Questions about WVD

%3CLINGO-SUB%20id%3D%22lingo-sub-1638514%22%20slang%3D%22en-US%22%3EQuestions%20about%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1638514%22%20slang%3D%22en-US%22%3E%3CP%3ECan%20WVD%20be%20configured%20to%20only%20allow%20connections%20from%20trusted%20devices%20including%20ones%20that%20we%20don%E2%80%99t%20own%20and%20manage%20ourselves%20(such%20as%20devices%20from%20our%20business%20partners%20that%20we%20have%20no%20ability%20to%20manage)%3F%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAmazon%20workspaces%20have%20an%20option%20called%20%E2%80%9Ctrusted%20devices%E2%80%9D%20where%20you%20upload%20a%20copy%20of%20root%20CAs%20and%20you%20can%20configure%20it%20to%20only%20allow%20connections%20from%20devices%20that%20have%20a%20certificate%20installed%20from%20one%20of%20the%20root%20CAs%20you.%20uploaded.%20%26nbsp%3BIt%20does%20not%20require%20the%20device%20to%20be%20from%20your%20own%20domain%20or%20for%20you%20to%20manage%20the%20device%20with%20an%20MDM%20and%20push%20your%20own%20certificates%20to%20it%20for%20this%20to%20work.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20WVD%20have%20anything%20that%20would%20accomplish%20the%20same%20requirement%20even%20if%20the%20methods%20to%20accomplish%20the%20goal%20are%20different%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20WVD%20work%20with%20third%20party%20MFA%20such%20as%20Duo%20Security%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20WVD%20be%20used%20a%20%E2%80%9Cjump%20server%E2%80%9D%20to%20access%20our%20internal%20LAN%20resources%20via%20RDP%20and%20pass%20through%20RDP%20to%20the%20second%20device%20with%20full%20dual%20monitor%20functionality%20(remote%20laptop%20with%20external%20monitor%20attached%26gt%3B%26gt%3B%26gt%3BWVD%26gt%3B%26gt%3B%26gt%3BRDP%20to%20internal%20resource%20with%20multi-monitor%20support)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20IP%20ranges%20available%20so%20that%20we%20could%20add%20WVD%20access%20to%20split%20tunnel%20VPN%20and%20then%20require%20those%20accessing%20WVD%20to%20be%20coming%20from%20one%20of%20our%20trusted%20IPs%20such%20as%20the%20VPN%20gateway%20IP%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Can WVD be configured to only allow connections from trusted devices including ones that we don’t own and manage ourselves (such as devices from our business partners that we have no ability to manage)?  

 

Amazon workspaces have an option called “trusted devices” where you upload a copy of root CAs and you can configure it to only allow connections from devices that have a certificate installed from one of the root CAs you. uploaded.  It does not require the device to be from your own domain or for you to manage the device with an MDM and push your own certificates to it for this to work.  

 

Does WVD have anything that would accomplish the same requirement even if the methods to accomplish the goal are different?

 

Does WVD work with third party MFA such as Duo Security?

 

Can WVD be used a “jump server” to access our internal LAN resources via RDP and pass through RDP to the second device with full dual monitor functionality (remote laptop with external monitor attached>>>WVD>>>RDP to internal resource with multi-monitor support)?

 

Are IP ranges available so that we could add WVD access to split tunnel VPN and then require those accessing WVD to be coming from one of our trusted IPs such as the VPN gateway IP?

1 Reply

Hi @Kalimanne J 

 

Yes WVD can be configured to use Conditional Access. Here you can configure rules to determine whether your clients can access your WVD resources or not.  You can view more about conditional access policies here - https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-acces...

 

I don't know about Duo but I do know that it definitely works on Okta. WVD authenticates via AzureAD & O365 so if Duo supports that, it will work.  It also supports native MFA. 

 

As for your jump server question, yes it can! That is how some people use it. See here for a good example - https://www.robinhobo.com/how-to-publish-the-remote-server-administration-tools-rsat-with-windows-vi...