Insider Preview: Single sign-on and passwordless authentication for Azure Virtual Desktop

Microsoft

Today we’re announcing the Insider preview for enabling an Azure AD-based single sign-on experience and support for passwordless authentication, using Windows Hello and security devices (like FIDO2 keys). With this preview, you can now:

  • Enable a single sign-on experience to Azure AD-joined and Hybrid Azure AD-joined session hosts
  • Use passwordless authentication to sign in to the host using Azure AD
  • Use passwordless authentication inside the session
  • Use third-party Identity Providers (IdP) that integrate with Azure AD to sign in to the host

 

Getting started

This new functionality is currently available in Insider builds of Windows 11 22H2, available in the Azure Gallery when deploying new session hosts in a host pool.

  • Want a quick overview of the new functionality? Watch this intro video on Azure Academy!
  • To get started with single sign-on, follow the instructions to Configure single sign-on which will guide you in enabling the new authentication protocol.
  • To start using Windows Hello and FIDO2 keys inside the session, follow the instructions for In-session passwordless authentication to use the new WebAuthn redirection functionality.
  • Learn more about the supported authentication methods supported by Azure Virtual Desktop, including single sign-on on our Identities and authentication page.

 

Stay tuned for news about the upcoming public preview which will add support for Windows 10 and current Windows 11 hosts.

23 Replies

@David Belanger , do you know if there are any updates about the SSO for Azure Virtual Desktop, according to the popups the user gets from every AVD servers " You are attempting to connect to a remote devices with the following details: <AVD-servername>

 

I hope this is GA soon and fixed without all the prompts.

 

Thanks Gertjan van de Kolk

@gkolk001 Thank you for reaching out. The ability to hide that dialog for all AVD hosts is one of the 2 remaining items we are fixing before we declare GA.

@David Belanger thanks for the explanation. I hope this will be soon GA.

 

Kind regards, Gertjan