Forum Discussion
Kam_VedBrat
Mar 02, 2021Former Employee
Windows Virtual Desktop Announcements at Microsoft Ignite
We hope you are all enjoying the https://myignite.microsoft.com/home conference. Here are some announcements on Windows Virtual Desktop that you will be hearing during the event.
Azure Moni...
Philip_doITflex
Mar 04, 2021Copper Contributor
Quentin Gerlach it is extremely easy to Deploy and integrate AADDS for your session hosts and Azure Files enrolment. Additional cost, yes $100/month for the smallest SKU that will work for a several hundred users environment. SSO option with AD-connect was around for a few months now, also really easy to implement, have a look.
Mar 04, 2021
Again, ease isn’t the problem. The problem is that one is in essence going backwards - going to the cloud only, and now embracing legacy methods of domain authentication. And as others have pointed out, this comes with some large caveats.
As for SSO for WVD, as far as I’m aware, this is only supported for AD-FS environments - https://docs.microsoft.com/en-us/answers/questions/35827/single-sign-on-with-windows-virtual-desktop-for-of.html If you have a MS doc link or something describing setup of SSO for WVD via PTA/PHS, please share - that would be a great help.
As for SSO for WVD, as far as I’m aware, this is only supported for AD-FS environments - https://docs.microsoft.com/en-us/answers/questions/35827/single-sign-on-with-windows-virtual-desktop-for-of.html If you have a MS doc link or something describing setup of SSO for WVD via PTA/PHS, please share - that would be a great help.
- Philip_doITflexMar 04, 2021Copper ContributorCompletely agree, the option of AAD as the only Identity source should be available for WVD.
As per the end-to-end SingleSO it is not supported: https://docs.microsoft.com/en-us/azure/virtual-desktop/authentication#single-sign-on-sso
SameSO functionality with both PTA/PHS and saving credentials on the client provides the most friction-free functionality. Some colleagues resort to ADFS just to ensure on-prem DC's authenticate users and my point was that for SameSO Pass-Through is often a better option.