The Feature EVERY AVD Admin Has Been Waiting For...

  Рет қаралды 13,895

Azure Academy

Azure Academy

Күн бұрын

Пікірлер: 104
@robb1267
@robb1267 2 жыл бұрын
This is awesome, thank you!!!! My users and I thank you!!! (OK, and the Microsoft product team, too...)
@AzureAcademy
@AzureAcademy 2 жыл бұрын
You are very welcome! I will pass it on to the team ☺️
@davidbelanger8440
@davidbelanger8440 2 жыл бұрын
Hi Rob, I’m David and I own this feature on the Azure Virtual Desktop team. You're welcome from the product group side 🙂 Feel free to leave feedback on the forum post at after giving it a try: techcommunity.microsoft.com/t5/azure-virtual-desktop/insider-preview-single-sign-on-and-passwordless-authentication/m-p/3608842
@AzureAcademy
@AzureAcademy Жыл бұрын
👍👍
@Timmy-Hi5
@Timmy-Hi5 2 жыл бұрын
hahaha🤣 after the Walter > Wonder Woman is leading this space hahaha you crack me up every single time ...great vid ;)🥰
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks as always Tim!
@TheStevenWhiting
@TheStevenWhiting Жыл бұрын
Yet 2 years on and they still haven't fixed the black screen issue at sign in. When you'll connect to the AVD and it will get stuck, loading the profile. Or you'll get disconnected and the AVD user profile will get stuck disconnected, again with the black screen issue.
@AzureAcademy
@AzureAcademy Жыл бұрын
That issue was fixed a long time ago. It’s the version of the image you are using.
@diabilliq
@diabilliq 2 жыл бұрын
this is excellent news! hopefully support for other builds of Windows 10/11 will be available soon as well. I remember for anyone that is a Nerdio user the now legacy NFA product would deploy an ADFS proxy server to handle the double login.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
That’s right Bill ADFS is needed for classic AD join and support for windows 10 is coming
@Stinger301
@Stinger301 2 жыл бұрын
This just got interesting... Thanks for sharing.. Love your work.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Happy to share, and thanks for watching! What other things would make this more interesting?
@blackmen2000
@blackmen2000 2 жыл бұрын
You're the best! I look forward to the video on how to update the W10 custom image to the W11. I have a lot of software installed there…
@AzureAcademy
@AzureAcademy 2 жыл бұрын
It’s gunna be great! Updating host and updating images are 2 different things. For the image I would use Azure Image Builder to automate the whole process…makes it SO easy!
@KefashWhite
@KefashWhite 2 жыл бұрын
Gems 💎 keep them coming. Thanks
@AzureAcademy
@AzureAcademy 2 жыл бұрын
NICE! Thanks for watching!
@PaulShadwell
@PaulShadwell 2 жыл бұрын
I was super excited till you got to the requirement of a preview build of Window 11. Will this ever be available for Windows 10?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
I hear ya Paul. Remember how I said a ton of work went into windows to make this so easy…to do that workin win 10…let’s just say I will not hold my breath but many have commented asking for it…so I will go to the PG and push for it, just for you! ☺️
@davidbelanger8440
@davidbelanger8440 2 жыл бұрын
Hi Paul, I’m David and I own this feature on the Azure Virtual Desktop team. Thanks for the feedback and interest. Stay tuned for Windows 10, it's coming.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks David!
@PaulShadwell
@PaulShadwell 2 жыл бұрын
@@davidbelanger8440 that IS good news. Thankyou.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
👍
@stevedowns8601
@stevedowns8601 2 жыл бұрын
Thanks for sharing, Dean!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Happy to help Steve!
@otakuguild5603
@otakuguild5603 10 ай бұрын
Could you please make a video on how to configure Hello for Buissness in AVD? I have a hybrid avd env and I am accessing the avd from my local device, do I need to domain join my local device as well to use the hello for buisness auth for AVD ?
@AzureAcademy
@AzureAcademy 10 ай бұрын
In a Hybrid environment you would setup Win Hello first then your VMs ONLY do a traditional domain join. There should be a GPO in AD that will do the Cloud join after. Once that is setup then your AVD users will need to setup WebAuthN to use windows Hello pass through in their AVD sessions
@testaaa88
@testaaa88 2 жыл бұрын
Hi, and congratulations for your channel! I've one question about performance and compatibility of Windows 11 vs Windows 10 in AVD environment. Actually I use only 21h2 Windows 10, is Windows 11 more heavy? Thanks!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Win 11 does have high requirements Win10: 1 cpu core 1gb Ram Win11: 2 cpu core 4gb Ram
@IvanBudylin
@IvanBudylin 2 жыл бұрын
So need it!!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Enjoy!
@the_fatshark
@the_fatshark Жыл бұрын
Hi Dean, loving the videos and tutorials. But for once i hit a road block. We have on-prem AD joined AVD session hosts. AVD with Windows 10 22h2 multi session. AVD session hosts are synced and hybrid azure ad joined. We have Created the ADKerberosServer object in on-prem AD. We enabled the sso aad option in rdp properties. Even disabled mfa. Added VM user login role. User is not in domain admin group. We use latest AVD/RD client but no SSO , we get a verification/authentication error. Also we cannot logon via web client anymore , we have to disable the aad sso rdp property so we can login again.
@AzureAcademy
@AzureAcademy Жыл бұрын
I haven’t run into that issue but sounds like you aren’t getting the Kerberos auth. Check the AD computer object for Azure AD Kerberos, verify that it is working properly
@amolshirke9507
@amolshirke9507 2 жыл бұрын
I created win 11 22H2 version build and enabled RDP settings as well as created AD account for Kerberos auth. Still its asking for password
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Since you setup the Kerberos Auth...I assume you have a Hybrid Join environment? If that is the case...did you configure Azure AD Connect for Hybrid Join and do you have a Group policy configured for Hybrid and Single Sign On?
@kmajors
@kmajors 2 жыл бұрын
Great news! Will it ever be available for Windows 10 multisession?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Yes multisession is supported right now!
@philippgerber3898
@philippgerber3898 2 жыл бұрын
Nice many thanks for this Information. It works only with Azure AD joined Host Pools and not with Active Directory ore Azure AD DS joined Hostpools?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks for watching! This solution Works with Azure AD Joined and Hybrid Joined VMs. Traditional AD joined needs my ADFS solution And Azure AD Domain Services joined does not now and will not support single sign on
@haraprasadnayak4040
@haraprasadnayak4040 2 жыл бұрын
Is this supported on Windows10 Single and Multi session OS? Version 21H2.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Windows 10 is NOT supported at this time.
@jlou65535
@jlou65535 2 жыл бұрын
Good news ! Thanks Dean How could we get Azure Virtual Desktop T-shirt ? xD
@AzureAcademy
@AzureAcademy 2 жыл бұрын
I got this from Microsoft when I co-hosted the last AVD Master class
@jlou65535
@jlou65535 2 жыл бұрын
@@AzureAcademy hey Dean, do you know why targetisaadjoined does not work anymore ? thank you
@AzureAcademy
@AzureAcademy Жыл бұрын
It does now
@stevenism
@stevenism 2 жыл бұрын
Hello Dean, is AVD Hybrid Join SSO still require the preview build as of February 2023?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
That or newer
@Jamie-zs4yc
@Jamie-zs4yc 2 жыл бұрын
What about Windows365 since it uses AVD and the Remote Desktop Client? I've been wanting this so much for W365
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Excellent question…not yet but soon. Stay tuned and I’ll have a video about it
@andyhuynh2450
@andyhuynh2450 2 жыл бұрын
I followed all the instructions and it still not sso for me.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Do you have the windows 11 22h2 preview build like I said to use And did you set the RDP properties
@andyhuynh2450
@andyhuynh2450 2 жыл бұрын
Yes I've set Windows 11 version 22H2 Enterprise multi-session, had rdp properties set under advanced with enablerdsaadauth:i:1. I also created kerberos object as well. When on RDP client, I select the desktop and it still prompting for a password. Greatly appreciated with you can guide me what I did wrong.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Are you using the windows AVD client and is that client using the latest version?
@andyhuynh2450
@andyhuynh2450 2 жыл бұрын
@@AzureAcademy I am using the remote desktop and its showing "you're up to date".
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Remote Desktop??? Do you mean the windows version of the AVD client? You cannot use the normal RDP client
@TheRealJLucas
@TheRealJLucas 2 жыл бұрын
You do not mention needing Azure Active Directory Domain Services. does AVD still require AD DS? Also, have you done a video regarding Azure Netapp files? I am the under the assumption that ANF does not require AD DS. What are your thoughts? Thank you for your hard work.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks for watching! Azure AD Domain Services does not work with ANY Single Sign On method. AVD Does NOT require Active Directory. You can implement Azure AD Join for your VMs, which means you only need Azure AD Azure NetApp Files does NOT require Active Directory but it does make things easier. Here is my video on ANF - Happy Learning! 👉kzbin.info/www/bejne/mKTaepWKd5tlo7s
@TheRealJLucas
@TheRealJLucas 2 жыл бұрын
@@AzureAcademy Excellent. 👍
@AzureAcademy
@AzureAcademy 2 жыл бұрын
👍👍
@migueljamous5576
@migueljamous5576 10 ай бұрын
@@AzureAcademy Hi, the problem is that we cannot go full AZure AD join as we are using azure file shares with Azure AD Domain Services for security. there is no support for Azure AD to setup security at the moment for Azure file share or is there a solution?
@AzureAcademy
@AzureAcademy 10 ай бұрын
As a cloud only authenticated file share…yes it can…but not with NTFS like permissions…for that you need a domain controller
@MikeLister
@MikeLister 2 жыл бұрын
You mention Windows 22H2, can this work with Win10 21H2? Will see tomorrow but wanted to check as we will be 9 months before 22H2
@AzureAcademy
@AzureAcademy 2 жыл бұрын
This is exclusive to Windows 11 Windows 10 is NOT supported at this time.
@MikeLister
@MikeLister 2 жыл бұрын
@@AzureAcademy thanks for letting me know. Booo.... least it gives me more reasons why we should upgrade quicker!
@davidbelanger8440
@davidbelanger8440 2 жыл бұрын
Hi Mike, I’m David and I own this feature on the Azure Virtual Desktop team. Windows 10 support is in progress and will need a Windows update. Stay tuned.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Stay Tuned!
@AzureAcademy
@AzureAcademy 2 жыл бұрын
NICE!
@jlou65535
@jlou65535 2 жыл бұрын
Hello Dean, I have trouble now to deploy usual AVD Azure AD Join : Login failed RDP argument "targetisaadjoined" does not work and "enablerdsaadauth" does fix it the Azure AD user login :( Do you have idea good idea ? Thanks,
@AzureAcademy
@AzureAcademy 2 жыл бұрын
I assume you have BOTH of those RDP Properties set targetisaadjoined:i:1 & enablerdsaadauth:i:1 do you ALSO have the RBAC permissions set to allow Virtual Machine login?
@jlou65535
@jlou65535 2 жыл бұрын
@@AzureAcademy Yep. Even in the Microsoft Doc, targetisaadjoined argument RDP Properties is not anymore listed. Azure Portal does not allow targetisaadjoined but Powershell cmd still does :)
@AzureAcademy
@AzureAcademy Жыл бұрын
I checked on this, targetisaadjoined:I:1 is added to the RDP properties advanced screen now
@milosmaksimovic8746
@milosmaksimovic8746 2 жыл бұрын
Do you have official Microsoft websites announcing this feature? I didn't find any yet. Does it work with Windows 10?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Windows 10 is NOT supported at this time.
@davidbelanger8440
@davidbelanger8440 2 жыл бұрын
Hi Milos, I’m David and I own this feature on the Azure Virtual Desktop team. The official announcement was just posted on our Azure Virtual Desktop Forum. Windows 10 support is in progress but needs a Windows update. Stay tuned. techcommunity.microsoft.com/t5/azure-virtual-desktop/insider-preview-single-sign-on-and-passwordless-authentication/m-p/3608842
@AzureAcademy
@AzureAcademy Жыл бұрын
👍👍
@mateuszadamczak8675
@mateuszadamczak8675 2 жыл бұрын
Any idea if / when will be possible to log in with AAD from MacOs e.g. with fingerprint? Currently, this new Remote Desktop client is only allowing to log in with login name and password and only option to log in is to use Windows 11 with virtual TPM ( and it's not working perfectly... sometimes it's working, sometimes not 😔)
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Are you asking when will the MAC client support Azure AD Join Single Sign on??? Not sure. Windows client is the only one today that supports this…but I know support for other clients is being worked on
@stormlight1553
@stormlight1553 2 жыл бұрын
Is there a way for split brain domain customers to take advantage of this? When you have mismatched domain names ( one domain name for internal and one for Azure) you always get a pop up box to sign in no matter what type of SSON you try to use. Once you put in the domain name that matches your azure tennant at least you dont have to enter in the password. However, total SSON with no pop up would be great. Love the chanel! Do you have a slack or other chat group?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks for watching and the question! Because the domain names are different true SSO would not be able to work. The domain name uses something called home realm discovery, which looks up the name and sees what services like SSO are enabled. If it can’t find it or read the services because it isn’t registered with Azure it prompts for creds. I do not currently have a discord or slack…not enough hours in the day…BUT if I am able to go full time KZbinr then I would add lots of services ☺️one day soon I hope!
@stormlight1553
@stormlight1553 2 жыл бұрын
@@AzureAcademy In my case it's because i followed MS practice many years to have your on prem domain be .local. So mad at them for that. I wish Azure could say if its coming from trusted domain x.x.x.x its already syncing with AD then yeah, .internal is cool and replace it on the azure side.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Yeah…at the time it was a good security practice to segment your internet presence from your on prem But the cloud changed to many things…now we want to extend on prem to the cloud…and that requires a single domain name, and .local just doesn’t do it. I know how it feels to make this change I have had to do it myself and with many customers…it’s a pain but it does give you benefits like SSO
@BladeFireLight
@BladeFireLight 2 жыл бұрын
How do we get this on Windows 365?
@AzureAcademy
@AzureAcademy 2 жыл бұрын
YOU can’t do anything to make this happen…BUT the Win365 product team is working on this…it should be coming soon ☺️
@9to511
@9to511 2 жыл бұрын
Excellent
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Thanks!
@waddid9645
@waddid9645 2 жыл бұрын
Hi Dean, can this be used on a non AAD or domain joined client? I want to use a Windows 10 IoT thin client running with a kiosk account and using the Remote Desktop Client, subscribe to my resources but when opening a desktop or application remove the second Windows Security prompt. Should that be possible with what you have described in the video? Thanks in advance 👍
@AzureAcademy
@AzureAcademy 2 жыл бұрын
This feature is only for Azure AD joined hosts There is another single sign on method using ADFS see here 👉 kzbin.info/www/bejne/lYeydpxmmLJ1rLM
@waddid9645
@waddid9645 2 жыл бұрын
@@AzureAcademy Hi Dean, thanks for the prompt reply. So does the ADFS method work with non domain joined hosts, which would be ideal for a kiosk way of working. Just confirming before going down that route and setting up as I had read some comments from people complaining having to use ADFS as saw is as outdated. Many thanks and great content as always. 👍
@AzureAcademy
@AzureAcademy 2 жыл бұрын
No, SSO requires some kind of Join ADFS requires domain join. Azure AD SSO requires AADJoin or hybrid AVD requires some kind of join option in general And there is no SSO log in support for RDP without some kind of join
@waddid9645
@waddid9645 2 жыл бұрын
@@AzureAcademy Thanks Dean. Appreciate your help with these answers. 😀
@AzureAcademy
@AzureAcademy Жыл бұрын
Anytime
@gbaity
@gbaity 2 жыл бұрын
Will the Kerberos piece work on existing haadj machines for ppl looking to go to aadj full cloud.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
Hybrid or AzureAD Join both work as I covered in the video with this new feature. Traditional AD Join will still require ADFS So…yes 100% cloud works!
@gbaity
@gbaity 2 жыл бұрын
Just so I’m asking the question right, I mean window machines not AVD session that are HaDJ. Have client in this state currently but wanting to go full cloud with AADJ away from HAADJ.
@AzureAcademy
@AzureAcademy 2 жыл бұрын
This feature for so you can connect to your AVD session hosts with SSO. As for AADJ or Hybrid Join outside of AVD...not sure, I haven't had a chance to try it. but the Hybrid / Azure AD Kerberos PowerShell scripts I was showing are for general use...so try it and please let me know!
Sign In To Azure Virtual Desktop ONCE
22:00
Azure Academy
Рет қаралды 12 М.
The Ultimate FSLogix Compilation!!!
55:43
Azure Academy
Рет қаралды 11 М.
1% vs 100% #beatbox #tiktok
01:10
BeatboxJCOP
Рет қаралды 67 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН
What is RDP Shortpath for AVD Managed Networks and How to Use It
13:33
Travis Roberts
Рет қаралды 4,2 М.
How to Configure a Conditional Access Policy for AVD
13:01
Travis Roberts
Рет қаралды 3 М.
3 BIGGEST Mistakes Admins Make in Azure 2025
14:04
Azure Academy
Рет қаралды 6 М.
3 Biggest Mistakes AVD Admins Make (Easy, Simple Fix)
16:07
Azure Academy
Рет қаралды 22 М.
The AVD Admins Super Power!!!
10:00
Azure Academy
Рет қаралды 15 М.
What is RDP Shortpath for AVD Public Networks and How to Use It
6:11
Travis Roberts
Рет қаралды 3,4 М.
FSLogix SECRETS Every AVD Admin Should LEARN
9:50
Azure Academy
Рет қаралды 10 М.
3 Secrets To AVD NOBODY Tells you (But Are Easy To Do)
16:50
Azure Academy
Рет қаралды 2,4 М.
NEVER install these programs on your PC... EVER!!!
19:26
JayzTwoCents
Рет қаралды 4,9 МЛН
How to run Azure Virtual Desktop on-premises
10:23
Microsoft Mechanics
Рет қаралды 43 М.
1% vs 100% #beatbox #tiktok
01:10
BeatboxJCOP
Рет қаралды 67 МЛН