Skip to content

Commit 1d048fb

Browse files
author
Angela Fleischmann
authored
Merge pull request #8328 from MicrosoftDocs/main
Publish 08/26/2022 3:30 PM PT
2 parents cc78400 + bcfdadb commit 1d048fb

3 files changed

Lines changed: 22 additions & 10 deletions

File tree

memdocs/intune/apps/apps-win32-supersedence.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ keywords:
66
author: Erikre
77
ms.author: erikre
88
manager: dougeby
9-
ms.date: 08/18/2022
9+
ms.date: 08/25/2022
1010
ms.topic: how-to
1111
ms.service: microsoft-intune
1212
ms.subservice: apps
@@ -62,7 +62,7 @@ The following steps help you create a supersedence relationship between apps:
6262
6. Once this step is finalized, click **Review + save** > **Save**.
6363

6464
> [!IMPORTANT]
65-
> Superseding apps do not get automatic targeting. Each app must have explicit targeting to take effect. Superseding apps that are not targeted will be ignored by the agent. If the superseding app is targeted to a device with a superseded app, then the supersedence will take place regardless of whether the superseded app has targeting or not. For more information on Supersedence behavior, please refer to the matrix below. This behavior is in direct contrast to dependencies, which does not require targeting.
65+
> Superseding apps do not get automatic targeting. Each app must have explicit targeting to take effect. Superseding apps that are not targeted will be ignored by the agent. If the superseding app is targeted to a device with a superseded app, then the supersedence will take place regardless of whether the superseded app has targeting or not. For more information on Supersedence behavior, please refer to the matrix below. This behavior is in direct contrast to dependencies, which does not require targeting. Additionally, only apps that are targeted will show install statuses in Microsoft Endpoint Manager admin center.
6666
6767
## Supersedence behavior
6868

@@ -153,6 +153,7 @@ In the following Supersedence diagram, there are five nodes in total. Hence, fiv
153153
Additional supersedence limitations:
154154
- Azure Virtual Desktop multi-session only supports supersedence relationships with system-context (device-based) apps.
155155
- The Enrollment Status Page (ESP) is not supported with the supersedence public preview. ESP displays provisioning progress after a new device is enrolled, as well as when new users sign into the device. For the supersedence public preview, if an app has a supersedence relationship, it will not be enforced during ESP even if it is included as a selected app in an ESP policy. Additionally, apps that are involved in supersedence relationships will not be sent to the client device during ESP. However, the apps will be sent to the device after ESP completes, and the supersedence relationship will be respected.
156+
- Only apps that are targeted will show install statuses in Microsoft Endpoint Manager admin center.
156157

157158
## Next steps
158159

memdocs/intune/fundamentals/azure-virtual-desktop-multi-session.md

Lines changed: 14 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ ms.collection:
3333

3434
Azure Virtual Desktop multi-session with Microsoft Intune is now generally available.
3535

36-
You can now use Microsoft Intune to manage Windows 10 or Windows 11 Enterprise multi-session remote desktops in the Microsoft Endpoint Manager admin center just as you can manage a shared Windows 10 or Windows 11 client device. When managing such virtual machines (VMs), you'll be able to use both device-based and user configuration.
36+
You can now use Microsoft Intune to manage Windows 10 or Windows 11 Enterprise multi-session remote desktops in the Microsoft Endpoint Manager admin center just as you can manage a shared Windows 10 or Windows 11 client device. When managing such virtual machines (VMs), you'll be able to use both device-based configuration targeted to devices or user-based configuration targeted to users.
3737

3838
Windows 10 or Windows 11 Enterprise multi-session is a new Remote Desktop Session Host exclusive to [Azure Virtual Desktop](/azure/virtual-desktop/) on Azure. It provides the following benefits:
3939

@@ -45,7 +45,10 @@ You can manage **Windows 10** and **Windows 11 Enterprise multi-session** VMs cr
4545

4646
## Overview
4747

48-
Device configuration support in Microsoft Intune for Windows 10 or Windows 11 Enterprise multi-session is Generally Available (GA). This means [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, multi-session configurations can be targeted to devices or device groups.
48+
Device configuration support in Microsoft Intune for Windows 10 or Windows 11 Enterprise multi-session is Generally Available (GA). This means [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs when assigned to device groups.
49+
50+
> [!NOTE]
51+
> Device-based configuration cannot be assigned to users and user-based configuration cannot be assigned to devices. It will be reported as **Error** or **Not applicable**.
4952
5053
User configuration support in Microsoft Intune for Windows 11 multi-session VMs is in public preview. With this you'll be able to:
5154

@@ -70,7 +73,7 @@ This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs, whi
7073
- Configured with [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy), set to use Device credentials, and set to automatically enroll devices that are Hybrid Azure AD-joined.
7174
- [Configuration Manager co-management](/configmgr/comanage/overview).
7275
- Azure AD-joined and enrolled in Microsoft Intune by enabling [Enroll the VM with Intune](/azure/virtual-desktop/deploy-azure-ad-joined-vm#deploy-azure-ad-joined-vms) in the Azure portal.
73-
- Licensing: The appropriate Microsoft Intune license is required if a user or device benefits directly or indirectly from the Microsoft Intune service, including access to the Microsoft Intune service through a Microsoft API. For more information, see Microsoft Intune licensing.
76+
- Licensing: The appropriate Azure Virtual Desktop and Microsoft Intune license is required if a user or device benefits directly or indirectly from the Microsoft Intune service, including access to the Microsoft Intune service through a Microsoft API. For more information, go to [Microsoft Intune licensing](licenses.md).
7477

7578
> [!NOTE]
7679
> If you're joining session hosts to Azure Active Directory Domain Services, you can't manage them using Intune.
@@ -88,9 +91,9 @@ To configure configuration policies for Windows 10 or Windows 11 Enterprise mult
8891

8992
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, except for the following templates:
9093

91-
- [Trusted certificate](../protect/certificates-trusted-root.md#create-trusted-certificate-profiles) - Device (machine) only
92-
- [SCEP certificate](../protect/certificates-profile-scep.md#create-a-scep-certificate-profile) - Device (machine) only
93-
- [PKCS certificate](../protect/certificates-pfx-configure.md#create-a-pkcs-certificate-profile) - Device (machine) only
94+
- [Trusted certificate](../protect/certificates-trusted-root.md#create-trusted-certificate-profiles) - Device (machine) when targeting devices and User when targeting users
95+
- [SCEP certificate](../protect/certificates-profile-scep.md#create-a-scep-certificate-profile) - Device (machine) when targeting devices and User when targeting users
96+
- [PKCS certificate](../protect/certificates-pfx-configure.md#create-a-pkcs-certificate-profile) - Device (machine) when targeting devices and User when targeting users
9497
- [VPN](../configuration/vpn-settings-configure.md#create-the-profile) - Device Tunnel only
9598

9699
Microsoft Intune won't deliver unsupported templates to multi-session devices, and those policies appear as *Not applicable* in reports.
@@ -160,14 +163,17 @@ All other policies report as **Not applicable**.
160163
> [Conditional Access for Exchange on-premises](../protect/conditional-access-exchange-create.md) isn't supported for Windows 10 or Windows 11 Enterprise multi-session VMs.
161164
162165
> [!NOTE]
163-
> Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
166+
> Configuration and compliance policies for BitLocker, Secure Boot, and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
164167
165168
## Endpoint security
166169

167-
You can configure profiles under Endpoint security for multi-session VMs by selecting Platform Windows 10, Windows 11, and Windows Server.
170+
You can configure profiles under Endpoint security for multi-session VMs by selecting Platform Windows 10, Windows 11, and Windows Server. If that Platform is not available, the profile is not supported on multi-session VMs.
168171

169172
For more information, see [Manage device security with endpoint security policies in Microsoft Intune](../protect/endpoint-security-policy.md)
170173

174+
> [!NOTE]
175+
> Tamper protection is not supported on Azure Virtual Desktop VMs today. This functionality will be enabled in a future release.
176+
171177
## Application deployment
172178

173179
All Windows 10 or Windows 11 apps can be deployed to Windows 10 or Windows 11 Enterprise multi-session with the following restrictions:

memdocs/intune/includes/mdm-supported-devices.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,11 @@ ms.localizationpriority: high
1414
- Apple iPadOS 13.0 and later
1515
- macOS 10.15 and later
1616

17+
> [!NOTE]
18+
> Intune requires iOS 13.x or later for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies.
19+
>
20+
> For Intune app protection policies and app configuration delivered through Managed apps App configuration policies, Intune requires iOS 14.x or later.
21+
1722
### Google
1823

1924
- Android 8.0 and later (including Samsung KNOX Standard 2.4 and higher: [requirements](https://www.samsungknox.com/en/knox-platform/supported-devices/2.4+))

0 commit comments

Comments
 (0)