Configuring the subscription in Remote Desktop Client automatically

%3CLINGO-SUB%20id%3D%22lingo-sub-889673%22%20slang%3D%22en-US%22%3EConfiguring%20the%20subscription%20in%20Remote%20Desktop%20Client%20automatically%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-889673%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%3C%2FP%3E%3CP%3EIs%20there%20currently%20any%20way%20of%20automating%20the%20subscription%20config%20in%20Remote%20Desktop%2C%20so%20that%20our%20users%20don't%20have%20to%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20want%20to%20silently%20install%20the%20client%20on%20the%20users%20device%2C%20automatically%20set%20up%20the%20subscription%20against%20WVD%20without%20requiring%20any%20user%20intervention%2C%20so%20when%20the%20users%20click%20an%20application%2C%20with%20SSO%2C%20they%20will%20automagically%20be%20able%20to%20start%20the%20application%20on%20WVD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20the%20native%20%22remoteapp%20and%20desktop%20connections%22%20we%20were%20able%20to%20configure%20this%20with%20GPO%2C%20so%20users%20wouldn't%20have%20to%20input%20anything%2C%20but%20as%20I%20understand%2C%20this%20is%20not%20supported%20with%20WVD.%20(Even%20though%20it%20still%20works%20at%20the%20moment)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20with%20experience%20around%20this%3F%20Or%20know%20about%20any%20roadmap%20plans%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-893970%22%20slang%3D%22en-US%22%3ERE%3A%20Configuring%20the%20subscription%20in%20Remote%20Desktop%20Client%20automatically%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-893970%22%20slang%3D%22en-US%22%3EThank%20you%20for%20sharing%20your%20requirement%20Ola!%20I%20will%20take%20your%20feedback%20to%20the%20product%20team%20for%20consideration.%20If%20possible%2C%20can%20you%20please%20share%20how%20many%20client%20devices%2Fusers%20are%20you%20setting%20up%20for%20WVD%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-894331%22%20slang%3D%22en-US%22%3ERE%3A%20Configuring%20the%20subscription%20in%20Remote%20Desktop%20Client%20automatically%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-894331%22%20slang%3D%22en-US%22%3EThank%20you!%3CBR%20%2F%3EWe%20have%20approx%2019.000%20users%20in%20our%20organization%2C%20which%20we%20would%20like%20to%20automate%20the%20process%20of%20connecting%20to%20WVD.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1137643%22%20slang%3D%22en-US%22%3ERE%3A%20Configuring%20the%20subscription%20in%20Remote%20Desktop%20Client%20automatically%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1137643%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20the%20other%20hand%20we%20have%20a%20similar%2C%20but%20opposite%20problem.%3C%2FP%3E%3CP%3EWe%20would%20like%20to%20centrally%20remove%20the%20WVD%20Client%20subscription%20as%20some%20users%20inevitably%20will%20leave%20configured%20clients%20around%20potentially%20with%20saved%20credentials.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdditionally%2C%20is%20there%20a%20way%20to%20force%20Multi%20Factor%20Authentication%20*each%20time*%20a%20user%20logs%20into%20WVD%3F%3C%2FP%3E%3CP%3EIt%20seems%20that%20due%20to%20financial%20sector%20auditors%20request%20we%20need%20to%20verify%20each%20and%20every%20WVD%20desktop%20login%20with%20more%20than%20one%20credential%20factor.%20At%20the%20moment%20the%20security%20side%20of%20WVD%20is%20a%20concern%20as%20once%20the%20user%20subscribed%20(and%20potentially%20saved%20credentials)%20anyone%20can%20click%20an%20unattended%20client%20device%20and%20be%20logged%20on%20WVD%20without%20further%20challenge...%20handy%20but%20scary.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20very%20Much%3C%2FP%3E%3CP%3ENicola%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1105850%22%20slang%3D%22en-US%22%3ERE%3A%20Configuring%20the%20subscription%20in%20Remote%20Desktop%20Client%20automatically%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1105850%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F181812%22%20target%3D%22_blank%22%3E%40Soo%20Kuan%20Teo%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Soo%20Kuan%2C%20do%20you%20have%20any%20update%20on%20this%20one%3F%20We%20have%20multiple%20projects%20where%20WVD%20will%20be%20used%20for%20environments%20between%20250%20and%201000.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20in%20advance!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi there

Is there currently any way of automating the subscription config in Remote Desktop, so that our users don't have to?

 

We want to silently install the client on the users device, automatically set up the subscription against WVD without requiring any user intervention, so when the users click an application, with SSO, they will automagically be able to start the application on WVD.

 

With the native "remoteapp and desktop connections" we were able to configure this with GPO, so users wouldn't have to input anything, but as I understand, this is not supported with WVD. (Even though it still works at the moment)

 

Anyone with experience around this? Or know about any roadmap plans?

16 Replies
Highlighted
Thank you for sharing your requirement Ola! I will take your feedback to the product team for consideration. If possible, can you please share how many client devices/users are you setting up for WVD?
Highlighted
Thank you!
We have approx 19.000 users in our organization, which we would like to automate the process of connecting to WVD.
Highlighted

@Soo Kuan Teo 

 

Hi Soo Kuan, do you have any update on this one? We have multiple projects where WVD will be used for environments between 250 and 1000. 

 

Thank you in advance!

Highlighted

Hi All,

 

On the other hand we have a similar, but opposite problem.

We would like to centrally remove the WVD Client subscription as some users inevitably will leave configured clients around potentially with saved credentials.

 

Additionally, is there a way to force Multi Factor Authentication *each time* a user logs into WVD?

It seems that due to financial sector auditors request we need to verify each and every WVD desktop login with more than one credential factor. At the moment the security side of WVD is a concern as once the user subscribed (and potentially saved credentials) anyone can click an unattended client device and be logged on WVD without further challenge... handy but scary.

 

Thank you very Much

Nicola

 

Highlighted

Hi @nicoladv I know this is not exactly what you are asking but I would recommend checking out the solutions of our wvd partner DeviceTrust (devicetrust.com/wvd) : they add a lot of value to WVD in terms of contextual security.  

Highlighted

@Ola Holtberget 

 

Hey Ola,

I actually have the exact same need. We have been implementing a WVD solution, and I have been tasked with configuring Azure Intune Autopilot to deploy in such a way that all our helpdesk will have to do is give the user a laptop and the setup should be completely automated. The Windows Virtual Desktop app works great, but I can't find any way to automate the subscription process. Theoretically this should be do-able in Intune, but I'm unable to find any settings to govern it.

Highlighted

@JimCopeland63 Thanks for the feedback Jim. We've been looking at different ways to improve the initial subscription flow, at least for cases where the user's AAD token is already available for us to use (ex: AADJ or workplace joined devices).

 

One option is similar to RDS, where we'd add a policy/regkey like AutoSubscribeURL that when present would try to automatically subscribe the user using their existing AAD token. This workspace would not be removable by the user, contrary to manually added ones.

 

Thoughts on this?

Highlighted

@David Belanger 
It sounds like that would solve our immediate problem for sure.
Together with the Remote Desktop client itself starting in the background, and SSO, the users startmenu would populate automatically with assigned applications from WVD, without the users even having to see the client!

Highlighted

@David Belanger 

 

Could you tell us where this policy \ reg key is located?

Highlighted

@Soo Kuan Teo I have this requirement too.  I'm working with multiple UK public sector clients.  The two I'm working with right now are 50K users and 140K users.

Highlighted

I also have kind of that opposite need that I want the Remote Desktop client to UNSUBSCRIBE ever time it is closed so that MFA is actually forced each time a user logs in.  Any other way to force MFA ever time a user logs in to their Wvd?

Highlighted

@David Belanger 

That's an interesting idea, which regkey would need to be configured?

Highlighted

@Jeff Gustafson 

 

Maybe you can configure the Sign-in frequency for this and set it to 1 hour.

Highlighted

@David Belanger on the same boat, could you share that GPO\key that can help us with that?

Highlighted

@David Belanger any development on this?

 

Cheers

M.

Highlighted

@David Belanger  Please do this. We have shared thin clients that we want to keep subscribed.