Skip to content

Commit a37a37d

Browse files
author
Angela Fleischmann
authored
Merge pull request #6814 from MicrosoftDocs/main
Publish 02/15/2022 3:30 PM PT
2 parents 9efa228 + adbe438 commit a37a37d

3 files changed

Lines changed: 130 additions & 3 deletions

File tree

windows-365/enterprise/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,8 @@ items:
1313
items:
1414
- name: Architecture
1515
href: architecture.md
16+
- name: Identity and authentication
17+
href: identity-authentication.md
1618
- name: Lifecycle
1719
href: lifecycle.md
1820
- name: Provisioning

windows-365/enterprise/architecture.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -88,6 +88,8 @@ When configuring Cloud PCs to use Azure AD Join, Azure AD provides:
8888
- The domain join mechanism for the Cloud PCs.
8989
- User authentication for RDP connections.
9090

91+
For more information on how the identity services impact the deployment, management, and usage of Cloud PCs, see [identity and authentication](identity-authentication.md).
92+
9193
### Azure AD
9294

9395
Azure AD provides user authentication and authorization for both the Windows 365 web portal and for the Remote Desktop client apps. Both support modern authentication, which means Azure AD Conditional Access can be integrated to provide:
@@ -104,13 +106,13 @@ For more information on how to use Azure AD Conditional Access with Windows 365,
104106

105107
### Active Directory Domain Services
106108

107-
Windows 365 Cloud PCs can be either Hybrid azure AD joined or Azure AD Joined. When using Hybrid Azure AD Join, Cloud PCs must domain join to an AD DS domain. This domain must be synchronized with Azure AD. The domain’s domain controllers may be hosted in Azure or on-premises. If hosted on-premises, connectivity must be established from Azure to the on-premises environment. The connectivity can be in the form of [Azure Express Route](/azure/architecture/reference-architectures/hybrid-networking/expressroute) or a [site-to-site VPN](/azure/architecture/reference-architectures/hybrid-networking/vpn). For more information on establish hybrid network connectivity, see [implement a secure hybrid network](/azure/architecture/reference-architectures/dmz/secure-vnet-dmz). The connectivity must allow communication from the Cloud PCs to the domain controllers required by Active Directory. For more information, see [Configure firewall for AD domain and trusts](/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts).
109+
Windows 365 Cloud PCs can be either Hybrid Azure AD joined or Azure AD Joined. When using Hybrid Azure AD Join, Cloud PCs must domain join to an AD DS domain. This domain must be synchronized with Azure AD. The domain’s domain controllers may be hosted in Azure or on-premises. If hosted on-premises, connectivity must be established from Azure to the on-premises environment. The connectivity can be in the form of [Azure Express Route](/azure/architecture/reference-architectures/hybrid-networking/expressroute) or a [site-to-site VPN](/azure/architecture/reference-architectures/hybrid-networking/vpn). For more information on establish hybrid network connectivity, see [implement a secure hybrid network](/azure/architecture/reference-architectures/dmz/secure-vnet-dmz). The connectivity must allow communication from the Cloud PCs to the domain controllers required by Active Directory. For more information, see [Configure firewall for AD domain and trusts](/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts).
108110

109111
## "Hosted on behalf of" architecture
110112

111113
The "hosted on behalf of" architecture lets Microsoft services, after they’re delegated appropriate and scoped permissions to a virtual network by a subscription owner, attach hosted Azure services to a customer subscription. This connectivity model lets a Microsoft service provide software-as-a-service and user licensed services as opposed to standard consumption-based services.
112114

113-
All Cloud PC connectivity is provided by the virtual network interface card. The "hosted on behalf of" architecture means that the Cloud PCs exists in the subscription owned by Microsoft. Therefore, Microsoft incurs the costs for running and managing this infrastructure.
115+
All Cloud PC connectivity is provided by the virtual network interface card. The "hosted on behalf of" architecture means that the Cloud PCs exist in the subscription owned by Microsoft. Therefore, Microsoft incurs the costs for running and managing this infrastructure.
114116

115117
Windows 365 manages the capacity and in-region availability in the Windows 365 subscriptions. Windows 365 determines the size and type of VM based on the [license](cloud-pc-size-recommendations.md) you [assign to the user](assign-licenses.md). Windows 365 determines the Azure region to host your Cloud PCs in based on the virtual network you select when [creating an on-prem network connection](create-on-premises-network-connection.md).
116118

@@ -143,4 +145,4 @@ Windows 365 Cloud PCs don't support third-party connection brokers.
143145
<!-- ########################## -->
144146
## Next steps
145147

146-
[Learn about the Cloud PC lifecycle](lifecycle.md).
148+
[Learn about Windows 365 identity and authentication](identity-authentication.md).
Lines changed: 123 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,123 @@
1+
---
2+
# required metadata
3+
title: Windows 365 identity and authentication
4+
titleSuffix:
5+
description: Windows 365 identity and authentication
6+
keywords:
7+
author: ErikjeMS
8+
ms.author: erikje
9+
manager: dougeby
10+
ms.date: 02/11/2022
11+
ms.topic: overview
12+
ms.service: cloudpc
13+
ms.subservice:
14+
ms.localizationpriority: high
15+
ms.technology:
16+
ms.assetid:
17+
18+
# optional metadata
19+
20+
#ROBOTS:
21+
#audience:
22+
23+
ms.reviewer: chrimo
24+
ms.suite: ems
25+
search.appverid: MET150
26+
#ms.tgt_pltfrm:
27+
ms.custom: intune-azure; get-started
28+
ms.collection: M365-identity-device-management
29+
---
30+
31+
# Windows 365 identity and authentication
32+
33+
A Cloud PC user's identity defines which access management services manage that user and Cloud PC. This identity defines:
34+
35+
- What types of Cloud PCs the user has access to.
36+
- What types of non-Cloud PC resources the user has access to.
37+
38+
A device can also have an identity which is determined by its join type to Azure Active Directory (Azure AD). For a device, the join type defines:
39+
40+
- If the device requires line of sight to a domain controller.
41+
- How the device is managed.
42+
- How users authenticate to the device.
43+
44+
## Identity types
45+
46+
There are two identity types:
47+
48+
- **[Hybrid identity](/azure/active-directory/hybrid/whatis-hybrid-identity)**: Users or devices that are created in on-premises Windows Server Active Directory, then synchronized to Azure AD.
49+
- **Cloud-only identity**: Users or devices that are created and only exist in Azure AD.
50+
51+
## Device join types
52+
53+
There are two join types that you can select from when [provisioning a Cloud PC](provisioning.md):
54+
55+
- **[Hybrid Azure AD Join](/azure/active-directory/devices/concept-azure-ad-join-hybrid)**: If you choose this join type, Windows 365 will join your Cloud PC to the Windows Server Active Directory domain you provide. Then, if your organization is properly [configured for Hybrid Azure AD Join](/azure/active-directory/devices/howto-hybrid-azure-ad-join), the device will be synchronized to Azure AD.
56+
- **[Azure AD Join](/azure/active-directory/devices/concept-azure-ad-join)**: If you choose this join type, Windows 365 will join your Cloud PC directly to Azure AD.
57+
58+
59+
Below is a table showing key capabilities or requirements based on the selected join type:
60+
61+
|Capability or requirement|Hybrid Azure AD Join|Azure AD Join|
62+
|-|-|-|
63+
|Azure subscription|Required|Optional|
64+
|Azure virtual network with line of sight to the domain controller|Required|Optional|
65+
|User identity type supported for login|Hybrid users only|Hybrid users or cloud-only users|
66+
|Policy management|Group Policy Objects (GPO) or Intune MDM|Intune MDM only|
67+
|Windows Hello for Business login supported|Yes, and the connecting device must have line of sight to the domain controller through the direct network or a VPN|Yes|
68+
69+
## Authentication
70+
71+
To successfully access a Cloud PC, a user must authenticate, in turn, with both:
72+
73+
- The Windows 365 service.
74+
- The Cloud PC.
75+
76+
>[!NOTE]
77+
>Single sign-on (defined as a single authentication prompt that can satisfy both the Windows 365 service authentication and Cloud PC authentication) is not supported at this time.
78+
79+
>[!IMPORTANT]
80+
>In order for authentication to work properly, the user's local machine must also be able to access the URLs in the [Remote Desktop clients](/azure/virtual-desktop/safe-url-list#remote-desktop-clients) section of the [Azure Virtual Desktop required URL list](/azure/virtual-desktop/safe-url-list).
81+
82+
### Windows 365 service authentication
83+
84+
Users must authenticate with the Windows 365 service when:
85+
86+
- They access [windows365.microsoft.com](https://windows365.microsoft.com).
87+
- They navigate to the URL that maps directly to their Cloud PC.
88+
- They use a [Remote Desktop client](/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients to list their Cloud PCs.
89+
90+
This authentication triggers an Azure Active Directory prompt, allowing any credential type that is supported by both Azure Active Directory and your OS.
91+
92+
### Cloud PC authentication
93+
94+
Users must authenticate with the Windows 365 service when:
95+
96+
- They navigate to the URL that maps directly to their Cloud PC.
97+
- They use a [Remote Desktop client](/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients) to connect to their Cloud PC.
98+
99+
>[!NOTE]
100+
>If a user launches the web browser URL that maps directly to their Cloud PC, they will encounter the Windows 365 service authentication first, then encounter the Cloud PC authentication.
101+
102+
The following credential types are supported for Cloud PC authentication:
103+
- Windows desktop client
104+
- Username and password
105+
- Smartcard
106+
- [Windows Hello for Business certificate trust](/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust)
107+
- [Windows Hello for Business key trust with certificates](/windows/security/identity-protection/hello-for-business/hello-deployment-rdp-certs)
108+
- Windows store client
109+
- Username and password
110+
- Web client
111+
- Username and password
112+
- Android
113+
- Username and password
114+
- iOS
115+
- Username and password
116+
- macOS
117+
- Username and password
118+
119+
120+
<!-- ########################## -->
121+
## Next steps
122+
123+
[Learn about the Cloud PC lifecycle](lifecycle.md).

0 commit comments

Comments
 (0)