Skip to content

Commit 24fa6de

Browse files
committed
minor edits to note placement
1 parent bba83e1 commit 24fa6de

3 files changed

Lines changed: 37 additions & 37 deletions

File tree

memdocs/intune/fundamentals/azure-virtual-desktop-multi-session.md

Lines changed: 27 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -45,15 +45,15 @@ You can manage **Windows 10** and **Windows 11 Enterprise multi-session** VMs cr
4545

4646
## Overview
4747

48-
Microsoft Intune only supports managing Windows 10 or Windows 11 Enterprise multi-session with device configurations. This means only [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, all multi-session configurations must be targeted to devices or device groups. User scope policies are not supported at this time.
48+
Microsoft Intune only supports managing Windows 10 or Windows 11 Enterprise multi-session with device configurations. This means only [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, all multi-session configurations must be targeted to devices or device groups. User scope policies aren't supported at this time.
4949

5050
## Prerequisites
5151

52-
This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs which are:
52+
This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs, which are:
5353

5454
- Running Windows 10 multi-session, version 1903 or later, or running Windows 11 multi-session.
5555
- Set up as remote desktops in pooled host pools that have been deployed through Azure Resource Manager.
56-
- Running a Azure Virtual Desktop agent version of 1.0.2944.1400 or later.
56+
- Running an Azure Virtual Desktop agent version of 1.0.2944.1400 or later.
5757
- [Hybrid Azure AD-joined](/azure/active-directory/devices/hybrid-azuread-join-plan) and enrolled in Microsoft Intune using one of the following methods:
5858
- Configured with [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy), set to use Device credentials, and set to automatically enroll devices that are Hybrid Azure AD-joined.
5959
- [Configuration Manager co-management](/configmgr/comanage/overview).
@@ -64,13 +64,13 @@ This feature supports Windows 10 or Windows 11 Enterprise multi-session VMs whic
6464
6565
See [What is Azure Virtual Desktop?](/azure/virtual-desktop/overview#requirements) for more information about Azure Virtual Desktop licensing requirements.
6666

67-
Windows 10 or Windows 11 Enterprise multi-session VMs are treated as a separate OS edition and some Windows 10 or Windows 11 Enterprise configurations won’t be supported for this edition. Using Microsoft Intune does not depend on or interfere with Azure Virtual Desktop management of the same VM.
67+
Windows 10 or Windows 11 Enterprise multi-session VMs are treated as a separate OS edition and some Windows 10 or Windows 11 Enterprise configurations won’t be supported for this edition. Using Microsoft Intune doesn't depend on or interfere with Azure Virtual Desktop management of the same VM.
6868

6969
## Create the device configuration profile
7070

7171
To configure configuration policies for Windows 10 or Windows 11 Enterprise multi-session VMs, you'll need to use the [Settings catalog](../configuration/settings-catalog.md) in the Microsoft Endpoint Manager admin center.
7272

73-
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, with the exception of the following templates:
73+
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, except for the following templates:
7474

7575
- [Trusted certificate](../protect/certificates-trusted-root.md#create-trusted-certificate-profiles) - Device (machine) only
7676
- [SCEP certificate](../protect/certificates-profile-scep.md#create-a-scep-certificate-profile) - Device (machine) only
@@ -104,8 +104,8 @@ Microsoft Intune won't deliver unsupported templates to multi-session devices, a
104104

105105
Windows 10 or Windows 11 Administrative Templates are supported for Windows 10 or Windows 11 Enterprise multi-session via the Settings catalog with some limitations:
106106

107-
- ADMX-backed policies are supported. Some policies are not yet available in the Settings catalog.
108-
- ADMX-ingested policies are supported, including Office and Microsoft Edge settings available in Office administrative template files and Microsoft Edge administrative template files. For a complete list of ADMX-ingested policy categories, see [Win32 and Desktop Bridge app policy configuration](/windows/client-management/mdm/win32-and-centennial-app-policy-configuration#overview). Some ADMX ingested settings will not be applicable to Windows 10 or Windows 11 Enterprise multi-session.
107+
- ADMX-backed policies are supported. Some policies aren't yet available in the Settings catalog.
108+
- ADMX-ingested policies are supported, including Office and Microsoft Edge settings available in Office administrative template files and Microsoft Edge administrative template files. For a complete list of ADMX-ingested policy categories, see [Win32 and Desktop Bridge app policy configuration](/windows/client-management/mdm/win32-and-centennial-app-policy-configuration#overview). Some ADMX ingested settings won't be applicable to Windows 10 or Windows 11 Enterprise multi-session.
109109

110110
## Compliance and Conditional access
111111

@@ -139,6 +139,9 @@ All other policies report as **Not applicable**.
139139
> [!NOTE]
140140
> [Conditional Access for Exchange on-premises](../protect/conditional-access-exchange-create.md) isn't supported for Windows 10 or Windows 11 Enterprise multi-session VMs.
141141
142+
> [!NOTE]
143+
> Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
144+
142145
## Endpoint security
143146

144147
You can configure profiles under Endpoint security for multi-session VMs by selecting Platform Windows 10, Windows 11, and Windows Server.
@@ -149,10 +152,10 @@ For more information, see [Manage device security with endpoint security policie
149152

150153
All Windows 10 or Windows 11 apps can be deployed to Windows 10 or Windows 11 Enterprise multi-session with the following restrictions:
151154

152-
- All apps must be configured to install in the system/device context and be targeted to devices. Web apps are always applied in the user context by default so they will not apply to multi-session VMs.
153-
- All apps must be configured with **Required** or **Uninstall** app assignment intent. The **Available apps** deployment intent is not supported on multi-session VMs.
154-
- If a Win32 app configured to install in the system context has dependencies or supersedence relationship on any apps configured to install in the user context, the app will not be installed. To apply to a Windows 10 or Windows 11 Enterprise multi-session VM, create a separate instance of the system context app or make sure all app dependencies are configured to install in the system context.
155-
- Azure Virtual Desktop RemoteApp and MSIX app attach are not currently supported in Microsoft Intune.
155+
- All apps must be configured to install in the system/device context and be targeted to devices. Web apps are always applied in the user context by default so they won't apply to multi-session VMs.
156+
- All apps must be configured with **Required** or **Uninstall** app assignment intent. The **Available apps** deployment intent isn't supported on multi-session VMs.
157+
- If a Win32 app configured to install in the system context has dependencies or supersedence relationship on any apps configured to install in the user context, the app won't be installed. To apply to a Windows 10 or Windows 11 Enterprise multi-session VM, create a separate instance of the system context app or make sure all app dependencies are configured to install in the system context.
158+
- Azure Virtual Desktop RemoteApp and MSIX app attach aren't currently supported in Microsoft Intune.
156159

157160
## Script deployment
158161

@@ -175,7 +178,7 @@ The following settings are available in the catalog, with the links opening the
175178

176179
## Remote actions
177180

178-
The following Windows 10 or Windows 11 desktop device remote actions are not supported and will be grayed out in the UI and disabled in Graph for Windows 10 or Windows 11 Enterprise multi-session VMs:
181+
The following Windows 10 or Windows 11 desktop device remote actions aren't supported and will be grayed out in the UI and disabled in Graph for Windows 10 or Windows 11 Enterprise multi-session VMs:
179182

180183
- Autopilot reset
181184
- BitLocker key rotation
@@ -186,24 +189,20 @@ The following Windows 10 or Windows 11 desktop device remote actions are not sup
186189

187190
## Retirement
188191

189-
Deleting VMs from Azure will leave orphaned device records in the Microsoft Endpoint Manager admin center. They will be automatically cleaned up according to the cleanup rules configured for the tenant.
192+
Deleting VMs from Azure will leave orphaned device records in the Microsoft Endpoint Manager admin center. They'll be automatically cleaned up according to the cleanup rules configured for the tenant.
190193

191194
## Security baselines
192195

193-
Security baselines are not available for Windows 10 or Windows 11 Enterprise multi-session at this time. We recommend that you review the [Available security baselines](../protect/security-baselines.md) and configure the recommended policies and values in the [Settings catalog](../configuration/settings-catalog.md).
196+
Security baselines aren't available for Windows 10 or Windows 11 Enterprise multi-session at this time. We recommend that you review the [Available security baselines](../protect/security-baselines.md) and configure the recommended policies and values in the [Settings catalog](../configuration/settings-catalog.md).
194197

195-
## Additional configurations which are not supported on Windows 10 or Windows 11 Enterprise multi-session VMs
198+
## Additional configurations that aren't supported on Windows 10 or Windows 11 Enterprise multi-session VMs
196199

197200
Out of Box Experience (OOBE) enrollment isn't supported for Window 10 or Windows 11 Enterprise multi-session. This restriction means that:
198201

199202
- Windows Autopilot and Commercial OOBE aren't supported.
200203
- Enrollment status page isn’t supported.
201204

202-
Windows 10 or Windows 11 Enterprise multi-session managed by Microsoft Intune is not currently supported for China.
203-
204-
## Additional Limitations
205-
206-
Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
205+
Windows 10 or Windows 11 Enterprise multi-session managed by Microsoft Intune isn't currently supported for China Sovereign Cloud.
207206
## Troubleshooting
208207

209208
The following sections provide troubleshooting guidance for common issues.
@@ -212,19 +211,19 @@ The following sections provide troubleshooting guidance for common issues.
212211

213212
|Issue|Detail|
214213
|---------------|---------------------------------|
215-
|Enrollment of hybrid Azure AD joined virtual machine fails|<ul><li>Auto-enrollment is configured to use user credentials. Windows 10 or Windows 11 Enterprise multi-session virtual machines must be enrolled using device credentials.<li>The Azure Virtual Desktop agent you’re using must be version 2944.1400 or later.<li>You have more than one MDM provider, which is not supported.<li>Windows 10 or Windows 11 Enterprise multi-session VM is configured outside of a host pool. Microsoft Intune only supports VMs provisioned as part of a host pool.<li>The Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
216-
|Enrollment of Azure AD joined virtual machine fails|<ul><li>The Azure Virtual Desktop agent you’re using is not updated. The agent must be version 2944.1400 or above.<li>Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
214+
|Enrollment of hybrid Azure AD joined virtual machine fails|<ul><li>Auto-enrollment is configured to use user credentials. Windows 10 or Windows 11 Enterprise multi-session virtual machines must be enrolled using device credentials.<li>The Azure Virtual Desktop agent you’re using must be version 2944.1400 or later.<li>You've more than one MDM provider, which isn't supported.<li>Windows 10 or Windows 11 Enterprise multi-session VM is configured outside of a host pool. Microsoft Intune only supports VMs provisioned as part of a host pool.<li>The Azure Virtual Desktop host pool wasn't created through the Azure Resource Manager template.|
215+
|Enrollment of Azure AD joined virtual machine fails|<ul><li>The Azure Virtual Desktop agent you’re using isn't updated. The agent must be version 2944.1400 or above.<li>Azure Virtual Desktop host pool wasn't created through the Azure Resource Manager template.|
217216

218217
### Configuration issues
219218

220219
|Issue|Detail|
221220
|--------|------------------------------|
222-
|Settings catalog policy fails|Confirm the VM is enrolled using device credentials. Enrollment with user credentials is not currently supported for Windows 10 or Windows 11 Enterprise multi-session.|
223-
|Configuration policy did not apply|Templates (with the exception of Certificates) are not supported on Windows 10 or Windows 11 Enterprise multi-session. All policies must be created via the settings catalog.|
224-
Configuration policy reports as Not applicable|Some policies are not applicable to Azure Virtual Desktop VMs.|
225-
|Microsoft Edge/Microsoft Office ADMX policy does not show up when I apply the filter for Windows 10 or Windows 11 Enterprise multi-session edition|Applicability for these settings is not based on the Windows version or edition but on whether those apps have been installed on the device. To add these settings to your policy, you may have to remove any filters applied in the settings picker.|
226-
|App configured to install in system context did not apply|Confirm the app does not have a dependency or supersedence relationship on any apps configured to install in user context. User context apps are not currently supported on Windows 10 or Windows 11 Enterprise multi-session.|
227-
|Update rings for Windows 10 and later policy did not apply|Windows Update for Business policies are not currently supported.|
221+
|Settings catalog policy fails|Confirm the VM is enrolled using device credentials. Enrollment with user credentials isn't currently supported for Windows 10 or Windows 11 Enterprise multi-session.|
222+
|Configuration policy didn't apply|Templates (except for Certificates) aren't supported on Windows 10 or Windows 11 Enterprise multi-session. All policies must be created via the settings catalog.|
223+
Configuration policy reports as Not applicable|Some policies aren't applicable to Azure Virtual Desktop VMs.|
224+
|Microsoft Edge/Microsoft Office ADMX policy doesn't show up when I apply the filter for Windows 10 or Windows 11 Enterprise multi-session edition|Applicability for these settings isn't based on the Windows version or edition but on whether those apps have been installed on the device. To add these settings to your policy, you may have to remove any filters applied in the settings picker.|
225+
|App configured to install in system context didn't apply|Confirm the app doesn't have a dependency or supersedence relationship on any apps configured to install in user context. User context apps aren't currently supported on Windows 10 or Windows 11 Enterprise multi-session.|
226+
|Update rings for Windows 10 and later policy didn't apply|Windows Update for Business policies aren't currently supported.|
228227

229228
## Next steps
230229

memdocs/intune/fundamentals/azure-virtual-desktop.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,9 @@ Also, the following profiles aren't currently supported:
6565

6666
Make sure that the [RemoteDesktopServices/AllowUsersToConnectRemotely policy](/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-allowuserstoconnectremotely) isn't disabled.
6767

68+
> [!NOTE]
69+
> Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
70+
6871
### Remote actions
6972

7073
The following Windows 10 desktop device remote actions aren't supported/recommended for Azure Virtual Desktop VMs:
@@ -89,9 +92,6 @@ The following table provides a set of known issues along with more information a
8992
| Cannot auto-enroll if tenant has more than one MDM provider | This issue will be fixed in the future. |
9093
| Modern apps, such as Universal Windows Platform (UWP) apps, are not working correctly if [FSLogix](/fslogix/overview) is configured | Using FSLogix and Modern apps could cause compatibility issues. We recommend that you don’t configure Modern apps when FSLogix is configured.|
9194

92-
## Additional Limitations
93-
94-
Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
9595
## Next steps
9696

9797
* [Learn more about Azure Virtual Desktops](/azure/virtual-desktop/).

memdocs/intune/fundamentals/windows-10-virtual-machines.md

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,9 +31,10 @@ ms.collection: M365-identity-device-management
3131

3232
# Using Windows 10 virtual machines with Intune
3333

34-
Intune supports managing virtual machines running Windows 10 Enterprise with certain limitations. Intune management does not depend on, or interfere with Azure Virtual Desktop management of the same virtual machine.
34+
Intune supports managing virtual machines running Windows 10 Enterprise with certain limitations. Intune management doesn't depend on, or interfere with Azure Virtual Desktop management of the same virtual machine.
3535

3636
## Enrollment
37+
3738
- We recommend that you don't use Intune to manage on-demand, session-host virtual machines, also known as non-persistent virtual desktop infrastructure (VDI). Each VM must be enrolled when it's created. Also, regularly deleting VMs will leave orphaned device records in Intune until they're [cleaned up](../remote-actions/devices-wipe.md#automatically-delete-devices-with-cleanup-rules).
3839
- Windows Autopilot Self-deploying and pre-provisioning deployment types aren't supported because they require a physical Trusted Platform Module (TPM).
3940
- Out of Box Experience (OOBE) enrollment isn't supported on VMs that can only be accessed by using RDP (such as VMs that are hosted on Azure). This restriction means:
@@ -42,20 +43,20 @@ Intune supports managing virtual machines running Windows 10 Enterprise with cer
4243

4344

4445
## Configuration
45-
Intune does not support any configuration that utilizes a Trusted Platform Module or hardware management, including:
46+
47+
Intune doesn't support any configuration that utilizes a Trusted Platform Module or hardware management, including:
4648
- [BitLocker settings](../configuration/device-profiles.md#endpoint-protection)
4749
- [Device Firmware Configuration Interface settings](../configuration/device-profiles.md#device-firmware-configuration-interface)
4850

4951
## Reporting
52+
5053
Intune automatically detects virtual machines and reports them as "Virtual Machine" in **Devices** > **All devices** > choose a device > **Overview** > **Model** field.
5154

5255
Deallocated virtual machines may contribute to noncompliant device reports because they're unable to [check in with the Intune service](../configuration/device-profile-troubleshoot.md#how-long-does-it-take-for-devices-to-get-a-policy-profile-or-app-after-they-are-assigned).
5356

5457
## Retirement
55-
If you only have RDP access, don't use the [Wipe action](../remote-actions/devices-wipe.md#wipe). The Wipe action will delete the virtual machine's RDP settings and prevent you from ever connecting again.
5658

57-
## Additional Limitations
58-
59-
Configuration and compliance policies for Secure Boot and features leveraging vTPM (Virtual Trusted Platform Module) are not supported at this time for Azure Virtual Desktop VMs.
59+
If you only have RDP access, don't use the [Wipe action](../remote-actions/devices-wipe.md#wipe). The Wipe action will delete the virtual machine's RDP settings and prevent you from ever connecting again.
6060
## Next steps
61+
6162
[Learn about using Azure Virtual Desktop with Intune](azure-virtual-desktop.md)

0 commit comments

Comments
 (0)