WVD and Intune / Endpoint Manager

%3CLINGO-SUB%20id%3D%22lingo-sub-2251118%22%20slang%3D%22de-DE%22%3EWVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2251118%22%20slang%3D%22de-DE%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3EI%20am%20using%20a%20pure%20cloud%20environment%20(Azure%20AD%20-%20Azure%20AD%20Domain%20Services%20-%20Windows%20Virtual%20Desktop).%20How%20can%20I%20use%20Intune%20%2F%20Endpoint%20Manater%20for%20the%20sessions%20hosts%20in%20the%20environment%3F%3C%2FP%3E%3CP%3EThanks%20a%20lot%20%3CBR%20%2F%3E%20Stefan%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2251420%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2251420%22%20slang%3D%22en-US%22%3EYou%20can't%20at%20all%20if%20your%20using%20windows%2010%20multi-session%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fwindows-virtual-desktop%23windows-10-enterprise-multi-session%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fwindows-virtual-desktop%23windows-10-enterprise-multi-session%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2256220%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2256220%22%20slang%3D%22en-US%22%3EMicrosoft%20-%20are%20there%20plans%20to%20support%20management%20of%20WVD%20Windows%2010%20Multi-Session%20through%20Intune%2FEndpoint%20Manager%3F%20We%20have%20embraced%20the%20modern%20desktop%20and%20deployed%20Azure%20AD%20joined%20endpoints%20to%20all%20users%2C%20locked%20down%20using%20Intune%20security%20baselines.%20It%20seems%20like%20a%20lot%20of%20wasted%20effort%20to%20have%20to%20go%20back%20to%20traditional%20group%20policy%20to%20set%20up%20a%20consistent%20user%20experience%20on%20WVD...%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2257705%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2257705%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F142465%22%20target%3D%22_blank%22%3E%40lukewilcock%3C%2FA%3E%26nbsp%3BYes.%20See%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fin-development%23device-management%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fin-development%23device-management%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2258507%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2258507%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F5090%22%20target%3D%22_blank%22%3E%40David%20Schrag%3C%2FA%3E%26nbsp%3B-%20thanks%20for%20the%20link.%20Looks%20like%20the%20feature%20is%20scheduled%20for%20release%20in%20May%202021%20according%20to%20the%20roadmap.%20Fingers%20crossed!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2263111%22%20slang%3D%22es-ES%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2263111%22%20slang%3D%22es-ES%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F98746%22%20target%3D%22_blank%22%3E%40Stefan%20Kie-ig%3C%2FA%3E%20you%20can%20use%20auto-enrollment%20configured%20in%20your%20AAD%20server%20in%20the%20cloud%2C%20check%20my%20post%20%3CA%20href%3D%22https%3A%2F%2Fwww.deployment.mx%2Fenroll-windows-virtual-desktop-a-microsoft-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EEnroll%20Windows%20Virtual%20Desktop%20to%20Microsoft%20Intune%20%E2%80%93%20Deployment%20MX%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2263272%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2263272%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F431380%22%20target%3D%22_blank%22%3E%40DeploymentMX%3C%2FA%3E%26nbsp%3BAD%20Connect%20does%20not%20work%20for%20me%20because%20I%20do%20not%20have%20an%20onPremise%20domain.%3CBR%20%2F%3EThe%20domain%20functionality%20is%20provided%20by%20the%20Azure%20AD%20Domain%20Service.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2263351%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2263351%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F98746%22%20target%3D%22_blank%22%3E%40Stefan%20Kie%C3%9Fig%3C%2FA%3E%26nbsp%3B-%20I%20think%20the%20only%20(supported)%20way%20would%20be%20to%20spin%20up%20a%20traditional%20domain%20controller%2C%20e.g.%20in%20Azure%20so%20not%20on%20premise%20as%20such%2C%20install%20AD%20Connect%20and%20go%20from%20there.%20We%20had%20to%20retain%20an%20'on-premise'%20domain%20controller%20for%20a%20line%20of%20business%20app.%20It%20was%20frustrating%20at%20the%20time%2C%20but%20proving%20useful%20for%20WVD%20and%20some%20other%20use%20cases.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2263898%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2263898%22%20slang%3D%22en-US%22%3EThere%20are%20too%20many%20limitations%20with%20only%20using%20AADS%2C%20in%20my%20opinion%20its%20really%20only%20good%20for%20very%20simple%20small%20business%20situations.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2394598%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20and%20Intune%20%2F%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2394598%22%20slang%3D%22en-US%22%3Esame%20for%20us.%20We%20moved%20our%20clients%20to%20cloud%20only%20azure%20ad%20join%20and%20I%20was%20excited%20about%20the%20intune%20what's%20new%20this%20week%20as%20wvd%20windows%2010%20multi%20user%20is%20in%20public%20preview%20now.%20But%20at%20a%20closer%20look%20we%20still%20need%20an%20hybrid%20join%20for%20wvd%20machines%20as%20a%20requierement.%20Are%20there%20plans%20in%20near%20future%20to%20have%20cloud%20only%20aad%20joined%20wvds%3F%3C%2FLINGO-BODY%3E
Contributor

Hello,

I am using a pure cloud environment (Azure AD - Azure AD Domain Services - Windows Virtual Desktop). How can I use Intune / Endpoint Manater for the sessions hosts in the environment?

Thanks a lot
Stefan

12 Replies
Microsoft - are there plans to support management of WVD Windows 10 Multi-Session through Intune/Endpoint Manager? We have embraced the modern desktop and deployed Azure AD joined endpoints to all users, locked down using Intune security baselines. It seems like a lot of wasted effort to have to go back to traditional group policy to set up a consistent user experience on WVD...

@David Schrag - thanks for the link. Looks like the feature is scheduled for release in May 2021 according to the roadmap. Fingers crossed!

How do I get the machine into Azure AD?

I do not have an AD Connect running because it is a cloud-only environment. The domain services are provided via Azure AD Domain Services.

@Stefan Kießig you can use auto-enrollment configured in your AAD server in the cloud, check my post Enroll Windows Virtual Desktop a Microsoft Intune – Deployment MX

@DeploymentMX AD Connect does not work for me because I do not have an onPremise domain.
The domain functionality is provided by the Azure AD Domain Service.

@Stefan Kießig - I think the only (supported) way would be to spin up a traditional domain controller, e.g. in Azure so not on premise as such, install AD Connect and go from there. We had to retain an 'on-premise' domain controller for a line of business app. It was frustrating at the time, but proving useful for WVD and some other use cases.  

There are too many limitations with only using AADS, in my opinion its really only good for very simple small business situations.
same for us. We moved our clients to cloud only azure ad join and I was excited about the intune what's new this week as wvd windows 10 multi user is in public preview now. But at a closer look we still need an hybrid join for wvd machines as a requierement. Are there plans in near future to have cloud only aad joined wvds?

@lukewilcock Hey Luke, But why aren't you are using Group policies for those devices.. I am just trying to understand whats wrong with on premise policy for those WVD devices and people are going with Intune policies. Apart from the external devices? I have a customer who is looking for managing WVD devices and they have on premise group policies. 

@AK_MS - there isn't anything wrong with using Group Policy. Indeed it would make sense if that is your main method for securing your environments. We made a decision a couple of years ago to transition to Azure AD joined endpoints fully managed by Intune. We no longer use Group Policy and were very keen to avoid having to re-invent the wheel and try to mirror settings we already have set up in Microsoft Endpoint Manager.