Home

Lock down of Windows Virtual desktop

%3CLINGO-SUB%20id%3D%22lingo-sub-565892%22%20slang%3D%22en-US%22%3ELock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-565892%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20a%20possibility%20of%20locking%20down%20of%20Azure%20Windows%20virtual%20desktop%20to%20be%20accessible%20from%20Corporate%20office%20%3F%3C%2FP%3E%3CP%3EIs%20conditional%20access%20supported%20and%20if%20yes%2C%20how%20to%20enable%20it%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-570088%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-570088%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F341882%22%20target%3D%22_blank%22%3E%40Jasmer%3C%2FA%3E%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3EYes%2C%20because%20Windows%20Virtual%20Desktop%20is%20a%20registered%20application%20in%20Azure%20AD%20you%20can%20configure%20conditional%20access.%20Follow%20the%20steps%20here%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fapp-based-mfa%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fapp-based-mfa%3C%2FA%3E)%20and%20use%20the%20%E2%80%9CWindows%20Virtual%20Desktop%20Client%E2%80%9D%20app.%E2%80%9D%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-833449%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-833449%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F139744%22%20target%3D%22_blank%22%3E%40Eva%20Seydl%3C%2FA%3E%26nbsp%3Bsomehow%20I%20can't%20get%20it%20to%20work%2C%20configured%20everything%20but%20neither%20the%20app%20nor%20the%20webinterface%20are%20blocking%20me%20from%20acessing%20with%20my%20non-MFA%20account%2C%20anything%20I%20am%20missing%20here%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-839478%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-839478%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F380065%22%20target%3D%22_blank%22%3E%40A_priori_superior%3C%2FA%3E%26nbsp%3B%3A%20Can%20you%20clarify%20what%20you%20mean%20by%20%22with%20my%20non-MFA%20account%22%3F%20Has%20this%20account%20never%20required%20MFA%3F%20I'm%20not%20sure%20of%20the%20direct%20interaction%2C%20but%20you%20may%20need%20to%20enable%20MFA%20for%20this%20user%20first%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fhowto-mfa-userstates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fauthentication%2Fhowto-mfa-userstates%3C%2FA%3E%26nbsp%3B.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-839487%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-839487%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F305776%22%20target%3D%22_blank%22%3E%40christianmontoya%3C%2FA%3EThis%20account%20has%20never%20been%20enabled%20for%20MFA%2C%20correct.%20But%20that's%20the%20whole%20reason%20to%20set%20a%20conditional%20access%20policy%2C%20to%20prevent%20user%20not%20meeting%20the%20criteria%2C%20in%20this%20case%20having%20MFA%20enabled%2C%20to%20access%20certain%20resources.%20If%20I%20enable%20MFA%20for%20the%20users%20manually%20or%20automatically%2C%20there%20is%20no%20reason%20to%20define%20a%20conditional%20access%20rule%20for%20certain%20apps.%3CBR%20%2F%3E%3CBR%20%2F%3EBtw%20it's%20working%20for%20other%20applications%2C%20but%20not%20WVD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-839721%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-839721%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F380065%22%20target%3D%22_blank%22%3E%40A_priori_superior%3C%2FA%3E%26nbsp%3B%3A%20It's%20working%20on%20other%20applications%20by%20individually%20listing%20them%2C%20like%20you%20tried%20with%26nbsp%3B%3CSTRONG%3EWindows%20Virtual%20Desktop%20Client%3C%2FSTRONG%3E%3F%20Can%20you%20add%26nbsp%3B%3CSTRONG%3EWindows%20Virtual%20Desktop%3C%2FSTRONG%3Eto%20the%20list%20of%20apps%3F%20Or%20Replace%20the%20client%20with%20this%20one%2C%20and%20let%20us%20know%20if%20that%20works%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-843719%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-843719%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F305776%22%20target%3D%22_blank%22%3E%40christianmontoya%3C%2FA%3EAdding%20WVD%20as%20well%20did%20the%20trick%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-844859%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-844859%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F380065%22%20target%3D%22_blank%22%3E%40A_priori_superior%3C%2FA%3E%26nbsp%3B%3A%20Perfect!%20If%20you%20actually%20replace%20the%20%22Windows%20Virtual%20Desktop%20Client%22%20and%20only%20have%20%22Windows%20Virtual%20Desktop%22%2C%20does%20that%20also%20work%20for%20you%3F%20This%20is%20the%20catch-all%20approach%20and%20likely%20what%20we%20will%20be%20documenting%20on%20our%20docs%20site.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-846553%22%20slang%3D%22en-US%22%3ERe%3A%20Lock%20down%20of%20Windows%20Virtual%20desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-846553%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F305776%22%20target%3D%22_blank%22%3E%40christianmontoya%3C%2FA%3E%26nbsp%3BYes%20it%20did%20work%20with%20Windows%20Virtual%20Desktop%20only%20as%20well.%20Thanks%3C%2FP%3E%3C%2FLINGO-BODY%3E
Jasmer
New Contributor

Is there a possibility of locking down of Azure Windows virtual desktop to be accessible from Corporate office ?

Is conditional access supported and if yes, how to enable it?

8 Replies

@Jasmer Yes, because Windows Virtual Desktop is a registered application in Azure AD you can configure conditional access. Follow the steps here (https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/app-based-mfa) and use the “Windows Virtual Desktop Client” app.”

@Eva Seydl somehow I can't get it to work, configured everything but neither the app nor the webinterface are blocking me from acessing with my non-MFA account, anything I am missing here?

@A_priori_superior : Can you clarify what you mean by "with my non-MFA account"? Has this account never required MFA? I'm not sure of the direct interaction, but you may need to enable MFA for this user first: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates .

@christianmontoyaThis account has never been enabled for MFA, correct. But that's the whole reason to set a conditional access policy, to prevent user not meeting the criteria, in this case having MFA enabled, to access certain resources. If I enable MFA for the users manually or automatically, there is no reason to define a conditional access rule for certain apps.

Btw it's working for other applications, but not WVD.

@A_priori_superior : It's working on other applications by individually listing them, like you tried with Windows Virtual Desktop Client? Can you add Windows Virtual Desktop to the list of apps? Or Replace the client with this one, and let us know if that works?

@christianmontoyaAdding WVD as well did the trick :)

@A_priori_superior : Perfect! If you actually replace the "Windows Virtual Desktop Client" and only have "Windows Virtual Desktop", does that also work for you? This is the catch-all approach and likely what we will be documenting on our docs site.

@christianmontoya Yes it did work with Windows Virtual Desktop only as well. Thanks

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies