You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Windows 10 or Windows 11 Enterprise multi-session remote desktops (preview)
33
33
34
34
> [!IMPORTANT]
35
-
> Azure Virtual Desktop multi-session with Microsoft Endpoint Manager is currently in preview and may be modified before it’s released. See [Public preview in Microsoft Intune](public-preview.md) for more information.
35
+
> Azure Virtual Desktop multi-session with Microsoft Intune is currently in preview and may be modified before it’s released. See [Public preview in Microsoft Intune](public-preview.md) for more information.
36
36
37
-
You can now use Microsoft Endpoint Manager to manage Windows 10 or Windows 11 Enterprise multi-session remote desktops just as you can manage a shared Windows 10 or Windows 11 client device. When managing such VMs, you must use device-based configurations. Such configurations require user-less enrollments.
37
+
You can now use Microsoft Intune to manage Windows 10 or Windows 11 Enterprise multi-session remote desktops in the Microsoft Endpoint Manager admin center just as you can manage a shared Windows 10 or Windows 11 client device. When managing such virtual machines (VMs), you must use device-based configurations. Such configurations require user-less enrollments.
38
38
39
39
Windows 10 or Windows 11 Enterprise multi-session is a new Remote Desktop Session Host exclusive to [Azure Virtual Desktop](/azure/virtual-desktop/) on Azure. It provides the following benefits:
40
40
@@ -44,7 +44,7 @@ Windows 10 or Windows 11 Enterprise multi-session is a new Remote Desktop Sessio
44
44
45
45
## Overview
46
46
47
-
Microsoft Endpoint Manager only supports managing Windows 10 or Windows 11 Enterprise multi-session with device configurations. This means only [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, all multi-session configurations must be targeted to devices or device groups. User scope policies are not supported at this time.
47
+
Microsoft Intune only supports managing Windows 10 or Windows 11 Enterprise multi-session with device configurations. This means only [policies defined in the OS scope](/windows/client-management/mdm/policy-configuration-service-provider) and apps configured to install in the system context can be applied to Azure Virtual Desktop multi-session VMs. Additionally, all multi-session configurations must be targeted to devices or device groups. User scope policies are not supported at this time.
48
48
49
49
## Prerequisites
50
50
@@ -53,21 +53,21 @@ This public preview feature supports Windows 10 or Windows 11 Enterprise multi-s
53
53
- Running Windows 10 multi-session, version 1903 or later, or running Windows 11 multi-session.
54
54
- Set up as remote desktops in pooled host pools that have been deployed through Azure Resource Manager.
55
55
- Running a Azure Virtual Desktop agent version of 1.0.2944.1400 or later.
56
-
-[Hybrid Azure AD-joined](/azure/active-directory/devices/hybrid-azuread-join-plan) and enrolled in Microsoft Endpoint Manager using one of the following methods:
57
-
- Configured with [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy), set to use Device credentials, and set to automatically enroll devices that are Hybrid Azure AD-joined. For this preview, we only support enrollment via group policy if you're using a single MDM provider.
56
+
-[Hybrid Azure AD-joined](/azure/active-directory/devices/hybrid-azuread-join-plan) and enrolled in Microsoft Intune using one of the following methods:
57
+
- Configured with [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy), set to use Device credentials, and set to automatically enroll devices that are Hybrid Azure AD-joined. For this preview, we only support enrollment via group policy if you're using a single MDM provider.
- Azure AD-joined and enrolled in Microsoft Endpoint Manager by enabling [Enroll the VM with Intune](/azure/virtual-desktop/deploy-azure-ad-joined-vm#deploy-azure-ad-joined-vms) in the Azure portal.
59
+
- Azure AD-joined and enrolled in Microsoft Intune by enabling [Enroll the VM with Intune](/azure/virtual-desktop/deploy-azure-ad-joined-vm#deploy-azure-ad-joined-vms) in the Azure portal.
60
60
61
61
> [!IMPORTANT]
62
-
> If you’re using Windows 10, versions 2004, 20H2, or 21H1 builds, make sure that you install the July 2021 Windows Update or a later Windows update. Otherwise, remote actions in Microsoft Endpoint Manager, like remote sync, won’t work correctly. As a result, pending policies assigned to devices might take up to 8 hours to be applied.
62
+
> If you’re using Windows 10, versions 2004, 20H2, or 21H1 builds, make sure that you install the July 2021 Windows Update or a later Windows update. Otherwise, remote actions in the Microsoft Endpoint Manager admin center, like remote sync, won’t work correctly. As a result, pending policies assigned to devices might take up to 8 hours to be applied.
63
63
64
-
For more information on Azure Virtual Desktop licensing requirements, see [What is Azure Virtual Desktop?](/azure/virtual-desktop/overview#requirements)
64
+
See [What is Azure Virtual Desktop?](/azure/virtual-desktop/overview#requirements) for more information about Azure Virtual Desktop licensing requirements.
65
65
66
-
Windows 10 or Windows 11 Enterprise multi-session VMs are treated as a separate OS edition and some existing Windows 10 or Windows 11 Enterprise configurations won’t be supported for this edition. Using Microsoft Endpoint Manager does not depend on or interfere with Azure Virtual Desktop management of the same VM.
66
+
Windows 10 or Windows 11 Enterprise multi-session VMs are treated as a separate OS edition and some Windows 10 or Windows 11 Enterprise configurations won’t be supported for this edition. Using Microsoft Intune does not depend on or interfere with Azure Virtual Desktop management of the same VM.
67
67
68
68
## Create the device configuration profile
69
69
70
-
To configure configuration policies for Windows 10 or Windows 11 Enterprise multi-session VMs, you'll usually use the [Settings catalog](../configuration/settings-catalog.md).
70
+
To configure configuration policies for Windows 10 or Windows 11 Enterprise multi-session VMs, you'll usually use the [Settings catalog](../configuration/settings-catalog.md) in the Microsoft Endpoint Manager admin center.
71
71
72
72
The existing device configuration profile templates aren't supported for Windows 10 or Windows 11 Enterprise multi-session VMs, with the exception of the following templates:
73
73
@@ -76,7 +76,7 @@ The existing device configuration profile templates aren't supported for Windows
76
76
-[PKCS certificate](../protect/certificates-pfx-configure.md#create-a-pkcs-certificate-profile) - Device (machine) only
77
77
-[VPN](../configuration/vpn-settings-configure.md#create-the-profile) - Device Tunnel only
78
78
79
-
Intune won't deliver unsupported templates to multi-session devices, and those policies appear as *Not applicable* in reports.
79
+
Microsoft Intune won't deliver unsupported templates to multi-session devices, and those policies appear as *Not applicable* in reports.
80
80
81
81
### To configure policies
82
82
@@ -101,7 +101,7 @@ Intune won't deliver unsupported templates to multi-session devices, and those p
101
101
102
102
### Administrative templates
103
103
104
-
Windows 10 Administrative Templates are supported for Windows 10 or Windows 11 Enterprise multi-session via the Settings catalog with some limitations:
104
+
Windows 10 or Windows 11 Administrative Templates are supported for Windows 10 or Windows 11 Enterprise multi-session via the Settings catalog with some limitations:
105
105
106
106
- ADMX-backed policies are supported. Some policies are not yet available in the Settings catalog.
107
107
- ADMX-ingested policies are supported, including Office and Microsoft Edge settings available in Office administrative template files and Microsoft Edge administrative template files. For a complete list of ADMX-ingested policy categories, see [Win32 and Desktop Bridge app policy configuration](/windows/client-management/mdm/win32-and-centennial-app-policy-configuration#overview). Some ADMX ingested settings will not be applicable to Windows 10 or Windows 11 Enterprise multi-session.
@@ -111,7 +111,7 @@ Windows 10 Administrative Templates are supported for Windows 10 or Windows 11 E
111
111
112
112
## Compliance and Conditional access
113
113
114
-
You can secure your Windows 10 or Windows 11 Enterprise multi-session VMs by configuring compliance policies and Conditional Access policies in the Endpoint Manager admin center. The following compliance policies are supported on Windows 10 or Windows Enterprise multi-session VMs:
114
+
You can secure your Windows 10 or Windows 11 Enterprise multi-session VMs by configuring compliance policies and Conditional Access policies in the Microsoft Endpoint Manager admin center. The following compliance policies are supported on Windows 10 or Windows 11 Enterprise multi-session VMs:
115
115
116
116
- Minimum OS version
117
117
- Maximum OS version
@@ -148,7 +148,7 @@ All Windows 10 or Windows 11 apps can be deployed to Windows 10 or Windows 11 En
148
148
- All apps must be configured to install in the system/device context and be targeted to devices. Web apps are always applied in the user context by default so they will not apply to multi-session VMs.
149
149
- All apps must be configured with **Required** or **Uninstall** app assignment intent. The **Available apps** deployment intent is not supported on multi-session VMs.
150
150
- If a Win32 app configured to install in the system context has dependencies or supersedence relationship on any apps configured to install in the user context, the app will not be installed. To apply to a Windows 10 or Windows 11 Enterprise multi-session VM, create a separate instance of the system context app or make sure all app dependencies are configured to install in the system context.
151
-
- Azure Virtual Desktop RemoteApp and MSIX app attach are not currently supported in Microsoft Endpoint Manager.
151
+
- Azure Virtual Desktop RemoteApp and MSIX app attach are not currently supported in Microsoft Intune.
152
152
153
153
## Script deployment
154
154
@@ -182,20 +182,20 @@ The following Windows 10 or Windows 11 desktop device remote actions are not sup
182
182
183
183
## Retirement
184
184
185
-
Deleting VMs from Azure will leave orphaned device records in Microsoft Endpoint Manager. They will be automatically cleaned up according to the cleanup rules configured for the tenant.
185
+
Deleting VMs from Azure will leave orphaned device records in the Microsoft Endpoint Manager admin center. They will be automatically cleaned up according to the cleanup rules configured for the tenant.
186
186
187
187
## Security baselines
188
188
189
189
Security baselines are not available for Windows 10 or Windows 11 Enterprise multi-session at this time. We recommend that you review the [Available security baselines](../protect/security-baselines.md) and configure the recommended policies and values in the [Settings catalog](../configuration/settings-catalog.md).
190
190
191
191
## Additional configurations which are not supported on Windows 10 or Windows 11 Enterprise multi-session VMs
192
192
193
-
Out of Box Experience (OOBE) enrollment isn't supported for Window 10 Enterprise multi-session. This restriction means that:
193
+
Out of Box Experience (OOBE) enrollment isn't supported for Window 10 or Windows 11 Enterprise multi-session. This restriction means that:
194
194
195
195
- Windows Autopilot and Commercial OOBE aren't supported.
196
196
- Enrollment status page isn’t supported.
197
197
198
-
Windows 10 or Windows 11 Enterprise multi-session managed by Microsoft Endpoint Manager is not currently supported for US Government Community (GCC), GCC High, DoD, or China.
198
+
Windows 10 or Windows 11 Enterprise multi-session managed by Microsoft Intune is not currently supported for US Government Community (GCC), GCC High, DoD, or China.
199
199
200
200
## Troubleshooting
201
201
@@ -205,7 +205,7 @@ The following sections provide troubleshooting guidance for common issues.
|Enrollment of hybrid Azure AD joined virtual machine fails|<ul><li>Auto-enrollment is configured to use user credentials. Windows 10 or Windows 11 Enterprise multi-session virtual machines must be enrolled using device credentials.<li>The Azure Virtual Desktop agent you’re using must be version 2944.1400 or later.<li>You have more than one MDM provider, which is not supported.<li>Windows 10 or Windows 11 Enterprise multi-session VM is configured outside of a host pool. Microsoft Endpoint Manager only supports VMs provisioned as part of a host pool.<li>The Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
208
+
|Enrollment of hybrid Azure AD joined virtual machine fails|<ul><li>Auto-enrollment is configured to use user credentials. Windows 10 or Windows 11 Enterprise multi-session virtual machines must be enrolled using device credentials.<li>The Azure Virtual Desktop agent you’re using must be version 2944.1400 or later.<li>You have more than one MDM provider, which is not supported.<li>Windows 10 or Windows 11 Enterprise multi-session VM is configured outside of a host pool. Microsoft Intune only supports VMs provisioned as part of a host pool.<li>The Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
209
209
|Enrollment of Azure AD joined virtual machine fails|<ul><li>The Azure Virtual Desktop agent you’re using is not updated. The agent must be version 2944.1400 or above.<li>Azure Virtual Desktop host pool was not created through the Azure Resource Manager template.|
0 commit comments