SOLVED

Basic auth / redirect clipboard without drives / controlling logout timings of subscription

%3CLINGO-SUB%20id%3D%22lingo-sub-1840557%22%20slang%3D%22en-US%22%3EBasic%20auth%20%2F%20redirect%20clipboard%20without%20drives%20%2F%20controlling%20logout%20timings%20of%20subscription%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1840557%22%20slang%3D%22en-US%22%3E%3CP%3EHello.%20I'm%20new%20to%20WVD%20and%20to%20this%20forum.%20I%20have%20a%20few%20questions%20I%20hope%20you%20can%20help%20me%20with%20%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fhtml%2Fimages%2Femoticons%2Fsmile_40x40.gif%22%20alt%3D%22%3Asmile%3A%22%20title%3D%22%3Asmile%3A%22%20%2F%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EWe%20subscribe%20to%20the%20applications%20in%20Remote%20Desktop%20with%20modern%20authentication.%20But%20then%20when%20we%20start%20the%20first%20application%20everytime%20we%20get%20this%20(please%20see%20attached%20image).%20We%20can%20say%20remember%20my%20credentials%2C%20which%20makes%20it%20go%20away%2C%20but%20is%20it%20really%20normal%20for%20this%20oldschool%20prompt%20to%20show%20up%20in%20the%20first%20place%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3EWhen%20we%20redirect%20clipboard%20and%20disable%20the%20redirection%20of%20drives%2C%20it%20still%20redirects%20drives.%20We%20must%20disable%20clipboard%20redirection%20to%20not%20get%20the%20drives.%20We%20had%20a%20consultant%20which%20tried%20it%20in%20his%20demo%20environment%20and%20got%20the%20same%20behaviour.%20Is%20this%20really%20expected%3F%20Ideally%2C%20we%20want%20to%20be%20able%20to%20copy%2Fpaste%20text%20and%20nothing%20else.%20Is%20this%20possible%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3EHow%20do%20we%20control%20the%20logout%20timings%20of%20the%20Remote%20Desktop%20client%3F%20It%20seems%20that%20if%20we%20have%20a%20user%20log%20in%20(subscribe)%20and%20they%20leave%20their%20computer%20on%20they%20almost%20never%20have%20to%20login%20to%20that%20subscription%20again%3F%20Ideally%20we%20want%20it%20to%20require%20modern%20authentication%20with%20MFA%20daily.%3C%2FLI%3E%3C%2FOL%3E%3CP%3EThank%20you%20so%20much!%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fhtml%2Fimages%2Femoticons%2Fsmile_40x40.gif%22%20alt%3D%22%3Asmile%3A%22%20title%3D%22%3Asmile%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1840557%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Elogout%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eredirect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ERemote%20Desktop%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWVD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1845939%22%20slang%3D%22en-US%22%3ERe%3A%20Basic%20auth%20%2F%20redirect%20clipboard%20without%20drives%20%2F%20controlling%20logout%20timings%20of%20subscription%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1845939%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F164833%22%20target%3D%22_blank%22%3E%40Melmix%3C%2FA%3E%26nbsp%3BFor%20your%20first%20question%2C%20yes%20that%20is%20expected%20today%20as%20it's%20prompting%20for%20standard%20Active%20Directory%20credentials%20to%20sign%20in%20to%20the%20remote%20VM.%20This%20is%20similar%20to%20doing%20a%20manual%20RDP%20connecting%20to%20a%20remote%20system.%20We%20are%20working%20on%20functionality%20to%20improve%20this%20like%20supporting%20SSO%20using%20AD%20FS%20and%20eventually%20supporting%20AADJ%20VMs.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20the%20second%20question%2C%20this%20isn't%20expected.%20You%20should%20be%20able%20to%20disable%20drive%20redirection%20and%20leave%20clipboard%20redirection%20on.%20How%20are%20you%20disabling%20drive%20redirection%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20the%20prompting%20for%20MFA%20again%20on%20a%20daily%20basis%2C%20you%20can%20currently%20use%20the%20Sign%20In%20Frequency%20in%20AAD.%20Information%20can%20be%20found%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fset-up-mfa%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fset-up-mfa%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1847629%22%20slang%3D%22en-US%22%3ERe%3A%20Basic%20auth%20%2F%20redirect%20clipboard%20without%20drives%20%2F%20controlling%20logout%20timings%20of%20subscription%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1847629%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F217952%22%20target%3D%22_blank%22%3E%40David%20Belanger%3C%2FA%3E%26nbsp%3Bthank%20you%20for%20your%20response.%20Regarding%20the%20second%20question%2C%20I%20have%20attached%20a%20screenshot%20(pic2.png)%20of%20the%20setting.%20I%20also%20tried%20some%20stuff%20in%20Advanced%20RDP%20Properties%2C%20but%20with%20no%20effect.%20When%20I%20change%20something%20in%20the%20Device%20redirection%20tab%20it%20automatically%20reflects%20in%20the%20Advanced%20RDP%20Properties.%20It%20currently%20shows%20like%20pic3.png.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello. I'm new to WVD. I have a few questions I hope you can help me with :smile:

 

  1. We subscribe to the applications in Remote Desktop with modern authentication. But then when we start the first application everytime we get this (please see attached image). We can say remember my credentials, which makes it go away, but is it really normal for this oldschool prompt to show up in the first place?

  2. When we redirect clipboard and disable the redirection of drives, it still redirects drives. We must disable clipboard redirection to not get the drives. We had a consultant which tried it in his demo environment and got the same behaviour. Is this really expected? Ideally, we want to be able to copy/paste text and nothing else. Is this possible?

  3. How do we control the logout timings of the Remote Desktop client? It seems that if we have a user log in (subscribe) and they leave their computer on they almost never have to login to that subscription again? Ideally we want it to require modern authentication with MFA daily.

Thank you so much! :smile:

3 Replies
best response confirmed by Melmix (Occasional Contributor)
Solution

@Melmix For your first question, yes that is expected today as it's prompting for standard Active Directory credentials to sign in to the remote VM. This is similar to doing a manual RDP connecting to a remote system. We are working on functionality to improve this like supporting SSO using AD FS and eventually supporting AADJ VMs.

 

For the second question, this isn't expected. You should be able to disable drive redirection and leave clipboard redirection on. How are you disabling drive redirection?

 

For the prompting for MFA again on a daily basis, you can currently use the Sign In Frequency in AAD. Information can be found here: https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-mfa

 

@David Belanger thank you for your response. Regarding the second question, I have attached a screenshot (pic2.png) of the setting. I also tried some stuff in Advanced RDP Properties, but with no effect. When I change something in the Device redirection tab it automatically reflects in the Advanced RDP Properties. It currently shows like pic3.png.

Not sure why the 'Don't redirect any drives' option doesn't work, but try changing the advanced properties to drivestoreredirect:0 or in the GUI option, change to manually enter drive letters and enter 0.