You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/azure-virtual-desktop-multi-session.md
+27-28Lines changed: 27 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -45,15 +45,15 @@ You can manage **Windows 10** and **Windows 11 Enterprise multi-session** VMs cr
45
45
46
46
## Overview
47
47
48
-
Microsoft Intune only supports managing Windows 10 or Windows 11 Enterprise multi-session with device configurations. This means only [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, all multi-session configurations must be targeted to devices or device groups. User scope policies are not supported at this time.
48
+
Microsoft Intune only supports managing Windows 10 or Windows 11 Enterprise multi-session with device configurations. This means only [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, all multi-session configurations must be targeted to devices or device groups. User scope policies aren't supported at this time.
49
49
50
50
## Prerequisites
51
51
52
-
This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs which are:
52
+
This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs, which are:
53
53
54
54
- Running Windows 10 multi-session, version 1903 or later, or running Windows 11 multi-session.
55
55
- Set up as remote desktops in pooled host pools that have been deployed through Azure Resource Manager.
56
-
- Running a Azure Virtual Desktop agent version of 1.0.2944.1400 or later.
56
+
- Running an Azure Virtual Desktop agent version of 1.0.2944.1400 or later.
57
57
-[Hybrid Azure AD-joined](/azure/active-directory/devices/hybrid-azuread-join-plan) and enrolled in Microsoft Intune using one of the following methods:
58
58
- Configured with [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy), set to use Device credentials, and set to automatically enroll devices that are Hybrid Azure AD-joined.
@@ -64,13 +64,13 @@ This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs whic
64
64
65
65
See [What is Azure Virtual Desktop?](/azure/virtual-desktop/overview#requirements) for more information about Azure Virtual Desktop licensing requirements.
66
66
67
-
Windows 10 or Windows 11 Enterprise multi-session VMs are treated as a separate OS edition and some Windows 10 or Windows 11 Enterprise configurations won’t be supported for this edition. Using Microsoft Intune does not depend on or interfere with Azure Virtual Desktop management of the same VM.
67
+
Windows 10 or Windows 11 Enterprise multi-session VMs are treated as a separate OS edition and some Windows 10 or Windows 11 Enterprise configurations won’t be supported for this edition. Using Microsoft Intune doesn't depend on or interfere with Azure Virtual Desktop management of the same VM.
68
68
69
69
## Create the device configuration profile
70
70
71
71
To configure configuration policies for Windows 10 or Windows 11 Enterprise multi-session VMs, you'll need to use the [Settings catalog](../configuration/settings-catalog.md) in the Microsoft Endpoint Manager admin center.
72
72
73
-
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, with the exception of the following templates:
73
+
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, except for the following templates:
74
74
75
75
-[Trusted certificate](../protect/certificates-trusted-root.md#create-trusted-certificate-profiles) - Device (machine) only
76
76
-[SCEP certificate](../protect/certificates-profile-scep.md#create-a-scep-certificate-profile) - Device (machine) only
@@ -104,8 +104,8 @@ Microsoft Intune won't deliver unsupported templates to multi-session devices, a
104
104
105
105
Windows 10 or Windows 11 Administrative Templates are supported for Windows 10 or Windows 11 Enterprise multi-session via the Settings catalog with some limitations:
106
106
107
-
- ADMX-backed policies are supported. Some policies are not yet available in the Settings catalog.
108
-
- ADMX-ingested policies are supported, including Office and Microsoft Edge settings available in Office administrative template files and Microsoft Edge administrative template files. For a complete list of ADMX-ingested policy categories, see [Win32 and Desktop Bridge app policy configuration](/windows/client-management/mdm/win32-and-centennial-app-policy-configuration#overview). Some ADMX ingested settings will not be applicable to Windows 10 or Windows 11 Enterprise multi-session.
107
+
- ADMX-backed policies are supported. Some policies aren't yet available in the Settings catalog.
108
+
- ADMX-ingested policies are supported, including Office and Microsoft Edge settings available in Office administrative template files and Microsoft Edge administrative template files. For a complete list of ADMX-ingested policy categories, see [Win32 and Desktop Bridge app policy configuration](/windows/client-management/mdm/win32-and-centennial-app-policy-configuration#overview). Some ADMX ingested settings won't be applicable to Windows 10 or Windows 11 Enterprise multi-session.
109
109
110
110
## Compliance and Conditional access
111
111
@@ -139,6 +139,9 @@ All other policies report as **Not applicable**.
139
139
> [!NOTE]
140
140
> [Conditional Access for Exchange on-premises](../protect/conditional-access-exchange-create.md) isn't supported for Windows 10 or Windows 11 Enterprise multi-session VMs.
141
141
142
+
> [!NOTE]
143
+
> Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
144
+
142
145
## Endpoint security
143
146
144
147
You can configure profiles under Endpoint security for multi-session VMs by selecting Platform Windows 10, Windows 11, and Windows Server.
@@ -149,10 +152,10 @@ For more information, see [Manage device security with endpoint security policie
149
152
150
153
All Windows 10 or Windows 11 apps can be deployed to Windows 10 or Windows 11 Enterprise multi-session with the following restrictions:
151
154
152
-
- All apps must be configured to install in the system/device context and be targeted to devices. Web apps are always applied in the user context by default so they will not apply to multi-session VMs.
153
-
- All apps must be configured with **Required** or **Uninstall** app assignment intent. The **Available apps** deployment intent is not supported on multi-session VMs.
154
-
- If a Win32 app configured to install in the system context has dependencies or supersedence relationship on any apps configured to install in the user context, the app will not be installed. To apply to a Windows 10 or Windows 11 Enterprise multi-session VM, create a separate instance of the system context app or make sure all app dependencies are configured to install in the system context.
155
-
- Azure Virtual Desktop RemoteApp and MSIX app attach are not currently supported in Microsoft Intune.
155
+
- All apps must be configured to install in the system/device context and be targeted to devices. Web apps are always applied in the user context by default so they won't apply to multi-session VMs.
156
+
- All apps must be configured with **Required** or **Uninstall** app assignment intent. The **Available apps** deployment intent isn't supported on multi-session VMs.
157
+
- If a Win32 app configured to install in the system context has dependencies or supersedence relationship on any apps configured to install in the user context, the app won't be installed. To apply to a Windows 10 or Windows 11 Enterprise multi-session VM, create a separate instance of the system context app or make sure all app dependencies are configured to install in the system context.
158
+
- Azure Virtual Desktop RemoteApp and MSIX app attach aren't currently supported in Microsoft Intune.
156
159
157
160
## Script deployment
158
161
@@ -175,7 +178,7 @@ The following settings are available in the catalog, with the links opening the
175
178
176
179
## Remote actions
177
180
178
-
The following Windows 10 or Windows 11 desktop device remote actions are not supported and will be grayed out in the UI and disabled in Graph for Windows 10 or Windows 11 Enterprise multi-session VMs:
181
+
The following Windows 10 or Windows 11 desktop device remote actions aren't supported and will be grayed out in the UI and disabled in Graph for Windows 10 or Windows 11 Enterprise multi-session VMs:
179
182
180
183
- Autopilot reset
181
184
- BitLocker key rotation
@@ -186,24 +189,20 @@ The following Windows 10 or Windows 11 desktop device remote actions are not sup
186
189
187
190
## Retirement
188
191
189
-
Deleting VMs from Azure will leave orphaned device records in the Microsoft Endpoint Manager admin center. They will be automatically cleaned up according to the cleanup rules configured for the tenant.
192
+
Deleting VMs from Azure will leave orphaned device records in the Microsoft Endpoint Manager admin center. They'll be automatically cleaned up according to the cleanup rules configured for the tenant.
190
193
191
194
## Security baselines
192
195
193
-
Security baselines are not available for Windows 10 or Windows 11 Enterprise multi-session at this time. We recommend that you review the [Available security baselines](../protect/security-baselines.md) and configure the recommended policies and values in the [Settings catalog](../configuration/settings-catalog.md).
196
+
Security baselines aren't available for Windows 10 or Windows 11 Enterprise multi-session at this time. We recommend that you review the [Available security baselines](../protect/security-baselines.md) and configure the recommended policies and values in the [Settings catalog](../configuration/settings-catalog.md).
194
197
195
-
## Additional configurations which are not supported on Windows 10 or Windows 11 Enterprise multi-session VMs
198
+
## Additional configurations that aren't supported on Windows 10 or Windows 11 Enterprise multi-session VMs
196
199
197
200
Out of Box Experience (OOBE) enrollment isn't supported for Window 10 or Windows 11 Enterprise multi-session. This restriction means that:
198
201
199
202
- Windows Autopilot and Commercial OOBE aren't supported.
200
203
- Enrollment status page isn’t supported.
201
204
202
-
Windows 10 or Windows 11 Enterprise multi-session managed by Microsoft Intune is not currently supported for China.
203
-
204
-
## Additional Limitations
205
-
206
-
Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
205
+
Windows 10 or Windows 11 Enterprise multi-session managed by Microsoft Intune isn't currently supported for China Sovereign Cloud.
207
206
## Troubleshooting
208
207
209
208
The following sections provide troubleshooting guidance for common issues.
@@ -212,19 +211,19 @@ The following sections provide troubleshooting guidance for common issues.
|Enrollment of hybrid Azure AD joined virtual machine fails|<ul><li>Auto-enrollment is configured to use user credentials. Windows 10 or Windows 11 Enterprise multi-session virtual machines must be enrolled using device credentials.<li>The Azure Virtual Desktop agent you’re using must be version 2944.1400 or later.<li>You have more than one MDM provider, which is not supported.<li>Windows 10 or Windows 11 Enterprise multi-session VM is configured outside of a host pool. Microsoft Intune only supports VMs provisioned as part of a host pool.<li>The Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
216
-
|Enrollment of Azure AD joined virtual machine fails|<ul><li>The Azure Virtual Desktop agent you’re using is not updated. The agent must be version 2944.1400 or above.<li>Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
214
+
|Enrollment of hybrid Azure AD joined virtual machine fails|<ul><li>Auto-enrollment is configured to use user credentials. Windows 10 or Windows 11 Enterprise multi-session virtual machines must be enrolled using device credentials.<li>The Azure Virtual Desktop agent you’re using must be version 2944.1400 or later.<li>You've more than one MDM provider, which isn't supported.<li>Windows 10 or Windows 11 Enterprise multi-session VM is configured outside of a host pool. Microsoft Intune only supports VMs provisioned as part of a host pool.<li>The Azure Virtual Desktop host pool wasn't created through the Azure Resource Manager template.|
215
+
|Enrollment of Azure AD joined virtual machine fails|<ul><li>The Azure Virtual Desktop agent you’re using isn't updated. The agent must be version 2944.1400 or above.<li>Azure Virtual Desktop host pool wasn't created through the Azure Resource Manager template.|
217
216
218
217
### Configuration issues
219
218
220
219
|Issue|Detail|
221
220
|--------|------------------------------|
222
-
|Settings catalog policy fails|Confirm the VM is enrolled using device credentials. Enrollment with user credentials is not currently supported for Windows 10 or Windows 11 Enterprise multi-session.|
223
-
|Configuration policy did not apply|Templates (with the exception of Certificates) are not supported on Windows 10 or Windows 11 Enterprise multi-session. All policies must be created via the settings catalog.|
224
-
Configuration policy reports as Not applicable|Some policies are not applicable to Azure Virtual Desktop VMs.|
225
-
|Microsoft Edge/Microsoft Office ADMX policy does not show up when I apply the filter for Windows 10 or Windows 11 Enterprise multi-session edition|Applicability for these settings is not based on the Windows version or edition but on whether those apps have been installed on the device. To add these settings to your policy, you may have to remove any filters applied in the settings picker.|
226
-
|App configured to install in system context did not apply|Confirm the app does not have a dependency or supersedence relationship on any apps configured to install in user context. User context apps are not currently supported on Windows 10 or Windows 11 Enterprise multi-session.|
227
-
|Update rings for Windows 10 and later policy did not apply|Windows Update for Business policies are not currently supported.|
221
+
|Settings catalog policy fails|Confirm the VM is enrolled using device credentials. Enrollment with user credentials isn't currently supported for Windows 10 or Windows 11 Enterprise multi-session.|
222
+
|Configuration policy didn't apply|Templates (except for Certificates) aren't supported on Windows 10 or Windows 11 Enterprise multi-session. All policies must be created via the settings catalog.|
223
+
Configuration policy reports as Not applicable|Some policies aren't applicable to Azure Virtual Desktop VMs.|
224
+
|Microsoft Edge/Microsoft Office ADMX policy doesn't show up when I apply the filter for Windows 10 or Windows 11 Enterprise multi-session edition|Applicability for these settings isn't based on the Windows version or edition but on whether those apps have been installed on the device. To add these settings to your policy, you may have to remove any filters applied in the settings picker.|
225
+
|App configured to install in system context didn't apply|Confirm the app doesn't have a dependency or supersedence relationship on any apps configured to install in user context. User context apps aren't currently supported on Windows 10 or Windows 11 Enterprise multi-session.|
226
+
|Update rings for Windows 10 and later policy didn't apply|Windows Update for Business policies aren't currently supported.|
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/azure-virtual-desktop.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -65,6 +65,9 @@ Also, the following profiles aren't currently supported:
65
65
66
66
Make sure that the [RemoteDesktopServices/AllowUsersToConnectRemotely policy](/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-allowuserstoconnectremotely) isn't disabled.
67
67
68
+
> [!NOTE]
69
+
> Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
70
+
68
71
### Remote actions
69
72
70
73
The following Windows 10 desktop device remote actions aren't supported/recommended for Azure Virtual Desktop VMs:
@@ -89,9 +92,6 @@ The following table provides a set of known issues along with more information a
89
92
| Cannot auto-enroll if tenant has more than one MDM provider | This issue will be fixed in the future. |
90
93
| Modern apps, such as Universal Windows Platform (UWP) apps, are not working correctly if [FSLogix](/fslogix/overview) is configured | Using FSLogix and Modern apps could cause compatibility issues. We recommend that you don’t configure Modern apps when FSLogix is configured.|
91
94
92
-
## Additional Limitations
93
-
94
-
Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
95
95
## Next steps
96
96
97
97
*[Learn more about Azure Virtual Desktops](/azure/virtual-desktop/).
Intune supports managing virtual machines running Windows 10 Enterprise with certain limitations. Intune management does not depend on, or interfere with Azure Virtual Desktop management of the same virtual machine.
34
+
Intune supports managing virtual machines running Windows 10 Enterprise with certain limitations. Intune management doesn't depend on, or interfere with Azure Virtual Desktop management of the same virtual machine.
35
35
36
36
## Enrollment
37
+
37
38
- We recommend that you don't use Intune to manage on-demand, session-host virtual machines, also known as non-persistent virtual desktop infrastructure (VDI). Each VM must be enrolled when it's created. Also, regularly deleting VMs will leave orphaned device records in Intune until they're [cleaned up](../remote-actions/devices-wipe.md#automatically-delete-devices-with-cleanup-rules).
38
39
- Windows Autopilot Self-deploying and pre-provisioning deployment types aren't supported because they require a physical Trusted Platform Module (TPM).
39
40
- Out of Box Experience (OOBE) enrollment isn't supported on VMs that can only be accessed by using RDP (such as VMs that are hosted on Azure). This restriction means:
@@ -42,20 +43,20 @@ Intune supports managing virtual machines running Windows 10 Enterprise with cer
42
43
43
44
44
45
## Configuration
45
-
Intune does not support any configuration that utilizes a Trusted Platform Module or hardware management, including:
46
+
47
+
Intune doesn't support any configuration that utilizes a Trusted Platform Module or hardware management, including:
Intune automatically detects virtual machines and reports them as "Virtual Machine" in **Devices** > **All devices** > choose a device > **Overview** > **Model** field.
51
54
52
55
Deallocated virtual machines may contribute to noncompliant device reports because they're unable to [check in with the Intune service](../configuration/device-profile-troubleshoot.md#how-long-does-it-take-for-devices-to-get-a-policy-profile-or-app-after-they-are-assigned).
53
56
54
57
## Retirement
55
-
If you only have RDP access, don't use the [Wipe action](../remote-actions/devices-wipe.md#wipe). The Wipe action will delete the virtual machine's RDP settings and prevent you from ever connecting again.
56
58
57
-
## Additional Limitations
58
-
59
-
Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
59
+
If you only have RDP access, don't use the [Wipe action](../remote-actions/devices-wipe.md#wipe). The Wipe action will delete the virtual machine's RDP settings and prevent you from ever connecting again.
60
60
## Next steps
61
+
61
62
[Learn about using Azure Virtual Desktop with Intune](azure-virtual-desktop.md)
0 commit comments