Тёмный

The Feature EVERY AVD Admin Has Been Waiting For... 

Azure Academy
Подписаться 59 тыс.
Просмотров 13 тыс.
50% 1

Опубликовано:

 

30 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 102   
@otakuguild5603
@otakuguild5603 6 месяцев назад
Could you please make a video on how to configure Hello for Buissness in AVD? I have a hybrid avd env and I am accessing the avd from my local device, do I need to domain join my local device as well to use the hello for buisness auth for AVD ?
@AzureAcademy
@AzureAcademy 6 месяцев назад
In a Hybrid environment you would setup Win Hello first then your VMs ONLY do a traditional domain join. There should be a GPO in AD that will do the Cloud join after. Once that is setup then your AVD users will need to setup WebAuthN to use windows Hello pass through in their AVD sessions
@TheStevenWhiting
@TheStevenWhiting Год назад
Yet 2 years on and they still haven't fixed the black screen issue at sign in. When you'll connect to the AVD and it will get stuck, loading the profile. Or you'll get disconnected and the AVD user profile will get stuck disconnected, again with the black screen issue.
@AzureAcademy
@AzureAcademy Год назад
That issue was fixed a long time ago. It’s the version of the image you are using.
@amolshirke9507
@amolshirke9507 2 года назад
I created win 11 22H2 version build and enabled RDP settings as well as created AD account for Kerberos auth. Still its asking for password
@AzureAcademy
@AzureAcademy 2 года назад
Since you setup the Kerberos Auth...I assume you have a Hybrid Join environment? If that is the case...did you configure Azure AD Connect for Hybrid Join and do you have a Group policy configured for Hybrid and Single Sign On?
@haraprasadnayak4040
@haraprasadnayak4040 2 года назад
Is this supported on Windows10 Single and Multi session OS? Version 21H2.
@AzureAcademy
@AzureAcademy 2 года назад
Windows 10 is NOT supported at this time.
@PaulShadwell
@PaulShadwell 2 года назад
I was super excited till you got to the requirement of a preview build of Window 11. Will this ever be available for Windows 10?
@AzureAcademy
@AzureAcademy 2 года назад
I hear ya Paul. Remember how I said a ton of work went into windows to make this so easy…to do that workin win 10…let’s just say I will not hold my breath but many have commented asking for it…so I will go to the PG and push for it, just for you! ☺️
@davidbelanger8440
@davidbelanger8440 2 года назад
Hi Paul, I’m David and I own this feature on the Azure Virtual Desktop team. Thanks for the feedback and interest. Stay tuned for Windows 10, it's coming.
@AzureAcademy
@AzureAcademy 2 года назад
Thanks David!
@PaulShadwell
@PaulShadwell 2 года назад
@@davidbelanger8440 that IS good news. Thankyou.
@AzureAcademy
@AzureAcademy 2 года назад
👍
@testaaa88
@testaaa88 2 года назад
Hi, and congratulations for your channel! I've one question about performance and compatibility of Windows 11 vs Windows 10 in AVD environment. Actually I use only 21h2 Windows 10, is Windows 11 more heavy? Thanks!
@AzureAcademy
@AzureAcademy 2 года назад
Win 11 does have high requirements Win10: 1 cpu core 1gb Ram Win11: 2 cpu core 4gb Ram
@kmajors
@kmajors 2 года назад
Great news! Will it ever be available for Windows 10 multisession?
@AzureAcademy
@AzureAcademy 2 года назад
Yes multisession is supported right now!
@robb1267
@robb1267 2 года назад
This is awesome, thank you!!!! My users and I thank you!!! (OK, and the Microsoft product team, too...)
@AzureAcademy
@AzureAcademy 2 года назад
You are very welcome! I will pass it on to the team ☺️
@davidbelanger8440
@davidbelanger8440 2 года назад
Hi Rob, I’m David and I own this feature on the Azure Virtual Desktop team. You're welcome from the product group side 🙂 Feel free to leave feedback on the forum post at after giving it a try: techcommunity.microsoft.com/t5/azure-virtual-desktop/insider-preview-single-sign-on-and-passwordless-authentication/m-p/3608842
@AzureAcademy
@AzureAcademy Год назад
👍👍
@BladeFireLight
@BladeFireLight Год назад
How do we get this on Windows 365?
@AzureAcademy
@AzureAcademy Год назад
YOU can’t do anything to make this happen…BUT the Win365 product team is working on this…it should be coming soon ☺️
@milosmaksimovic8746
@milosmaksimovic8746 2 года назад
Do you have official Microsoft websites announcing this feature? I didn't find any yet. Does it work with Windows 10?
@AzureAcademy
@AzureAcademy 2 года назад
Windows 10 is NOT supported at this time.
@davidbelanger8440
@davidbelanger8440 2 года назад
Hi Milos, I’m David and I own this feature on the Azure Virtual Desktop team. The official announcement was just posted on our Azure Virtual Desktop Forum. Windows 10 support is in progress but needs a Windows update. Stay tuned. techcommunity.microsoft.com/t5/azure-virtual-desktop/insider-preview-single-sign-on-and-passwordless-authentication/m-p/3608842
@AzureAcademy
@AzureAcademy Год назад
👍👍
@stevenism
@stevenism Год назад
Hello Dean, is AVD Hybrid Join SSO still require the preview build as of February 2023?
@AzureAcademy
@AzureAcademy Год назад
That or newer
@the_fatshark
@the_fatshark Год назад
Hi Dean, loving the videos and tutorials. But for once i hit a road block. We have on-prem AD joined AVD session hosts. AVD with Windows 10 22h2 multi session. AVD session hosts are synced and hybrid azure ad joined. We have Created the ADKerberosServer object in on-prem AD. We enabled the sso aad option in rdp properties. Even disabled mfa. Added VM user login role. User is not in domain admin group. We use latest AVD/RD client but no SSO , we get a verification/authentication error. Also we cannot logon via web client anymore , we have to disable the aad sso rdp property so we can login again.
@AzureAcademy
@AzureAcademy Год назад
I haven’t run into that issue but sounds like you aren’t getting the Kerberos auth. Check the AD computer object for Azure AD Kerberos, verify that it is working properly
@Stinger301
@Stinger301 2 года назад
This just got interesting... Thanks for sharing.. Love your work.
@AzureAcademy
@AzureAcademy 2 года назад
Happy to share, and thanks for watching! What other things would make this more interesting?
@philippgerber3898
@philippgerber3898 2 года назад
Nice many thanks for this Information. It works only with Azure AD joined Host Pools and not with Active Directory ore Azure AD DS joined Hostpools?
@AzureAcademy
@AzureAcademy 2 года назад
Thanks for watching! This solution Works with Azure AD Joined and Hybrid Joined VMs. Traditional AD joined needs my ADFS solution And Azure AD Domain Services joined does not now and will not support single sign on
@mateuszadamczak8675
@mateuszadamczak8675 2 года назад
Any idea if / when will be possible to log in with AAD from MacOs e.g. with fingerprint? Currently, this new Remote Desktop client is only allowing to log in with login name and password and only option to log in is to use Windows 11 with virtual TPM ( and it's not working perfectly... sometimes it's working, sometimes not 😔)
@AzureAcademy
@AzureAcademy 2 года назад
Are you asking when will the MAC client support Azure AD Join Single Sign on??? Not sure. Windows client is the only one today that supports this…but I know support for other clients is being worked on
@MikeLister
@MikeLister 2 года назад
You mention Windows 22H2, can this work with Win10 21H2? Will see tomorrow but wanted to check as we will be 9 months before 22H2
@AzureAcademy
@AzureAcademy 2 года назад
This is exclusive to Windows 11 Windows 10 is NOT supported at this time.
@MikeLister
@MikeLister 2 года назад
@@AzureAcademy thanks for letting me know. Booo.... least it gives me more reasons why we should upgrade quicker!
@davidbelanger8440
@davidbelanger8440 2 года назад
Hi Mike, I’m David and I own this feature on the Azure Virtual Desktop team. Windows 10 support is in progress and will need a Windows update. Stay tuned.
@AzureAcademy
@AzureAcademy 2 года назад
Stay Tuned!
@AzureAcademy
@AzureAcademy 2 года назад
NICE!
@Jamie-zs4yc
@Jamie-zs4yc 2 года назад
What about Windows365 since it uses AVD and the Remote Desktop Client? I've been wanting this so much for W365
@AzureAcademy
@AzureAcademy 2 года назад
Excellent question…not yet but soon. Stay tuned and I’ll have a video about it
@Timmy-Hi5
@Timmy-Hi5 2 года назад
hahaha🤣 after the Walter > Wonder Woman is leading this space hahaha you crack me up every single time ...great vid ;)🥰
@AzureAcademy
@AzureAcademy 2 года назад
Thanks as always Tim!
@blackmen2000
@blackmen2000 2 года назад
You're the best! I look forward to the video on how to update the W10 custom image to the W11. I have a lot of software installed there…
@AzureAcademy
@AzureAcademy 2 года назад
It’s gunna be great! Updating host and updating images are 2 different things. For the image I would use Azure Image Builder to automate the whole process…makes it SO easy!
@diabilliq
@diabilliq 2 года назад
this is excellent news! hopefully support for other builds of Windows 10/11 will be available soon as well. I remember for anyone that is a Nerdio user the now legacy NFA product would deploy an ADFS proxy server to handle the double login.
@AzureAcademy
@AzureAcademy 2 года назад
That’s right Bill ADFS is needed for classic AD join and support for windows 10 is coming
@IvanBudylin
@IvanBudylin 2 года назад
So need it!!
@AzureAcademy
@AzureAcademy 2 года назад
Enjoy!
@jlou65535
@jlou65535 2 года назад
Hello Dean, I have trouble now to deploy usual AVD Azure AD Join : Login failed RDP argument "targetisaadjoined" does not work and "enablerdsaadauth" does fix it the Azure AD user login :( Do you have idea good idea ? Thanks,
@AzureAcademy
@AzureAcademy 2 года назад
I assume you have BOTH of those RDP Properties set targetisaadjoined:i:1 & enablerdsaadauth:i:1 do you ALSO have the RBAC permissions set to allow Virtual Machine login?
@jlou65535
@jlou65535 2 года назад
@@AzureAcademy Yep. Even in the Microsoft Doc, targetisaadjoined argument RDP Properties is not anymore listed. Azure Portal does not allow targetisaadjoined but Powershell cmd still does :)
@AzureAcademy
@AzureAcademy Год назад
I checked on this, targetisaadjoined:I:1 is added to the RDP properties advanced screen now
@jlou65535
@jlou65535 2 года назад
Good news ! Thanks Dean How could we get Azure Virtual Desktop T-shirt ? xD
@AzureAcademy
@AzureAcademy 2 года назад
I got this from Microsoft when I co-hosted the last AVD Master class
@jlou65535
@jlou65535 2 года назад
@@AzureAcademy hey Dean, do you know why targetisaadjoined does not work anymore ? thank you
@AzureAcademy
@AzureAcademy Год назад
It does now
@stormlight1553
@stormlight1553 2 года назад
Is there a way for split brain domain customers to take advantage of this? When you have mismatched domain names ( one domain name for internal and one for Azure) you always get a pop up box to sign in no matter what type of SSON you try to use. Once you put in the domain name that matches your azure tennant at least you dont have to enter in the password. However, total SSON with no pop up would be great. Love the chanel! Do you have a slack or other chat group?
@AzureAcademy
@AzureAcademy 2 года назад
Thanks for watching and the question! Because the domain names are different true SSO would not be able to work. The domain name uses something called home realm discovery, which looks up the name and sees what services like SSO are enabled. If it can’t find it or read the services because it isn’t registered with Azure it prompts for creds. I do not currently have a discord or slack…not enough hours in the day…BUT if I am able to go full time RU-vidr then I would add lots of services ☺️one day soon I hope!
@stormlight1553
@stormlight1553 2 года назад
@@AzureAcademy In my case it's because i followed MS practice many years to have your on prem domain be .local. So mad at them for that. I wish Azure could say if its coming from trusted domain x.x.x.x its already syncing with AD then yeah, .internal is cool and replace it on the azure side.
@AzureAcademy
@AzureAcademy 2 года назад
Yeah…at the time it was a good security practice to segment your internet presence from your on prem But the cloud changed to many things…now we want to extend on prem to the cloud…and that requires a single domain name, and .local just doesn’t do it. I know how it feels to make this change I have had to do it myself and with many customers…it’s a pain but it does give you benefits like SSO
@KefashWhite
@KefashWhite 2 года назад
Gems 💎 keep them coming. Thanks
@AzureAcademy
@AzureAcademy 2 года назад
NICE! Thanks for watching!
@stevedowns8601
@stevedowns8601 2 года назад
Thanks for sharing, Dean!
@AzureAcademy
@AzureAcademy 2 года назад
Happy to help Steve!
@waddid9645
@waddid9645 Год назад
Hi Dean, can this be used on a non AAD or domain joined client? I want to use a Windows 10 IoT thin client running with a kiosk account and using the Remote Desktop Client, subscribe to my resources but when opening a desktop or application remove the second Windows Security prompt. Should that be possible with what you have described in the video? Thanks in advance 👍
@AzureAcademy
@AzureAcademy Год назад
This feature is only for Azure AD joined hosts There is another single sign on method using ADFS see here 👉 ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-_VOEi0cMBvQ.html
@waddid9645
@waddid9645 Год назад
@@AzureAcademy Hi Dean, thanks for the prompt reply. So does the ADFS method work with non domain joined hosts, which would be ideal for a kiosk way of working. Just confirming before going down that route and setting up as I had read some comments from people complaining having to use ADFS as saw is as outdated. Many thanks and great content as always. 👍
@AzureAcademy
@AzureAcademy Год назад
No, SSO requires some kind of Join ADFS requires domain join. Azure AD SSO requires AADJoin or hybrid AVD requires some kind of join option in general And there is no SSO log in support for RDP without some kind of join
@waddid9645
@waddid9645 Год назад
@@AzureAcademy Thanks Dean. Appreciate your help with these answers. 😀
@AzureAcademy
@AzureAcademy Год назад
Anytime
@TheRealJLucas
@TheRealJLucas 2 года назад
You do not mention needing Azure Active Directory Domain Services. does AVD still require AD DS? Also, have you done a video regarding Azure Netapp files? I am the under the assumption that ANF does not require AD DS. What are your thoughts? Thank you for your hard work.
@AzureAcademy
@AzureAcademy 2 года назад
Thanks for watching! Azure AD Domain Services does not work with ANY Single Sign On method. AVD Does NOT require Active Directory. You can implement Azure AD Join for your VMs, which means you only need Azure AD Azure NetApp Files does NOT require Active Directory but it does make things easier. Here is my video on ANF - Happy Learning! 👉ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-bswIbTB62mY.html
@TheRealJLucas
@TheRealJLucas 2 года назад
@@AzureAcademy Excellent. 👍
@AzureAcademy
@AzureAcademy 2 года назад
👍👍
@migueljamous5576
@migueljamous5576 6 месяцев назад
@@AzureAcademy Hi, the problem is that we cannot go full AZure AD join as we are using azure file shares with Azure AD Domain Services for security. there is no support for Azure AD to setup security at the moment for Azure file share or is there a solution?
@AzureAcademy
@AzureAcademy 6 месяцев назад
As a cloud only authenticated file share…yes it can…but not with NTFS like permissions…for that you need a domain controller
@9to511
@9to511 Год назад
Excellent
@AzureAcademy
@AzureAcademy Год назад
Thanks!
@andyhuynh2450
@andyhuynh2450 2 года назад
I followed all the instructions and it still not sso for me.
@AzureAcademy
@AzureAcademy 2 года назад
Do you have the windows 11 22h2 preview build like I said to use And did you set the RDP properties
@andyhuynh2450
@andyhuynh2450 2 года назад
Yes I've set Windows 11 version 22H2 Enterprise multi-session, had rdp properties set under advanced with enablerdsaadauth:i:1. I also created kerberos object as well. When on RDP client, I select the desktop and it still prompting for a password. Greatly appreciated with you can guide me what I did wrong.
@AzureAcademy
@AzureAcademy 2 года назад
Are you using the windows AVD client and is that client using the latest version?
@andyhuynh2450
@andyhuynh2450 2 года назад
@@AzureAcademy I am using the remote desktop and its showing "you're up to date".
@AzureAcademy
@AzureAcademy 2 года назад
Remote Desktop??? Do you mean the windows version of the AVD client? You cannot use the normal RDP client
@gbaity
@gbaity 2 года назад
Will the Kerberos piece work on existing haadj machines for ppl looking to go to aadj full cloud.
@AzureAcademy
@AzureAcademy 2 года назад
Hybrid or AzureAD Join both work as I covered in the video with this new feature. Traditional AD Join will still require ADFS So…yes 100% cloud works!
@gbaity
@gbaity 2 года назад
Just so I’m asking the question right, I mean window machines not AVD session that are HaDJ. Have client in this state currently but wanting to go full cloud with AADJ away from HAADJ.
@AzureAcademy
@AzureAcademy 2 года назад
This feature for so you can connect to your AVD session hosts with SSO. As for AADJ or Hybrid Join outside of AVD...not sure, I haven't had a chance to try it. but the Hybrid / Azure AD Kerberos PowerShell scripts I was showing are for general use...so try it and please let me know!
Далее
Sign In To Azure Virtual Desktop ONCE
22:00
Просмотров 12 тыс.
3 Biggest Mistakes AVD Admins Make (Easy, Simple Fix)
16:07
Шоколадная девочка
00:23
Просмотров 360 тыс.
titan tvman's plan (skibidi toilet 77)
01:00
Просмотров 6 млн
ХОМЯК ВСЕХ КИНУЛ
10:23
Просмотров 480 тыс.
The SECRET to FSLogix | Azure Virtual Desktop
14:18
Просмотров 33 тыс.
Avoid These 3 Mistakes With VM Images
14:04
Просмотров 6 тыс.
How to Configure a Conditional Access Policy for AVD
13:01
The AVD Admins Super Power!!!
10:00
Просмотров 13 тыс.
FSLogix SECRETS Every AVD Admin Should LEARN
9:50
Просмотров 9 тыс.
Azure Virtual Desktop on Azure Stack HCI
27:12
Просмотров 14 тыс.