Skip to content

Commit 5b922e6

Browse files
author
Angela Fleischmann
authored
Merge pull request #7423 from MicrosoftDocs/main
Publish 04/21/2022 3:30 PM PT
2 parents 5a0d083 + 2d2caa7 commit 5b922e6

37 files changed

Lines changed: 485 additions & 418 deletions

.openpublishing.redirection.json

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1097,6 +1097,31 @@
10971097
"source_path": "memdocs/configmgr/sum/deploy-use/uup-preview.md",
10981098
"redirect_url": "/mem/configmgr/sum/index",
10991099
"redirect_document_id": true
1100+
},
1101+
{
1102+
"source_path": "windows-365/enterprise/on-premises-network-connections.md",
1103+
"redirect_url": "/windows-365/enterprise/azure-network-connections",
1104+
"redirect_document_id": false
1105+
},
1106+
{
1107+
"source_path": "windows-365/enterprise/create-on-premises-network-connection.md",
1108+
"redirect_url": "/windows-365/enterprise/create-azure-network-connection",
1109+
"redirect_document_id": false
1110+
},
1111+
{
1112+
"source_path": "windows-365/enterprise/edit-on-premises-network-connection.md",
1113+
"redirect_url": "/windows-365/enterprise/edit-azure-network-connection",
1114+
"redirect_document_id": false
1115+
},
1116+
{
1117+
"source_path": "windows-365/enterprise/delete-on-premises-network-connection.md",
1118+
"redirect_url": "/windows-365/enterprise/delete-azure-network-connection",
1119+
"redirect_document_id": false
1120+
},
1121+
{
1122+
"source_path": "windows-365/enterprise/troubleshoot-on-premises-network-connection.md",
1123+
"redirect_url": "/windows-365/enterprise/troubleshoot-azure-network-connection",
1124+
"redirect_document_id": false
11001125
}
11011126
]
11021127
}

memdocs/intune/enrollment/android-dedicated-devices-fully-managed-enroll.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: Lenewsad
99
ms.author: lanewsad
1010
manager: dougeby
11-
ms.date: 01/19/2022
11+
ms.date: 04/21/2022
1212
ms.topic: how-to
1313
ms.service: microsoft-intune
1414
ms.subservice: enrollment
@@ -33,6 +33,9 @@ ms.collection:
3333

3434
# Enroll your Android Enterprise dedicated, fully managed, or corporate-owned with work profile devices
3535

36+
> [!IMPORTANT]
37+
> It's important that device users do not restart devices until enrollment is complete. If device users setting up fully managed devices or corporate-owned devices with a work profile restart their devices in the middle of enrollment, their devices may not be able to register with Microsoft Intune. Devices that restarted may appear to be enrolled but they won't be protected by your Intune policies.
38+
3639
After you've set up your Android Enterprise [dedicated devices](android-kiosk-enroll.md), [fully managed devices](android-fully-managed-enroll.md), or [corporate-owned work profile devices](android-corporate-owned-work-profile-enroll.md) in Intune, you can enroll the devices. Intune enrollment for dedicated devices, fully managed devices, and corporate-owned with a work profile start with a factory reset. How you enroll your Android Enterprise devices depends on the operating system.
3740

3841
| Enrollment method | Minimum Android OS version for dedicated and fully managed devices |

memdocs/intune/enrollment/enrollment-restrictions-set.md

Lines changed: 144 additions & 113 deletions
Large diffs are not rendered by default.

windows-365/enterprise/TOC.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -19,8 +19,8 @@ items:
1919
href: lifecycle.md
2020
- name: Provisioning
2121
href: provisioning.md
22-
- name: On-premises network connections
23-
href: on-premises-network-connections.md
22+
- name: Azure network connections
23+
href: azure-network-connections.md
2424
- name: Device images
2525
href: device-images.md
2626
- name: Lifecycle and operating system end of support
@@ -57,14 +57,14 @@ items:
5757
href: deployment-overview.md
5858
- name: Assign licenses
5959
href: assign-licenses.md
60-
- name: On-premises network connection
60+
- name: Azure network connection
6161
items:
62-
- name: Create on-premises network connection
63-
href: create-on-premises-network-connection.md
64-
- name: Edit on-premises network connection
65-
href: edit-on-premises-network-connection.md
66-
- name: Delete on-premises network connection
67-
href: delete-on-premises-network-connection.md
62+
- name: Create Azure network connection
63+
href: create-azure-network-connection.md
64+
- name: Edit Azure network connection
65+
href: edit-azure-network-connection.md
66+
- name: Delete Azure network connection
67+
href: delete-azure-network-connection.md
6868
- name: Provide a localized Windows experience
6969
items:
7070
- name: Provide a localized Windows experience
@@ -177,9 +177,9 @@ items:
177177
href: troubleshooting.md
178178
- name: Known issues
179179
href: known-issues-enterprise.md
180-
- name: On-premises network connections
181-
href: troubleshoot-on-premises-network-connection.md
182-
- name: On-premises network connection health checklist
180+
- name: Azure network connections
181+
href: troubleshoot-azure-network-connection.md
182+
- name: Azure network connection health checklist
183183
href: health-checks.md
184184
- name: Remote Desktop client
185185
href: /azure/virtual-desktop/troubleshoot-client?context=/windows-365/context/pr-context

windows-365/enterprise/architecture.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -37,14 +37,14 @@ Windows 365 provides a per-user per-month license model by hosting Cloud PCs on
3737
Each Cloud PC has a virtual network interface card (NIC) in Microsoft Azure. You have two NIC management options:
3838

3939
- If you use Azure Active Directory (Azure AD) Join and a Microsoft hosted network, you don’t need to bring an Azure subscription or manage the NIC.
40-
- If you bring your own network and use an on-premises network connection, the NICs are created by Windows 365 in your Azure subscription.
40+
- If you bring your own network and use an Azure network connection (ANC), the NICs are created by Windows 365 in your Azure subscription.
4141

42-
The NICs are attached to an Azure Virtual Network based on your [on-premises network connection (OPNC)](on-premises-network-connections.md) configuration.
42+
The NICs are attached to an Azure Virtual Network based on your [Azure network connection (ANC)](azure-network-connections.md) configuration.
4343

4444
Windows 365 is [supported in many Azure regions](requirements.md#supported-azure-regions-for-cloud-pc-provisioning). You can control which Azure region is used in two ways:
4545

4646
- By selecting the Microsoft-hosted network and an Azure region.
47-
- By selecting an Azure virtual network from your Azure subscription when [creating an OPNC](create-on-premises-network-connection.md).
47+
- By selecting an Azure virtual network from your Azure subscription when [creating an ANC](create-azure-network-connection.md).
4848

4949
The Azure virtual network's region determines where the Cloud PC is created and [hosted](architecture.md#hosted-on-behalf-of-architecture).
5050

@@ -127,7 +127,7 @@ Windows 365 Cloud PCs don't support third-party connection brokers.
127127

128128
The "hosted on behalf of" architecture lets Microsoft services, after they’re delegated appropriate and scoped permissions to a virtual network by a subscription owner, attach hosted Azure services to a customer subscription. This connectivity model lets a Microsoft service provide software-as-a-service and user licensed services as opposed to standard consumption-based services.
129129

130-
The following diagrams show the logical architecture for an Azure AD Join configuration using a Microsoft hosted network, an Azure AD Join configuration using a customer's network connection ("bring your own network"), and a Hybrid Azure AD Join configuration using an OPNC, respectively.
130+
The following diagrams show the logical architecture for an Azure AD Join configuration using a Microsoft hosted network, an Azure AD Join configuration using a customer's network connection ("bring your own network"), and a Hybrid Azure AD Join configuration using an ANC, respectively.
131131

132132
![Azure AD Join architecture with Microsoft hosted network](media/architecture/aadjhostednetwork.png)
133133

@@ -137,7 +137,7 @@ The following diagrams show the logical architecture for an Azure AD Join config
137137

138138
All Cloud PC connectivity is provided by the virtual network interface card. The "hosted on behalf of" architecture means that the Cloud PCs exist in the subscription owned by Microsoft. Therefore, Microsoft incurs the costs for running and managing this infrastructure.
139139

140-
Windows 365 manages the capacity and in-region availability in the Windows 365 subscriptions. Windows 365 determines the size and type of VM based on the [license](cloud-pc-size-recommendations.md) you [assign to the user](assign-licenses.md). Windows 365 determines the Azure region to host your Cloud PCs in based on the virtual network you select when [creating an on-prem network connection](create-on-premises-network-connection.md).
140+
Windows 365 manages the capacity and in-region availability in the Windows 365 subscriptions. Windows 365 determines the size and type of VM based on the [license](cloud-pc-size-recommendations.md) you [assign to the user](assign-licenses.md). Windows 365 determines the Azure region to host your Cloud PCs in based on the virtual network you select when [creating an on-prem network connection](create-azure-network-connection.md).
141141

142142
Windows 365 aligns with Microsoft 365 data protection policies and provisions. Customer data within Microsoft's enterprise cloud services is protected by various technologies and processes:
143143

windows-365/enterprise/assign-licenses.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,4 +39,4 @@ Before a user can use a Cloud PC, you must assign a [Windows 365 license](https:
3939
<!-- ########################## -->
4040
Next, check out the following article:
4141

42-
[Create on-premises network connection](create-on-premises-network-connection.md).
42+
[Create Azure network connection](create-azure-network-connection.md).

windows-365/enterprise/automated-provisioning-steps.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ ms.collection: M365-identity-device-management
3030

3131
# Automated provisioning steps
3232

33-
As an admin, you create provisioning policies and on-premises network connections to set up Windows 365 to provision Cloud PCs. Using this information, Windows 365 provisions Cloud PCs for your licensed users. This article explains all of the steps that Windows 365 completes automatically in the provisioning process.
33+
As an admin, you create provisioning policies and Azure network connections to set up Windows 365 to provision Cloud PCs. Using this information, Windows 365 provisions Cloud PCs for your licensed users. This article explains all of the steps that Windows 365 completes automatically in the provisioning process.
3434

3535
There are three stages that Windows 365 automatically completes for Cloud PC provisioning:
3636

@@ -44,7 +44,7 @@ Core provisioning is optimized to only perform necessary steps to make sure a Cl
4444

4545
1. **Allocate Azure capacity**: When provisioning first begins, Windows 365 allocates Azure capacity in the customer’s supported region of choice. Customers don’t need to manage capacity and allocation manually.
4646
2. **Create VM**: A virtual machine is created based on the Windows 365 license assigned to the user. Each Windows 365 license includes hardware capacity information. The VM is created with these specs.
47-
3. **Attach the VM to the appropriate network**: When the VM is created, a virtual NIC is also created. If the provisioning policy specifies a Microsoft hosted network, the NIC is attached to an existing or new virtual network in the selected region specifically for the customer. If the provisioning policy specifies an on-premises network connection, the NIC is injected into the customers provided vNet. This lets the Cloud PC connect to the customers on-premises network.
47+
3. **Attach the VM to the appropriate network**: When the VM is created, a virtual NIC is also created. If the provisioning policy specifies a Microsoft hosted network, the NIC is attached to an existing or new virtual network in the selected region specifically for the customer. If the provisioning policy specifies an Azure network connection, the NIC is injected into the customers provided vNet. This lets the Cloud PC connect to the customers on-premises network.
4848
4. **Join to Azure AD**: After the VM is running, the device will be joined to Azure AD in one of two ways:
4949

5050
- Through Azure AD Join: the device performs the Azure AD Join operation and has no Windows Server Active Directory dependency.
Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,138 @@
1+
---
2+
# required metadata
3+
title: Azure network connection overview
4+
titleSuffix:
5+
description: Learn about Azure network connections in Windows 365
6+
keywords:
7+
author: ErikjeMS
8+
ms.author: erikje
9+
manager: dougeby
10+
ms.date: 02/16/2022
11+
ms.topic: overview
12+
ms.service: cloudpc
13+
ms.subservice:
14+
ms.localizationpriority: high
15+
ms.technology:
16+
ms.assetid:
17+
18+
# optional metadata
19+
20+
#ROBOTS:
21+
#audience:
22+
23+
ms.reviewer: mattsha
24+
ms.suite: ems
25+
search.appverid: MET150
26+
#ms.tgt_pltfrm:
27+
ms.custom: intune-azure; get-started
28+
ms.collection: M365-identity-device-management
29+
---
30+
31+
# Azure network connection overview
32+
33+
An Azure network connection (ANC) is an object in the Microsoft Endpoint Manager admin center that provides Cloud PC provisioning profiles with required information to connect to network-based resources. ANCs are used:
34+
35+
- When a Cloud PC is initially provisioned.
36+
- When Windows 365 periodically checks the connection to the on-premises infrastructure to ensure the best end-user experience.
37+
38+
## Network connection types
39+
40+
There are two kinds of ANCs based on their join type. Both let you manage traffic and Cloud PC access to network based resources but they have different connectivity requirements.
41+
42+
- **Azure AD Join**: Doesn't require connectivity to a Windows Server Active Directory (AD) domain.
43+
- **Hybrid Azure AD Join**: Requires connectivity to a Windows Server AD domain. You must provide the AD domain details when you [create the ANC](create-azure-network-connection.md).
44+
45+
46+
## Provisioning
47+
48+
When a Cloud PC is provisioned, the information in the ANC is used by the provisioning policy to provision the Cloud PC the Azure subnet. The information required in an ANC includes:
49+
50+
- **Network details**: The Azure subscription, resource group, virtual network, and subnet that the Cloud PC will be associated with. When a provisioning policy runs, it creates a Cloud PC in the Microsoft hosted Azure subscription. To connect to a customers on-premises network, a virtual network interface card (vNic) is injected into a customer-provided Azure virtual network (vNet). To create this vNic, Windows 365 needs sufficient access to an Azure subscription.
51+
- **Active Directory domain**: The Active Directory domain to join, an Organizational Unit (OU) destination for the computer object, and Active Directory user credentials with sufficient permissions to perform the domain join. When a provisioning policy runs, the Cloud PC is joined to this Active Directory domain. The credentials will be stored securely in the Windows 365 service.
52+
53+
During provisioning, the Cloud PC is connected to the Azure subnet and joined to a domain (either Windows Server Active Directory or Azure Active Directory (Azure AD)). This process results in a Cloud PC that is:
54+
55+
- On your network.
56+
- Registered to Azure AD.
57+
- Enrolled into Microsoft Endpoint Manager.
58+
- Ready to accept user sign-in requests.
59+
60+
The ANC settings are applied to the Cloud PC only at the time of provisioning.
61+
62+
## First health check
63+
64+
The information included in the ANC is used to provision a Cloud PC. For provisioning to succeed, the resources referenced in the ANC must be healthy and accessible. After an ANC object is created, Windows 365 verifies that:
65+
66+
- The objects referenced by the ANC are healthy.
67+
- Connections can be made to these objects.
68+
69+
These health checks use the ANC information provided to provision a Cloud PC. For a complete list of checks, see [Azure network connection health checks](health-checks.md).
70+
71+
While this first ANC health check is underway, you can’t assign it to a provisioning policy. After the health check is complete and successful, the ANC can be assigned to one or more provisioning policies.
72+
73+
## Periodic health checks
74+
75+
After provisioning, the information in an ANC is also used to monitor the connection health between your network-based resources and the Cloud PC hosted in the Microsoft hosted subscription. Windows 365 will report configuration issues that may cause provisioning failures or poor end-user experiences. This monitoring reduces your management overhead. For more information on these periodic checks, see [Azure network connection health checks](health-checks.md).
76+
77+
## Health check frequency
78+
79+
ANC checks are performed once every one to six hours.
80+
81+
The comprehensive, end-to end health check can take up to 30 minutes. The health checks are run on a temporary Azure virtual machine that is automatically created specifically for this purpose. This virtual machine is created automatically and deleted when the health checks are completed. The virtual machine is connected to your specified vNet and checks are performed to ensure provisioning should be successful.
82+
83+
After a check is complete, the results are posted on the Azure network connection pane of the Microsoft Endpoint Manager admin center. For information about the check results, see [Azure network connections health checks](health-checks.md).
84+
85+
## Retry health check
86+
87+
To manually trigger a full health check, sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Windows 365 (under Provisioning)** > **Azure network connection** > select an Azure network connection > **Retry**.
88+
89+
## Permissions required for Azure network connections
90+
91+
The ANC wizard requires access to Azure and, optionally, on-premises domain resources. The following permissions are required for the ANC:
92+
93+
- Azure
94+
- Subscription Owner or Subscription User Access Administrator.
95+
- Active directory (Hybrid Azure AD Join ANCs only)
96+
- An Active Directory user account with sufficient permissions to join the AD domain into this Organizational Unit.
97+
98+
To create, edit , or delete an ANC, you'll also need to have one of the following permissions:
99+
100+
- Intune Administrator in Azure AD
101+
- Cloud PC administrator
102+
- Global Administrator
103+
104+
For a full list of requirements, see [Windows 365 requirements](requirements.md).
105+
106+
## Changing an Azure network connection
107+
108+
Changing the settings in an ANC won’t affect Cloud PCs previously provisioned with that ANC. Only Cloud PCs provisioned after the changes to the ANC will reflect such later changes.
109+
110+
If you want to change the ANC related settings on a previously provisioned Cloud PC, you must reprovision the Cloud PC. Reprovisioning is a destructive action, so be sure it's an action you really want to take. For more information, see [reprovisioning](provisioning.md#reprovisioning).
111+
112+
## Delete an Azure network connection
113+
114+
You can’t delete an ANC that's in use. Before the object can be deleted, you must do one of the following actions for every provisioning policy that uses this ANC:
115+
116+
- Change the policy to use a different ANC.
117+
- Delete the policy. For more information, [Delete an Azure network connection](delete-azure-network-connection.md).
118+
119+
After completing either of these operations, you can delete the ANC.
120+
121+
## Maximum Azure network connections
122+
123+
Each tenant has a limit of 10 Azure network connections. If your organization needs more than 10 Azure network connections, contact support.
124+
125+
## User sign-in
126+
127+
When users attempt to sign in to their Cloud PC, user authentication occurs.
128+
129+
For Hybrid Azure AD Join ANCs, the ANC is used to route the authentication request to your domain controllers. If the ANC or the network connection to your domain is unhealthy, user sign-in can't occur. Windows cached credentials can't be used over the remote desktop channel, so domain controller availability is critical. Ensure your network is stable or place a domain controller server on the same subnet as your Cloud PCs.
130+
131+
For Azure AD Join ANCs, the ANC is used to route the authentication request to Azure AD. Windows cached credentials can’t be used over the remote desktop channel, so connectivity to Azure AD is critical.
132+
133+
<!-- ########################## -->
134+
## Next steps
135+
136+
[Learn about device images](device-images.md)
137+
138+
[Create an Azure network connection](create-azure-network-connection.md)

0 commit comments

Comments
 (0)