SOLVED

Windows Hello support available with our Remote Desktop client for Windows!

%3CLINGO-SUB%20id%3D%22lingo-sub-1551122%22%20slang%3D%22en-US%22%3EWindows%20Hello%20support%20available%20with%20our%20Remote%20Desktop%20client%20for%20Windows!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1551122%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22lia-message-body%20lia-component-message-view-widget-body%20lia-component-body-signature-highlight-escalation%20lia-component-message-view-widget-body-signature-highlight-escalation%22%3E%3CDIV%20class%3D%22lia-message-body-content%22%3E%3CP%3EHello%2C%20can%20I%20able%20to%20use%20latest%20WVD%20(%20Windows%20virtual%20Desktop)%26nbsp%3B%20image%20for%20pass%20wordless%20login%2C%20for%20using%20FIDO2%20device%2C%20PIN%20and%20smart%20card%20%3F.%20Or%20RDP%20for%20windows%20will%20support%20WVD%202004%20build%20%3F%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1554003%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20support%20available%20with%20our%20Remote%20Desktop%20client%20for%20Windows!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1554003%22%20slang%3D%22en-US%22%3ENo%20one%20from%20Microsoft%20is%20responding%20for%20this%20issue%20for%20WVD%20PASSWORDLESS%20LOGIN%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1555344%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20support%20available%20with%20our%20Remote%20Desktop%20client%20for%20Windows!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1555344%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F741911%22%20target%3D%22_blank%22%3E%40Deepu_k%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20not%20100%25%20sure%20about%20FIDO2%20devices%2C%20but%20PIN%20and%2For%20certificate%20are%20working%20in%20our%20WVD%20environment.%20It%20is%20important%20to%20point%20out%2C%20that%20for%20SSO%2C%20you%20need%20to%20deploy%20ADFS%20infrastructure%20(even%20in%20the%20Spring%202020%20Update%20of%20WVD).%20The%20product%20group%20is%20working%20on%20full%20Azure%20AD%20only%20support%20(without%20ADFS)%2C%20but%20it%20is%20not%20available%20yet.%3C%2FP%3E%3CP%3ENaturally%2C%20regardless%20of%20what%20OS%20image%20you%20use%20for%20your%20host%20pool%2C%20you%20need%20to%20domain%20join%20your%20hosts%20to%20Active%20Directory.%3C%2FP%3E%3CP%3EPlease%20note%2C%20I%20am%20not%20representing%20WVD%20Product%20Group%20here%2C%20so%20this%20isn't%20an%20official%20statement%2C%20I%20just%20share%20my%20knowledge%20and%20experience.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EDavid%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1555366%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20support%20available%20with%20our%20Remote%20Desktop%20client%20for%20Windows!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1555366%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20You%2C%20If%20i%20deploy%20ADFS%20server%20in%20the%20same%20DC%20machine%20%2Cwill%20it%20be%20sufficient%20for%20deploying%20WVD%20host%20pool%20which%20are%20connected%20to%20this%20DC%20(domain%20controller%20).%3C%2FP%3E%3CP%3EIf%20I%20add%20ADFS%20to%20DC%20can%20I%20able%20to%20see%20SSO%20option%20for%20WVD%20remote%20desktop%20client%20or%20RDweb%20client%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F10907%22%20target%3D%22_blank%22%3E%40David%20Pazdera%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1555404%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20support%20available%20with%20our%20Remote%20Desktop%20client%20for%20Windows!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1555404%22%20slang%3D%22en-US%22%3E%3CP%3EI%20would%20discourage%20you%20from%20deploying%20ADFS%20on%20your%20domain%20controller%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F741911%22%20target%3D%22_blank%22%3E%40Deepu_k%3C%2FA%3E%26nbsp%3B.%20Moreover%2C%20ADFS%20topology%20has%20a%20proxy%20component%20(ADFS%20Proxy)%20that%20needs%20to%20be%20exposed%20to%20the%20Internet%2C%20so%20your%20users%20can%20reach%20it%20from%20anywhere%2C%20and%20this%20is%20definitely%20something%20you%20should%20not%20do%20to%20your%20AD%20domain%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20review%20the%20documentation%20about%20ADFS%20%2F%20SSO%20configuration%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-fed-whatis%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-fed-whatis%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1555408%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20support%20available%20with%20our%20Remote%20Desktop%20client%20for%20Windows!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1555408%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%2C%20Can%20you%20please%20suggest%20me%20a%20scenario%20so%20that%20I%20can%20use%20pass%20wordless%20login%20through%20Windows%20Virtual%20Desktop%20-WVD%26nbsp%3B%20by%20using%26nbsp%3B%20Remote%20Desktop%20Client%20App%20or%20RDWeb%20link%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F10907%22%20target%3D%22_blank%22%3E%40David%20Pazdera%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hello, can I able to use latest WVD ( Windows virtual Desktop)  image for pass wordless login, for using FIDO2 device, PIN and smart card ?. Or RDP for windows will support WVD 2004 build ?

5 Replies
Highlighted
Best Response confirmed by Deepu_k (Occasional Contributor)
Solution
No one from Microsoft is responding for this issue for WVD PASSWORDLESS LOGIN
Highlighted

Hi @Deepu_k ,

 

I'm not 100% sure about FIDO2 devices, but PIN and/or certificate are working in our WVD environment. It is important to point out, that for SSO, you need to deploy ADFS infrastructure (even in the Spring 2020 Update of WVD). The product group is working on full Azure AD only support (without ADFS), but it is not available yet.

Naturally, regardless of what OS image you use for your host pool, you need to domain join your hosts to Active Directory.

Please note, I am not representing WVD Product Group here, so this isn't an official statement, I just share my knowledge and experience.

 

Regards,

David

Highlighted

Thank You, If i deploy ADFS server in the same DC machine ,will it be sufficient for deploying WVD host pool which are connected to this DC (domain controller ).

If I add ADFS to DC can I able to see SSO option for WVD remote desktop client or RDweb client @David Pazdera 

Highlighted

I would discourage you from deploying ADFS on your domain controller @Deepu_k . Moreover, ADFS topology has a proxy component (ADFS Proxy) that needs to be exposed to the Internet, so your users can reach it from anywhere, and this is definitely something you should not do to your AD domain :)

 

Please review the documentation about ADFS / SSO configuration: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-whatis

 

Highlighted

Thank you, Can you please suggest me a scenario so that I can use pass wordless login through Windows Virtual Desktop -WVD  by using  Remote Desktop Client App or RDWeb link @David Pazdera