Forum Discussion
Azure Virtual Desktop - Problems Attempting Locked down Exam Environment
Update #2
Well.... I'm so very close. Just one piece isn't working. Hopefully if you are reading this, might lend a suggestion.
The entire desktop is locked down.
- I've blocked internet access, except for the couple of sites I need
- I've blocked the integrated experience through all Microsoft apps
- Blocked OneDrive
- I've blocked the windows apps Miscorsoft Store, Microsoft 365 (CoPilot) and Outlook(new)
But what isn't working, is that it's keeping a local profile on the server\workstation. It's not using FSLogix, but a local profile is kept after the user signs out. And I want it to be deleted once they sign out, or the server reboots.
When a user logs into AVD, they are given access to which ever AVD is available to them. In this example, user logs onto Server#2 and is able to save a Word document to the desktop. When they are done, they sign out. If the user comes back another time they may be on Server#6. But if they are lucky enough to log back into Server#2 - the file they left on the desktop is still there.
There is a GPO setting
Computer -> Admin -> System\User Profiles
Delete user profiles older than a specified number of days on system restart -> (set number to 1)
I would leave the device running over the weekend, come back and restart the server - profile is still there with the document on the desktop.
Any thoughts?