OSDeploy | Sune Thomsen
TwitterLinkedInWindows 365 CommunityMVP ProfileGitHub
  • Home
  • Blog
    • Microsoft Intune
      • How to migrate BitLocker key(s) from all fixed drives to Microsoft Entra ID.
      • Migrate Bitlocker Recovery Key(s) to Azure AD with Proactive Remediation
      • Migrate imported GPOs to Intune with Group Policy analytics (preview)
      • Group Policy analytics (preview) made a bit easier with PowerShell
      • Analyze on-premises GPOs with MEM Group Policy Analytics (preview)
    • Virtual Machine
      • Fix the Hyper-V virtual switches after updating to Windows 11 (22H2)
    • 🆕Windows 365
      • 🆕Windows 365 Boot: Why User-Driven Mode?
      • 🆕Enhancing Security With Intune MAM (preview) for Windows 365
      • The Concept of Windows 365 Switch
      • The Concept of Windows 365 Boot
      • The Concept of Windows 365 Frontline
      • Move Cloud PCs to a new Azure Region or Azure Network Connection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 4. Windows 365 app and Cloud PC reporting
      • Windows 365 End-User Experience (Tips & Tricks) – Part 3. Multimedia Redirection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 2. Teams Optimization, SSO, and Localization
      • Windows 365 End-User Experience (Tips & Tricks) – Part 1. Connection experience
      • How to Configure Windows 365 Azure AD Join Single Sign-on (SSO)
      • Keep Windows 365 current and stay current with Windows Autopatch
      • Provide the end-users with a localized Windows 365 Cloud PC experience
      • How to configure Windows 365 Enterprise Azure AD join
      • How to secure Windows 365 using a FIDO2 security key
      • Prevent sensitive information from being captured on Windows 365 CPCs
      • Manage local administrator rights on Windows 365 Cloud PCs.
      • How to create a custom image for Windows 365 Enterprise Cloud PCs
      • How to reprovision existing Cloud PC (Windows 365) to Windows 11
      • How to configure Windows 365 Enterprise in Microsoft Endpoint Manager
  • Archive
    • Deployment
      • OSDCloud: The ZTI Way
      • OSDBuilder: WinPE Customization
    • Microsoft Configuration Manager
      • ConfigMgr: Run "All" Client Actions During OSD
      • ConfigMgr: WIM Your Applications Like a Boss
      • ConfigMgr: Deploy UWP Applications During OSD
      • ConfigMgr: Building a Basic LAB Environment
        • Part 1 - Installing Windows 10 (1909) on the Host
        • Part 2 - The Host and Hyper-V Configuration
        • Part 3 - Setting up the Domain Controller
          • Active Directory
          • DHCP
          • DNS
        • Part 4 - Setting up Microsoft Endpoint Configuration Manager
          • Prerequisites
          • SQL
        • Part 5 - Setting up Discovery Methods and Boundaries
        • Part 6 - Setting up Software Update Point
      • ConfigMgr: Splash Screen for Driver and BIOS Update
      • ConfigMgr: Global Conditions for Dell WD15 Dock Detection
    • Microsoft Intune
      • Block personally owned devices in Intune with enrollment restrictions
      • Remove Windows 10 built-in apps with Intune & Microsoft Store for Business Apps
    • Windows
      • Win10: Multi-Language Toast Notifications
        • Toast Notification: Low Disk Space
  • Links
    • Blogs
    • Microsoft
    • Scripts
Powered by GitBook
On this page
  • BEFORE YOU BEGIN
  • Introduction
  • Azure AD join (Microsoft Hosted Network)
  • Azure AD join (On-premises network connection)
  • Summary

Was this helpful?

  1. Blog
  2. Windows 365

How to configure Windows 365 Enterprise Azure AD join

30-05-2023 8:46 PM

PreviousProvide the end-users with a localized Windows 365 Cloud PC experienceNextHow to secure Windows 365 using a FIDO2 security key

Last updated 9 months ago

Was this helpful?

BEFORE YOU BEGIN

Disclaimer: All information and content in this blog post is provided without any warranty whatsoever. The entire risk of using this information or executing the provided content remains with you. Under no circumstances should the mentioned persons or vendors, the author, or anyone else involved in creating these blog posts be held liable for any damage or data loss.

Windows 365 Enterprise Azure AD join – Microsoft Hosted Network.

Introduction

Azure AD join (Microsoft Hosted Network)

Click Create policy.

Fill in the required Name field. Choose Join type, Network, Region, and click Next.

Select Image type and click Next. I chose Windows 11 Enterprise + Microsoft 365 Apps 21H2 from the image gallery.

Add a user-based Azure AD security group containing users eligible for a Windows 365 Enterprise Cloud PC, and click Next.

Review the configuration and click Create.

From Devices | Windows 365, click the All Cloud PCs tab. If all goes well, the Cloud PCs should appear in the list with the status shown as Provisioned after approx. 20-30 minutes.

Azure AD join (On-premises network connection)

Next, let’s configure the On-premises network connection provisioning policy. The Cloud PCs based on this policy will be Azure AD joined and connected to your Virtual Network, perfect for customers with an existing Azure or on-premises infrastructure that they need to reach from their Cloud PCs for several reasons. From Devices | Windows 365, click the On-premises network connection tab. Click Create and choose Azure AD join (preview) in the list.

Fill in the required Name field. Choose Subscription, Resource group, Virtual network, Subnet, and click Next.

Review the configuration and click Review + Create.

After approx. 5-10 minutes, we should be able to check the status of the on-premises network connection. Luckily for me, everything passed! Next, click the Provisioning policies tab.

Click Create policy.

Fill in the required Name field. Choose Join type, Network, and click Next.

Select Image type and click Next. Once again, I chose Windows 11 Enterprise + Microsoft 365 Apps 21H2 from the image gallery.

Add a user-based Azure AD security group containing users eligible for a Windows 365 Enterprise Cloud PC, and click Next.

Review the configuration and click Create.

From Devices | Windows 365, click the All Cloud PCs tab. If all goes well, the Cloud PCs should appear in the list with the status shown as Provisioned after approx. 20-30 minutes.

Summary

In this article, you learned how to configure Windows 365 Enterprise Azure AD join based on a Microsoft Hosted Network or an On-premises network connection provisioning policy in the Microsoft Endpoint Manager admin center. The capability to provision Windows 365 Enterprise Cloud PCs without the need for a connection to an on-premises domain controller is finally a reality. As already mentioned at the beginning of this article, native Azure AD join is something many of us have been looking forward to for several months, especially cloud-only customers! So this is something that I’m very excited to see available in public preview. – Happy testing, everyone! As always, if you have any questions regarding this topic, don’t hesitate to reach out to me.

Many of us have been waiting for native Azure AD join for Windows 365 Enterprise since its release in August 2021. But wait no longer! The native Azure AD join support has finally become a reality. In this article, I will guide you through the whole process of how to configure both the Built in Network (Referred to as Microsoft Hosted Network in this article) and the On-premises network connection provisioning policy in the Microsoft Endpoint Manager admin center. Read about the prerequisites and requirements for Windows 365 Enterprise Cloud PC and how to configure Hybrid Azure AD join in the original blog post here –

First, let’s configure the Microsoft Hosted Network provisioning policy by visiting the Microsoft Endpoint Manager admin center. The Cloud PCs based on this policy will be Azure AD joined, and they will run in a network hosted by Microsoft, which is perfect for cloud-only customers without an Azure or on-premises infrastructure. Go to Click Devices | Windows 365 | Provisioning policies

Let’s try and sign in to the newly created Azure AD joined Windows 365 Enterprise Cloud PC. Go to I can confirm from an elevated Command Prompt that the Cloud PC is Azure AD joined, and it’s running in a Microsoft hosted network.

Let’s try and sign in to the newly created Azure AD joined Windows 365 Enterprise Cloud PC. Go to Once again, I can confirm from an elevated Command Prompt that the Cloud PC is Azure AD joined. However, it’s connected to the newly created on-premises network connection, and I can communicate with an on-premises server.

🆕
How to configure Windows 365 Enterprise in Microsoft Endpoint Manager.
https://intune.microsoft.com
https://windows365.microsoft.com
https://windows365.microsoft.com