Windows Virtual Desktop Support for Trusted Launch

%3CLINGO-SUB%20id%3D%22lingo-sub-2206170%22%20slang%3D%22en-US%22%3EWindows%20Virtual%20Desktop%20Support%20for%20Trusted%20Launch%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2206170%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20excited%20to%20announce%20Windows%20Virtual%20Desktop%20support%20for%20Azure%20Trusted%20Launch!%20Trusted%20Launch%20is%20currently%20in%20Public%20Preview%2C%20and%20is%20a%20Gen2%20Azure%20VM%20with%20enhanced%20security%20features%20such%20as%20secure%20boot%2C%20vTPM%2C%20virtualization-based%20security%2C%20Windows%20Defender%20Credential%20Guard%2C%20and%20Hypervisor-Protected%20Code%20Integrity.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20capability%20to%20deploy%20a%20Trusted%20Launch%20VM%20through%20the%20host%20pool%20creation%20process%20has%20not%20been%20enabled%20yet.%20To%20try%20out%20Trusted%20Launch%20in%20WVD%2C%20you%20will%20need%20to%20deploy%20a%20Trusted%20Launch%20VM%20normally%20and%20then%20manually%20add%20the%20VM%20to%20your%20desired%20host%20pool%20through%20the%20following%20steps%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EGenerate%20a%20new%20registration%20key%20for%20your%20host%20pool%3C%2FLI%3E%0A%3CLI%3ERDP%20into%20your%20Trusted%20Launch%20VM%3C%2FLI%3E%0A%3CLI%3EDownload%20the%20Windows%20Virtual%20Desktop%20Agent%20and%20Windows%20Virtual%20Desktop%20Agent%20bootloader%20from%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fcreate-host-pools-powershell%23register-the-virtual-machines-to-the-windows-virtual-desktop-host-pool%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EInstall%20the%20Windows%20Virtual%20Desktop%20Agent%20on%20your%20VM%20and%20when%20prompted%20for%20the%20registration%20key%2C%20enter%20the%20one%20generated%20in%20step%201.%3C%2FLI%3E%0A%3CLI%3EInstall%20the%20Windows%20Virtual%20Desktop%20Agent%20bootloader%20on%20your%20VM.%3C%2FLI%3E%0A%3CLI%3EThe%20VM%20will%20now%20show%20up%20as%20a%20session%20host%20in%20your%20host%20pool.%20Sometimes%20the%20session%20host%20will%20show%20up%20as%20unavailable%20initially%2C%20this%20most%20likely%20means%20it's%20updating%20to%20the%20latest%20agent.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3EFor%20WVD's%20official%20support%20statement%20for%20Trusted%20Launch%2C%20please%20visit%20our%20documentation%20found%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fsecurity-guide%23windows-virtual-desktop-support-for-trusted-launch%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%20If%20you%20want%20to%20learn%20more%20about%20Trusted%20Launch%20and%20its%20various%20capabilities%2C%20documentation%20for%20Trusted%20Launch%20can%20be%20found%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-machines%2Ftrusted-launch%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

We're excited to announce Windows Virtual Desktop support for Azure Trusted Launch! Trusted Launch is currently in Public Preview, and is a Gen2 Azure VM with enhanced security features such as secure boot, vTPM, virtualization-based security, Windows Defender Credential Guard, and Hypervisor-Protected Code Integrity.

 

The capability to deploy a Trusted Launch VM through the host pool creation process has not been enabled yet. To try out Trusted Launch in WVD, you will need to deploy a Trusted Launch VM normally and then manually add the VM to your desired host pool through the following steps:

  1. Generate a new registration key for your host pool
  2. RDP into your Trusted Launch VM
  3. Download the Windows Virtual Desktop Agent and Windows Virtual Desktop Agent bootloader from here.
  4. Install the Windows Virtual Desktop Agent on your VM and when prompted for the registration key, enter the one generated in step 1.
  5. Install the Windows Virtual Desktop Agent bootloader on your VM.
  6. The VM will now show up as a session host in your host pool. Sometimes the session host will show up as unavailable initially, this most likely means it's updating to the latest agent.

For WVD's official support statement for Trusted Launch, please visit our documentation found here. If you want to learn more about Trusted Launch and its various capabilities, documentation for Trusted Launch can be found here.

0 Replies