OSDeploy | Sune Thomsen
TwitterLinkedInWindows 365 CommunityMVP ProfileGitHub
  • Home
  • Blog
    • Microsoft Intune
      • How to migrate BitLocker key(s) from all fixed drives to Microsoft Entra ID.
      • Migrate Bitlocker Recovery Key(s) to Azure AD with Proactive Remediation
      • Migrate imported GPOs to Intune with Group Policy analytics (preview)
      • Group Policy analytics (preview) made a bit easier with PowerShell
      • Analyze on-premises GPOs with MEM Group Policy Analytics (preview)
    • Virtual Machine
      • Fix the Hyper-V virtual switches after updating to Windows 11 (22H2)
    • 🆕Windows 365
      • 🆕Windows 365 Boot: Why User-Driven Mode?
      • 🆕Enhancing Security With Intune MAM (preview) for Windows 365
      • The Concept of Windows 365 Switch
      • The Concept of Windows 365 Boot
      • The Concept of Windows 365 Frontline
      • Move Cloud PCs to a new Azure Region or Azure Network Connection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 4. Windows 365 app and Cloud PC reporting
      • Windows 365 End-User Experience (Tips & Tricks) – Part 3. Multimedia Redirection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 2. Teams Optimization, SSO, and Localization
      • Windows 365 End-User Experience (Tips & Tricks) – Part 1. Connection experience
      • How to Configure Windows 365 Azure AD Join Single Sign-on (SSO)
      • Keep Windows 365 current and stay current with Windows Autopatch
      • Provide the end-users with a localized Windows 365 Cloud PC experience
      • How to configure Windows 365 Enterprise Azure AD join
      • How to secure Windows 365 using a FIDO2 security key
      • Prevent sensitive information from being captured on Windows 365 CPCs
      • Manage local administrator rights on Windows 365 Cloud PCs.
      • How to create a custom image for Windows 365 Enterprise Cloud PCs
      • How to reprovision existing Cloud PC (Windows 365) to Windows 11
      • How to configure Windows 365 Enterprise in Microsoft Endpoint Manager
  • Archive
    • Deployment
      • OSDCloud: The ZTI Way
      • OSDBuilder: WinPE Customization
    • Microsoft Configuration Manager
      • ConfigMgr: Run "All" Client Actions During OSD
      • ConfigMgr: WIM Your Applications Like a Boss
      • ConfigMgr: Deploy UWP Applications During OSD
      • ConfigMgr: Building a Basic LAB Environment
        • Part 1 - Installing Windows 10 (1909) on the Host
        • Part 2 - The Host and Hyper-V Configuration
        • Part 3 - Setting up the Domain Controller
          • Active Directory
          • DHCP
          • DNS
        • Part 4 - Setting up Microsoft Endpoint Configuration Manager
          • Prerequisites
          • SQL
        • Part 5 - Setting up Discovery Methods and Boundaries
        • Part 6 - Setting up Software Update Point
      • ConfigMgr: Splash Screen for Driver and BIOS Update
      • ConfigMgr: Global Conditions for Dell WD15 Dock Detection
    • Microsoft Intune
      • Block personally owned devices in Intune with enrollment restrictions
      • Remove Windows 10 built-in apps with Intune & Microsoft Store for Business Apps
    • Windows
      • Win10: Multi-Language Toast Notifications
        • Toast Notification: Low Disk Space
  • Links
    • Blogs
    • Microsoft
    • Scripts
Powered by GitBook
On this page
  • BEFORE YOU BEGIN
  • Introduction
  • Enable the Windows 365 SSO Option
  • Windows 365 SSO Experience (Web Portal)
  • Windows 365 SSO Experience (Windows 365 App)
  • Summary

Was this helpful?

  1. Blog
  2. Windows 365

How to Configure Windows 365 Azure AD Join Single Sign-on (SSO)

01-06-2023 8:46 PM

PreviousWindows 365 End-User Experience (Tips & Tricks) – Part 1. Connection experienceNextKeep Windows 365 current and stay current with Windows Autopatch

Last updated 9 months ago

Was this helpful?

BEFORE YOU BEGIN

Disclaimer: All information and content in this blog post is provided without any warranty whatsoever. The entire risk of using this information or executing the provided content remains with you. Under no circumstances should the mentioned persons or vendors, the author, or anyone else involved in creating these blog posts be held liable for any damage or data loss.

Introduction

In September 2022, Microsoft announced the public preview of single sign-on (SSO) and passwordless authentication for Azure Virtual Desktop. – Since then, many of us have been waiting for Windows 365 Azure AD Join SSO support. The wait is finally over because Microsoft has recently announced that Windows 365 now supports creating Azure AD Joined Cloud PCs that use SSO for Cloud PC login!

Note: Windows 365 Hybrid Azure AD Join SSO support is still not supported! – See

Why is SSO support that interesting, you might ask? It’s interesting because until now, the user must first sign in to the Windows 365 service and then to their personal Windows 365 Cloud PC either through the Web Portal, Remote Desktop App, or the new Windows 365 App. – And that’s not what I call a great end-user experience! So, In this blog post, I will show you how to enable SSO for an existing provisioning policy in Microsoft Intune. If you’re looking for Windows 365 Enterprise Cloud PC prerequisites and requirements and information about how to set it up, look no further:

Enable the Windows 365 SSO Option

First, let’s visit Microsoft Intune and turn on SSO for my current Windows 365 provisioning policy. Go to In the left pane, click Devices | Windows 365 | Provisioning policies Create a new policy or select an existing policy in the list of provisioning policies. – For this post, I chose to modify my current provisioning policy.

On the overview page, look for General and click Edit.

Check Use single sign-on (preview) and click Next.

Review the configuration and click Update.

From Devices | Windows 365, click the All Cloud PCs tab.

If you’re provisioning a new Cloud PC, it will show in the list after approx. 20-30 minutes. Otherwise, select an existing Cloud PC to reprovision. – For this post, I chose to reprovision an existing Cloud PC.

Click Reprovision. If all goes well, the new reprovisioned Cloud PC should appear in the All Cloud PCs list after approx. 20-30 minutes.

Windows 365 SSO Experience (Web Portal)

Enter your password and click Sign in.

Click Open in browser.

Click Connect.

Instead of the usual sign-in prompt for the Windows 365 Cloud PC, we now need to allow the remote device to access your account and sign you in. – This means that SSO is working! Click Yes.

And we are signed in to the Windows 365 Cloud PC. – Pretty Awesome!

Windows 365 SSO Experience (Windows 365 App)

Next, let’s try and sign in to the Windows 365 Cloud PC using the new Windows 365 App.

Note: The Windows 365 App is only available from the Microsoft Store on Windows 11.

Open the Windows 365 App.

Enter your account and click Next.

Enter your password and click Sign in.

Click Connect.

We can confirm once again that SSO works! – We are now signed in without any extra sign-in prompt.

Summary

Important: If you change the network, single sign-on configuration or image in a provisioning policy, no change will occur for previously provisioned Cloud PCs. Newly provisioned Cloud PCs will honor the changes in your provisioning policy. To change the previously provisioned Cloud PCs to align with the changes, you must reprovision those Cloud PCs. Source:

Let’s sign in to the newly reprovisioned Windows 365 Cloud PC and verify that SSO is enabled. Go to Enter your account and click Next.

In this blog post, you learned how to enable the new SSO option for Windows 365 Cloud PCs, and we then verified the results on a reprovisioned Cloud PC. No doubt Windows 365 Hybrid Azure AD Join SSO support will be very interesting for many Enterprise customers, so hopefully, we will see that feature very soon! – But with Windows 365 Azure AD Join (Bring Your Own Network), and if you have configured Azure AD Kerberos on-premises, you can actually leverage the new SSO option to access Kerberos-based resources and applications. See Personally, I think this is pretty awesome and one of the last pieces of the puzzle to provide the end user with the best possible sign-in experience on their personal Windows 365 Cloud PCs. That’s it, folks. Happy testing, and Merry Christmas! If you have any questions regarding this topic, please feel free to reach out to me.

Microsoft Docs
https://windows365.microsoft.com
Identity and authentication
🆕
features in development
How to configure Windows 365 Enterprise in Microsoft Endpoint Manager
How to configure Windows 365 Enterprise Azure AD join
https://intune.microsoft.com
Page cover image
Provisioning policy.
Enable SSO in the Windows 365 provisioning policy.
Reprovision the Cloud PC.
Provisioning policy.
Reprovision the Cloud PC.
Enable SSO in the Windows 365 provisioning policy.
Windows 365 SSO Experience (Web Portal).
Windows 365 SSO Experience (Web Portal).
Windows 365 SSO Experience (Web Portal).
Windows 365 SSO Experience (Web Portal).
Windows 365 SSO Experience (Web Portal).
Windows 365 SSO Experience (Web Portal).
Windows 365 SSO Experience (Windows 365 App).
Windows 365 SSO Experience (Windows 365 App).
Windows 365 SSO Experience (Windows 365 App).
Windows 365 SSO Experience (Windows 365 App).
Windows 365 SSO Experience (Windows 365 App).