AVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

I spoke at a global AVD event (Microsoft meets Community: Windows virtual Desktop virtual event 3rd XXL edition) on the 11th of Dec about the topic AVD Management with Intune. I share the details about the presentation and Windows Virtual Desktop experience with modern management tools like Intune in this post.

My session was the fourth (4th) one in the event and the session topic was “Sharing Tips and Tricks on how to Manage Windows Virtual Desktop via Intune in Microsoft Endpoint Manager“. You can download the PDF version of the presentation and you can also have a recording of the event soon.

Related Post – 63 Episodes of Free Intune Training for Device Management Admins

Patch My PC
Watch this video on YouTube.

Context

I tried to set the context of the AVD management in the first slide.

  • Why do you want to manage aVD with Intune?
  • When should you start AVD Management with Intune?
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop
AVD Management with Intune | Azure Virtual Desktop | Windows Virtual Desktop

Hybrid AAD Join & Group Policy

 Let’s go through some of the technical configurations and prerequisites that we need to complete before AVD Intune management.

  • Make sure the VMs are Hybrid AAD Join
  • MDM Group Policy for All AVD VMs

Windows 10 Intune Enrollment using Group Policy | Automatic Enrollment | AVD https://www.anoopcnair.com/windows-10-intune-enrollment-using-group-policy-automatic-enrollment-wvd/

1E Nomad
WVD Management with Intune | Windows Virtual Desktop
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

Azure AD Conditional Access & Groups

Modern management of AVD with Intune and Azure AD comes with some quick wins. This modern management helps to enable Multi-Factor Authentication (MFA) without any complex infra in place.

  • Modern Security Parameters with Azure AD CA
  • Dynamic Azure AD user/device groups
WVD Management with Intune | Windows Virtual Desktop
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

End User Experience

Let’s check what is the end-user experience for single session users. Microsoft is improving enrollment experience in coming months. Let’s wait and see.

  • The AVD VM will be ready to use immediately after the Intune enrollment
  • Azure AD registration of the VMs happens immediately after the VM provisioning process.
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop
AVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

Security Policies for AVD

Let’s check how to deploy security policies in the AVD modern management world with Intune. I have seen organizations follow the CIS benchmark system to Secure Windows Desktop and laptop devices. However, Windows 10 CSPs changed the way of applying security policies.

This is the modern way of securing devices with MDM policies. As you can see in the slide, the National Cyber Security Center of UK Govt did an excellent job to release a benchmark to secure Windows 10 devices using CSPs.

WVD Management with Intune | Windows Virtual Desktop
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

Application Deployment

Let’s understand Intune application deployment options for AVD in this slide. You can deploy almost all types of applications using Intune app deployment frameworks. There are app types that are supported natively by Windows 10 MDM management tools and those types are MSIX and simple MSI etc.

WVD Management with Intune | Windows Virtual Desktop
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

Patching & Windows 10 Upgrade

Let’s have a look into patching scenarios in the AVD modern management world with Intune. Also explained How the monthly patching and Windows 10 upgrade scenarios are handled. The big difference here with Intune management is Windows Update for Business instead of WSUS.

  • Monthly Patching is managed via Windows Update for Business (WUfB) policies
  • Windows 10 Upgrade policies are configured through WUfB feature update policies
WVD Management with Intune | Windows Virtual Desktop
WVD Management with Intune | Azure Virtual Desktop | AVD | Windows Virtual Desktop

Download

Let’s download the PDF from GitHub repository – https://github.com/AnoopCNair/WVD-Intune-Management-PDF

Recording

WVD Management with Intune | Microsoft Endpoint Manager | Microsoft Meets Community Event Recording – YouTube

Watch this video on YouTube.

Indian Windows Virtual Desktop User Group #INWVDUG

Today we announced the Indian Windows Virtual Desktop User Group (#INWVDUG). Welcome Windows Virtual Desktop (AVD) enthusiasts around the world.

There are several options to connect with us online. The following are some of the options:

Resources

Categories AVD