control plane (for extension coordination), and
- The storage endpoint hosting the configuration package (the
wvdportalstorageblob.blob.core.windows.netURL in the error).
- Ensure there is no outbound-deny NSG rule or firewall rule blocking HTTPS (TCP 443) from the VM to the internet or to Azure Storage endpoints.
- If using a custom DNS, proxy, or firewall appliance, verify that:
- The VM can resolve
*.blob.core.windows.net. - HTTPS to that endpoint is allowed.
- The VM can resolve
- The DSC extension requires the VM to reach:
- Validate NSG and any other network security
- Check the subnet and NIC NSGs:
- Confirm there is an outbound rule allowing TCP 443 to internet/AzureStorage.
- Ensure there is no higher-priority deny rule that overrides the allow rule.
- If the environment uses Azure Firewall or another NVA, confirm rules allow outbound HTTPS to
blob.core.windows.net.
- Check the subnet and NIC NSGs:
- Check the configuration package URL and SAS
- The DSC extension downloads a ZIP from a URL (often with a SAS token) defined in its settings.
- Common issues:
- SAS token expired.
- URL typo or container/blob deleted or moved.
- Regenerate the SAS URL for the configuration package, update the DSC extension settings (or the AVD template/ARM/Bicep that deploys it), and redeploy the extension.
- Retry the extension after fixing connectivity
- After confirming outbound connectivity and a valid configuration URL:
- Remove the failed DSC extension instance.
- Reapply the AVD deployment or re-add the
Microsoft.Powershell.DSCextension with corrected settings.
- Monitor status again via:
and by checking the extension status/log paths above.Get-AzVM -ResourceGroupName <rg-name> -Name <vm-name> -Status
- After confirming outbound connectivity and a valid configuration URL:
- If the VM was created from an image with old extensions
- If the session host VM was created from a generalized/specialized image that already had extensions on it, stale extension binaries and status files can cause inconsistent behavior.
- In such cases, remove existing extensions from the source VM before imaging, or remove/reinstall the DSC extension on the new VM so it starts clean.
If, after ensuring outbound HTTPS to blob.core.windows.net and fixing the configuration URL/SAS, the DSC extension still fails, collect the logs from C:\WindowsAzure\Logs\Plugins\Microsoft.Powershell.DSC\<version> and the status file under C:\Packages\Plugins\Microsoft.Powershell.DSC\<version>\Status and use them to open an Azure support case.
References: