azure virtual desktop setup

shelly kapoor 0 Reputation points
2025-01-29T09:24:00.69+00:00
  1. Having adds in hub
  2. Not having adds in hub & their limitation
  3. For AVD what are the auth options with security measure?
  4. list of security controls that can be enforced from Entra Id, AVD, on session host & on file share
  5. Outbound NAT with a public IP 
  6. Auth options for session host if we don't have sub 2 & if we have sub2.

 

whats's the purpose the sub 2, if we can remove it what will be the impact

 

what are the avd auth options

 

why adds server is needed here? write up for Adds "Hi I am having this questions regarding azure virtual desktop"

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,668 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Srinud 3,610 Reputation points Microsoft Vendor
    2025-01-30T13:07:25.1833333+00:00

    Hi shelly kapoor,

    Thanks for sharing the information; it helps us clarify your requirements.

    I have discussed this query with my team and gathered inputs. Still have the possibility to associate a Public IP with AVD and create a NAT rule. However, the users are unable to access the AVD VMs directly. We can only access AVD from Remote Desktop client app and Workspace URL.

    We can use both ADDS and Microsoft Entra ID as Azure Virtual Desktop supports different types of identities for accessing corporate resources and applications. As a workload owner, you can select from various types of identity providers according to your business and organizational needs. Review the identity design areas in this section to assess what's best for your workload.

    Azure Virtual Desktop supports hybrid identities through Microsoft Entra ID, including identities that are federated by using AD FS. You can manage these user identities in AD DS and sync them to Microsoft Entra ID by using Microsoft Entra Connect. You can also use Microsoft Entra ID to manage these identities and sync them to AD DS.

    Microsoft Entra ID: Azure Virtual Desktop supports cloud-only identities when you use VMs that are joined by using Microsoft Entra ID. These users are created and managed directly in Microsoft Entra ID.

    You can use third-party identity providers as long as they federate with Microsoft Entra ID. Please refer to this link- https://learn.microsoft.com/en-us/azure/virtual-desktop/authentication#federated-identity

    I would recommend that you refer to the link given below for more information on AVD. https://learn.microsoft.com/en-us/azure/virtual-desktop/users/

    If you have any further queries, please let us know. I am happy to assist you!

    Thank you!

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.