Forum Discussion

Ronald van Ackooij's avatar
Ronald van Ackooij
Brass Contributor
Aug 31, 2021

Conditional Access per HostPool or RDP properties conditional on clients

Good day all,

I am struggling with the RDP properties of our different host pools. Corporate policy states that nothing should be able to be redirected from the local device. Which is fine and for the Full Desktop publishing we have configured this so on the host pool in RDP properties. However, now we have a separate host pool for a remote app. This remote I would only like to be able to connect to from the desktop host pool (nested) and not from the local device. As this is a Remote App the users need to interact with this application with the clipboard. 
So I want to know if there is a method, and if not, request a feature to make this possible. 
With kind regards,

3 Replies

  • chris1170's avatar
    chris1170
    Copper Contributor
    Did anyone find a solution/workaround for this? We have a similar scenario and need to implement different conditional access policies per host pool.
  • kramer314's avatar
    kramer314
    Copper Contributor
    Not currently supported at all, and (at least from whenever we've asked support/ TAM/ other contacts about this exact functionality over the past few months) doesn't seem like it's going to be a platform feature anytime soon. We have a very similar use case - would really, really like to be able to allow certain redirections if accessing AVD from a corporate/Intune-compliant device and blanket deny otherwise.

    We are running into a number of compliance considerations which start to become really hard to accommodate in a larger, more mixed, environment related to this.

    AVD seems like it would be prime use case for the new AAD Conditional Access Authentication Context functionality that's been in public preview for a few months ... haven't seen or heard anything about if there's any plans for AVD to support that any time soon.

Resources