You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For single-session, Intune supports Azure Virtual Desktop VMs that are:
25
20
21
+
- Running Windows Enterprise.
26
22
- Set up as [personal remote desktops](/azure/virtual-desktop/configure-host-pool-personal-desktop-assignment-type) in Azure.
27
23
-[Microsoft Entra hybrid joined](/azure/active-directory/devices/hybrid-azuread-join-plan) and enrolled in Intune in one of the following methods:
28
24
- Configure [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy) to automatically enroll devices that are Microsoft Entra hybrid joined.
@@ -31,15 +27,15 @@ Currently, for single-session, Intune supports Azure Virtual Desktop VMs that ar
31
27
- Microsoft Entra joined and enrolled in Intune by enabling [Enroll the VM with Intune](/azure/virtual-desktop/deploy-azure-ad-joined-vm#deploy-azure-ad-joined-vms) in the Azure portal.
32
28
- Under the same tenant as Intune and in the same region.
33
29
34
-
For more information on Azure Virtual Desktop licensing requirements, see [What is Azure Virtual Desktop?](/azure/virtual-desktop/overview#requirements).
30
+
For more information on Azure Virtual Desktop licensing requirements, see [Licensing Azure Virtual Desktop](/azure/virtual-desktop/licensing).
35
31
36
-
For information about working with multi-session remote desktops, see [Windows 10 or Windows 11 Enterprise multi-session remote desktops](azure-virtual-desktop-multi-session.md).
32
+
For information about working with multi-session remote desktops, see [Windows Enterprise multi-session remote desktops](azure-virtual-desktop-multi-session.md).
37
33
38
-
Intune treats Azure Virtual Desktop personal VMs the same as Windows 10 or Windows 11 Enterprise physical desktops. This treatment lets you use some of your existing configurations and secure the VMs with compliance policy and Conditional Access. Intune management doesn't depend on or interfere with Azure Virtual Desktop management of the same virtual machine.
34
+
Intune treats Azure Virtual Desktop personal VMs the same as Windows Enterprise physical desktops. This treatment lets you use some of your existing configurations and secure the VMs with compliance policy and Conditional Access. Intune management doesn't depend on or interfere with Azure Virtual Desktop management of the same virtual machine.
39
35
40
36
## Limitations
41
37
42
-
There are some limitations to keep in mind when managing Windows 10 Enterprise remote desktops:
38
+
There are some limitations to keep in mind when managing Windows Enterprise remote desktops:
43
39
44
40
### Enrollment
45
41
@@ -58,15 +54,15 @@ Make sure that the [RemoteDesktopServices/AllowUsersToConnectRemotely policy](/w
58
54
59
55
### Cloning physical and virtual devices
60
56
61
-
Intune doesn't support using a cloned image of a computer that is already enrolled. This includes both physical and virtual devices such as Azure Virtual Desktop (AVD). When device enrollment or identity tokens are replicated between devices, Intune device enrollment or synchronization failures will occur.
57
+
Intune doesn't support using a cloned image of a computer that is already enrolled. This includes both physical and virtual devices such as Azure Virtual Desktop (AVD). When device enrollment or identity tokens are replicated between devices, Intune device enrollment or synchronization failures occur.
62
58
63
59
- For more information, see [Mobile device enrollment - Windows Client Management](/windows/client-management/mobile-device-enrollment) and [Certificate authentication device enrollment - Windows Client Management](/windows/client-management/certificate-authentication-device-enrollment).
64
60
- For information on disabling token roaming in AVD, see [Using Azure Virtual Desktop multi-session with Microsoft Intune](azure-virtual-desktop-multi-session.md#prerequisites).
65
61
- For information on troubleshooting issues related to image cloning, see [Error hr 0x8007064c: The machine is already enrolled](/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors#error-hr-0x8007064c-the-machine-is-already-enrolled).
66
62
67
63
### Remote actions
68
64
69
-
The following Windows 10 desktop device remote actions aren't supported/recommended for Azure Virtual Desktop VMs:
65
+
The following Windows desktop device remote actions aren't supported/recommended for Azure Virtual Desktop VMs:
Copy file name to clipboardExpand all lines: intune/intune-service/fundamentals/china-endpoints.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ You can modify proxy server settings on individual client computers. You can als
23
23
24
24
Managed devices require configurations that let **All Users** access services through firewalls.
25
25
26
-
For more information about Windows 10 auto-enrollment and device registration for U.S. customers, see [Windows auto enrollment and device registration ](../enrollment/windows-enrollment-create-cname.md#windows-auto-enrollment-and-device-registration).
26
+
For more information about Windows auto-enrollment and device registration for U.S. customers, see [Windows auto enrollment and device registration ](../enrollment/windows-enrollment-create-cname.md#windows-auto-enrollment-and-device-registration).
27
27
28
28
The following tables list the ports and services that the Intune client accesses:
Copy file name to clipboardExpand all lines: intune/intune-service/fundamentals/china.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -27,12 +27,12 @@ Because the China services are operated by a partner from inside China, there ar
27
27
- Migrations from public clouds to sovereign clouds aren't supported. Customers interested in moving to Intune operated by 21Vianet must migrate manually.
28
28
- The tenant attach feature (syncing devices to Intune without enrollment to support cloud console scenarios) isn't currently supported.
29
29
- Derived Credentials aren't supported with Intune operated by 21Vianet.
30
-
- Management of Windows 10 is supported by using the modern MDM channel.
30
+
- Management of Windows is supported by using the modern MDM channel.
31
31
- Intune operated by 21Vianet doesn't support on-premises Exchange Connector.
32
32
- Windows Autopilot and Business Store features aren't currently available. As part of the 2409 Intune service release, we announced support for Windows Autopilot Device Preparation policy in Intune operated by 21Vianet in China cloud. For more information, see [(What's new in Windows Autopilot device preparation | Microsoft Learn](/autopilot/device-preparation/whats-new#windows-autopilot-device-preparation-deployment-status-report-available-in-the-monitor-tab-under-enrollment)
33
33
- Intune operated by 21Vianet supports the Company Portal for Windows app. Use WinGet to download the Company portal package and dependencies and then deploy as a Line-of-Business app via Intune. [Use the WinGet tool to install and manage applications](/windows/package-manager/winget/).
34
34
- Microsoft Intune Endpoint Analytics and Log Analytics features aren't currently available.
35
-
- Azure Virtual Desktop Windows 10 and Windows 11 multi-session isn't currently supported for 21Vianet.
35
+
- Azure Virtual Desktop Windows multi-session isn't currently supported for 21Vianet.
36
36
- Because Google Mobile Services isn't available in China, customers in Intune operated by 21Vianet can't use features that require Google Mobile Services. These features include:
37
37
- Google Play Protect capabilities such as Play integrity verdict.
Copy file name to clipboardExpand all lines: intune/intune-service/fundamentals/create-custom-role.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -221,7 +221,7 @@ The following permissions are available when creating custom roles.
221
221
| Remote Help app/View screen | View screen allows the helper to view the sharer's device when Remote Help is enabled. |
222
222
| Remote tasks/Bypass activation lock | Remove the Activation Lock from supervised devices without requiring the user's Apple ID and password. This may be required if a user leaves the company and returns the device; without the user's Apple ID and password, there's no way to reactivate the device. Or, you need to reassign some devices to a different department during a device refresh in your organization. You can only reassign devices that don't have Activation Lock enabled. You must also have the Managed Device Read permission to view devices in the Azure portal before initiating this remote task. |
223
223
| Remote tasks/Change organizational unit | Move a Chrome Enterprise device to an existing organizational unit in your Google Workspace domain. |
224
-
| Remote tasks/Clean PC| Initiate a Fresh start device action. This action removes any apps that are installed on a Windows 10 PC that is running the Creators Update. Then, it automatically updates the PC to the latest version of Windows.|
224
+
| Remote tasks/Clean PC| Initiate a Fresh start device action. This action removes any apps that are installed on a Windows device. |
| Remote tasks/Disable lost mode| Turn off the lost mode for an iOS device. |
227
227
| Remote tasks/Enable lost mode | Initiate lost mode on lost or stolen iOS devices. This mode lets you enter a message and a phone number that appears on the lock screen of the device. To use lost mode, the device must be a corporate-owned iOS device that is in supervised mode. |
Copy file name to clipboardExpand all lines: intune/intune-service/fundamentals/deployment-guide-enrollment-windows.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,7 +58,7 @@ You can use this enrollment option to:
58
58
| --- | --- |
59
59
| You use Windows client. | ✅ <br/><br/> Configuration Manager supports Windows Server. |
60
60
| You have Microsoft Entra ID P1 or P2 | ✅ |
61
-
| You'll use Conditional Access (CA) on devices enrolled using [bulk enrollment](../enrollment/windows-bulk-enroll.md) with a provisioning package. | ✅ On Windows 11 and Windows 10 1803+, CA is available for Windows devices enrolled using bulk enrollment. <br/><br/> ❌ On Windows 10 1709 and older, CA isn't available for Windows devices enrolled using bulk enrollment. |
61
+
| You'll use Conditional Access (CA) on devices enrolled using [bulk enrollment](../enrollment/windows-bulk-enroll.md) with a provisioning package. | ✅ On Windows, CA is available for Windows devices enrolled using bulk enrollment. |
62
62
| You have remote workers. | ✅ |
63
63
| Devices are personal or BYOD. | ✅ <br/><br/> ❌ If you use Group Policy, then bulk enrollment and automatic enrollment are for corporate-owned devices, not personal or BYOD. |
64
64
| Devices are owned by the organization or school. | ✅ |
@@ -176,7 +176,7 @@ For more information about Windows Autopilot, go to [Windows Autopilot overview]
176
176
| Devices are Microsoft Entra hybrid joined. | ✅ <br/><br/> Microsoft Entra hybrid joined devices are joined to your on-premises Active Directory, and registered with your Microsoft Entra ID. Devices in Microsoft Entra ID are available to Intune. Devices that aren't registered in Microsoft Entra ID aren't available to Intune. <br/><br/>A full Microsoft Entra joined solution might be better for your organization. For more information, go to the [Success with remote Windows Autopilot and Microsoft Entra hybrid join](https://techcommunity.microsoft.com/t5/intune-customer-success/success-with-remote-windows-autopilot-and-hybrid-azure-active/ba-p/2749353) blog.|
177
177
| You have remote workers. | ✅ <br/><br/> The OEM or partner can send devices directly to your users.|
178
178
| Devices are owned by the organization or school. | ✅ |
179
-
| You have new or existing devices. | ✅ <br/><br/> You can update existing desktops running older Windows versions, like Windows 7, to Windows 10. This option also uses Microsoft Configuration Manager. |
179
+
| You have new or existing devices. | ✅ <br/><br/> You can update existing desktops running older Windows versions. This option also uses Microsoft Configuration Manager. |
180
180
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✅ |
181
181
| You have Microsoft Entra ID P1 or P2. | ✅ <br/><br/> Windows Autopilot uses Automatic enrollment. Automatic enrollment requires Microsoft Entra ID P1 or P2. |
182
182
| Devices are associated with a single user. | ✅ |
Copy file name to clipboardExpand all lines: intune/intune-service/fundamentals/deployment-guide-platform-windows.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -78,7 +78,7 @@ Use Microsoft Intune to enable or disable Windows settings and features on devic
78
78
|[Configure Wi-Fi profile](../configuration/wi-fi-settings-configure.md)|This profile enables people to find and connect to your organization's Wi-Fi network. For a description of the settings in this area, see the [Wi-Fi settings reference for Windows](../configuration/wi-fi-settings-windows.md).|
79
79
|[Configure VPN profile](../configuration/vpn-settings-configure.md)|Set up a secure VPN option, such as Microsoft Tunnel, for people connecting to your organization's network. For a description of the settings in this area, see the [VPN settings reference](../configuration/vpn-settings-windows-10.md). |
80
80
|[Configure email profile](../configuration/email-settings-configure.md)|Configure email settings so that people can connect to a mail server and access their work or school email. For a description of the settings in this area, see the [email settings reference](../configuration/email-settings-windows-10.md).|
81
-
|[Restrict device features](../configuration/device-restrictions-configure.md)|Protect users from unauthorized access and distractions by limiting the device features they can use at work or school. For a description of the settings in this area, see the [device restrictions reference for Windows](../configuration/device-restrictions-windows-10.md) and [Windows 10 Teams](../configuration/device-restrictions-windows-10-teams.md). |
81
+
|[Restrict device features](../configuration/device-restrictions-configure.md)|Protect users from unauthorized access and distractions by limiting the device features they can use at work or school. For a description of the settings in this area, see the [device restrictions reference for Windows](../configuration/device-restrictions-windows-10.md). |
82
82
|[Configure custom profile](../configuration/custom-settings-configure.md)|Add and assign device settings and features that aren't built into Intune. For a description of the settings in this area, see the [custom settings reference](../configuration/custom-settings-windows-10.md).|
83
83
|[Configure BIOS settings](../configuration/device-firmware-configuration-interface-windows.md)|Set up Intune so that you can control UEFI (BIOS) settings on enrolled devices, using the Device Firmware Configuration Interface (DFCI)|
84
84
|[Configure Domain Join](../configuration/domain-join-configure.md)|If you're planning to enroll Microsoft Entra joined devices, be sure to create a domain join profile so that Intune knows which on-premises domain to join.|
0 commit comments