Skip to content

Commit d5af6c0

Browse files
Merge pull request #18938 from MicrosoftDocs/main
[AutoPublish] main to live - 10/14 10:29 PDT | 10/14 22:59 IST
2 parents 9b68062 + 75a3a35 commit d5af6c0

36 files changed

+264
-408
lines changed

.openpublishing.redirection.intune.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1857,7 +1857,7 @@
18571857
},
18581858
{
18591859
"source_path": "intune/intune/fundamentals/intune-legacy-pc-client.md",
1860-
"redirect_url": "/intune/intune-service/fundamentals/intune-legacy-pc-client",
1860+
"redirect_url": "/intune/intune-service/fundamentals/tutorial-walkthrough-endpoint-manager",
18611861
"redirect_document_id": false
18621862
},
18631863
{

.openpublishing.redirection.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,11 @@
11
{
22
"redirections": [
33

4-
4+
{
5+
"source_path": "intune/intune-service/fundamentals/intune-legacy-pc-client.md",
6+
"redirect_url": "/intune/intune-service/fundamentals/tutorial-walkthrough-endpoint-manager",
7+
"redirect_document_id": false
8+
},
59
{
610
"source_path": "intune/intune-service/copilot/security-copilot-surface-portal.md",
711
"redirect_url": "/surface/security-copilot-surface-management-portal",

intune/intune-service/fundamentals/azure-virtual-desktop-multi-session.md

Lines changed: 36 additions & 43 deletions
Large diffs are not rendered by default.

intune/intune-service/fundamentals/azure-virtual-desktop.md

Lines changed: 9 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Using Azure Virtual Desktop single-session with Microsoft Intune
33
description: Guidelines for using Azure Virtual Desktop single-session with Microsoft Intune.
44
author: MandiOhlinger
55
ms.author: mandia
6-
ms.date: 02/13/2025
6+
ms.date: 10/14/2025
77
ms.topic: article
88
ms.reviewer: madakeva
99
ms.collection:
@@ -16,13 +16,9 @@ ms.collection:
1616

1717
## Prerequisites
1818

19-
Currently, for single-session, Intune supports Azure Virtual Desktop VMs that are:
20-
21-
- Running Windows 10 Enterprise, version 1809 or later, or running Windows 11.
22-
23-
> [!IMPORTANT]
24-
> [!INCLUDE [windows-10-support](../includes/windows-10-support.md)]
19+
For single-session, Intune supports Azure Virtual Desktop VMs that are:
2520

21+
- Running Windows Enterprise.
2622
- Set up as [personal remote desktops](/azure/virtual-desktop/configure-host-pool-personal-desktop-assignment-type) in Azure.
2723
- [Microsoft Entra hybrid joined](/azure/active-directory/devices/hybrid-azuread-join-plan) and enrolled in Intune in one of the following methods:
2824
- Configure [Active Directory group policy](/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy) to automatically enroll devices that are Microsoft Entra hybrid joined.
@@ -31,15 +27,15 @@ Currently, for single-session, Intune supports Azure Virtual Desktop VMs that ar
3127
- Microsoft Entra joined and enrolled in Intune by enabling [Enroll the VM with Intune](/azure/virtual-desktop/deploy-azure-ad-joined-vm#deploy-azure-ad-joined-vms) in the Azure portal.
3228
- Under the same tenant as Intune and in the same region.
3329

34-
For more information on Azure Virtual Desktop licensing requirements, see [What is Azure Virtual Desktop?](/azure/virtual-desktop/overview#requirements).
30+
For more information on Azure Virtual Desktop licensing requirements, see [Licensing Azure Virtual Desktop](/azure/virtual-desktop/licensing).
3531

36-
For information about working with multi-session remote desktops, see [Windows 10 or Windows 11 Enterprise multi-session remote desktops](azure-virtual-desktop-multi-session.md).
32+
For information about working with multi-session remote desktops, see [Windows Enterprise multi-session remote desktops](azure-virtual-desktop-multi-session.md).
3733

38-
Intune treats Azure Virtual Desktop personal VMs the same as Windows 10 or Windows 11 Enterprise physical desktops. This treatment lets you use some of your existing configurations and secure the VMs with compliance policy and Conditional Access. Intune management doesn't depend on or interfere with Azure Virtual Desktop management of the same virtual machine.
34+
Intune treats Azure Virtual Desktop personal VMs the same as Windows Enterprise physical desktops. This treatment lets you use some of your existing configurations and secure the VMs with compliance policy and Conditional Access. Intune management doesn't depend on or interfere with Azure Virtual Desktop management of the same virtual machine.
3935

4036
## Limitations
4137

42-
There are some limitations to keep in mind when managing Windows 10 Enterprise remote desktops:
38+
There are some limitations to keep in mind when managing Windows Enterprise remote desktops:
4339

4440
### Enrollment
4541

@@ -58,15 +54,15 @@ Make sure that the [RemoteDesktopServices/AllowUsersToConnectRemotely policy](/w
5854

5955
### Cloning physical and virtual devices
6056

61-
Intune doesn't support using a cloned image of a computer that is already enrolled. This includes both physical and virtual devices such as Azure Virtual Desktop (AVD). When device enrollment or identity tokens are replicated between devices, Intune device enrollment or synchronization failures will occur.
57+
Intune doesn't support using a cloned image of a computer that is already enrolled. This includes both physical and virtual devices such as Azure Virtual Desktop (AVD). When device enrollment or identity tokens are replicated between devices, Intune device enrollment or synchronization failures occur.
6258

6359
- For more information, see [Mobile device enrollment - Windows Client Management](/windows/client-management/mobile-device-enrollment) and [Certificate authentication device enrollment - Windows Client Management](/windows/client-management/certificate-authentication-device-enrollment).
6460
- For information on disabling token roaming in AVD, see [Using Azure Virtual Desktop multi-session with Microsoft Intune](azure-virtual-desktop-multi-session.md#prerequisites).
6561
- For information on troubleshooting issues related to image cloning, see [Error hr 0x8007064c: The machine is already enrolled](/troubleshoot/mem/intune/troubleshoot-windows-enrollment-errors#error-hr-0x8007064c-the-machine-is-already-enrolled).
6662

6763
### Remote actions
6864

69-
The following Windows 10 desktop device remote actions aren't supported/recommended for Azure Virtual Desktop VMs:
65+
The following Windows desktop device remote actions aren't supported/recommended for Azure Virtual Desktop VMs:
7066

7167
- Windows Autopilot reset
7268
- BitLocker key rotation

intune/intune-service/fundamentals/china-endpoints.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ You can modify proxy server settings on individual client computers. You can als
2323

2424
Managed devices require configurations that let **All Users** access services through firewalls.
2525

26-
For more information about Windows 10 auto-enrollment and device registration for U.S. customers, see [Windows auto enrollment and device registration ](../enrollment/windows-enrollment-create-cname.md#windows-auto-enrollment-and-device-registration).
26+
For more information about Windows auto-enrollment and device registration for U.S. customers, see [Windows auto enrollment and device registration ](../enrollment/windows-enrollment-create-cname.md#windows-auto-enrollment-and-device-registration).
2727

2828
The following tables list the ports and services that the Intune client accesses:
2929

intune/intune-service/fundamentals/china.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,12 +27,12 @@ Because the China services are operated by a partner from inside China, there ar
2727
- Migrations from public clouds to sovereign clouds aren't supported. Customers interested in moving to Intune operated by 21Vianet must migrate manually.
2828
- The tenant attach feature (syncing devices to Intune without enrollment to support cloud console scenarios) isn't currently supported.
2929
- Derived Credentials aren't supported with Intune operated by 21Vianet.
30-
- Management of Windows 10 is supported by using the modern MDM channel.
30+
- Management of Windows is supported by using the modern MDM channel.
3131
- Intune operated by 21Vianet doesn't support on-premises Exchange Connector.
3232
- Windows Autopilot and Business Store features aren't currently available. As part of the 2409 Intune service release, we announced support for Windows Autopilot Device Preparation policy in Intune operated by 21Vianet in China cloud. For more information, see [(What's new in Windows Autopilot device preparation | Microsoft Learn](/autopilot/device-preparation/whats-new#windows-autopilot-device-preparation-deployment-status-report-available-in-the-monitor-tab-under-enrollment)
3333
- Intune operated by 21Vianet supports the Company Portal for Windows app. Use WinGet to download the Company portal package and dependencies and then deploy as a Line-of-Business app via Intune. [Use the WinGet tool to install and manage applications](/windows/package-manager/winget/).
3434
- Microsoft Intune Endpoint Analytics and Log Analytics features aren't currently available.
35-
- Azure Virtual Desktop Windows 10 and Windows 11 multi-session isn't currently supported for 21Vianet.
35+
- Azure Virtual Desktop Windows multi-session isn't currently supported for 21Vianet.
3636
- Because Google Mobile Services isn't available in China, customers in Intune operated by 21Vianet can't use features that require Google Mobile Services. These features include:
3737
- Google Play Protect capabilities such as Play integrity verdict.
3838
- Managing apps from the Google Play Store.

intune/intune-service/fundamentals/cloud-configuration.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ Using Microsoft Intune, you can use a guided scenario to deploy a cloud configur
109109
Open the guided scenario:
110110

111111
1. Open the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
112-
2. Select **Troubleshooting + support** > **Guided scenarios** > **Deploy Windows 10 and later in cloud configuration** > **Start**.
112+
2. Select **Troubleshooting + support** > **Guided scenarios** > **Deploy Windows in cloud configuration** > **Start**.
113113
3. In **Introduction**, select **Next**.
114114

115115
## Step 2 - Basics

intune/intune-service/fundamentals/create-custom-role.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -221,7 +221,7 @@ The following permissions are available when creating custom roles.
221221
| Remote Help app/View screen | View screen allows the helper to view the sharer's device when Remote Help is enabled. |
222222
| Remote tasks/Bypass activation lock | Remove the Activation Lock from supervised devices without requiring the user's Apple ID and password. This may be required if a user leaves the company and returns the device; without the user's Apple ID and password, there's no way to reactivate the device. Or, you need to reassign some devices to a different department during a device refresh in your organization. You can only reassign devices that don't have Activation Lock enabled. You must also have the Managed Device Read permission to view devices in the Azure portal before initiating this remote task. |
223223
| Remote tasks/Change organizational unit | Move a Chrome Enterprise device to an existing organizational unit in your Google Workspace domain. |
224-
| Remote tasks/Clean PC| Initiate a Fresh start device action. This action removes any apps that are installed on a Windows 10 PC that is running the Creators Update. Then, it automatically updates the PC to the latest version of Windows.|
224+
| Remote tasks/Clean PC| Initiate a Fresh start device action. This action removes any apps that are installed on a Windows device. |
225225
| Remote tasks/Collect diagnostics | Collect device diagnostics |
226226
| Remote tasks/Disable lost mode| Turn off the lost mode for an iOS device. |
227227
| Remote tasks/Enable lost mode | Initiate lost mode on lost or stolen iOS devices. This mode lets you enter a message and a phone number that appears on the lock screen of the device. To use lost mode, the device must be a corporate-owned iOS device that is in supervised mode. |

intune/intune-service/fundamentals/deployment-guide-enrollment-windows.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ You can use this enrollment option to:
5858
| --- | --- |
5959
| You use Windows client. | ✅ <br/><br/> Configuration Manager supports Windows Server. |
6060
| You have Microsoft Entra ID P1 or P2 ||
61-
| You'll use Conditional Access (CA) on devices enrolled using [bulk enrollment](../enrollment/windows-bulk-enroll.md) with a provisioning package. | ✅ On Windows 11 and Windows 10 1803+, CA is available for Windows devices enrolled using bulk enrollment. <br/><br/> ❌ On Windows 10 1709 and older, CA isn't available for Windows devices enrolled using bulk enrollment. |
61+
| You'll use Conditional Access (CA) on devices enrolled using [bulk enrollment](../enrollment/windows-bulk-enroll.md) with a provisioning package. | ✅ On Windows, CA is available for Windows devices enrolled using bulk enrollment. |
6262
| You have remote workers. ||
6363
| Devices are personal or BYOD. | ✅ <br/><br/> ❌ If you use Group Policy, then bulk enrollment and automatic enrollment are for corporate-owned devices, not personal or BYOD. |
6464
| Devices are owned by the organization or school. ||
@@ -176,7 +176,7 @@ For more information about Windows Autopilot, go to [Windows Autopilot overview]
176176
| Devices are Microsoft Entra hybrid joined. | ✅ <br/><br/> Microsoft Entra hybrid joined devices are joined to your on-premises Active Directory, and registered with your Microsoft Entra ID. Devices in Microsoft Entra ID are available to Intune. Devices that aren't registered in Microsoft Entra ID aren't available to Intune. <br/><br/>A full Microsoft Entra joined solution might be better for your organization. For more information, go to the [Success with remote Windows Autopilot and Microsoft Entra hybrid join](https://techcommunity.microsoft.com/t5/intune-customer-success/success-with-remote-windows-autopilot-and-hybrid-azure-active/ba-p/2749353) blog.|
177177
| You have remote workers. | ✅ <br/><br/> The OEM or partner can send devices directly to your users.|
178178
| Devices are owned by the organization or school. ||
179-
| You have new or existing devices. | ✅ <br/><br/> You can update existing desktops running older Windows versions, like Windows 7, to Windows 10. This option also uses Microsoft Configuration Manager. |
179+
| You have new or existing devices. | ✅ <br/><br/> You can update existing desktops running older Windows versions. This option also uses Microsoft Configuration Manager. |
180180
| Need to enroll a few devices, or a large number of devices (bulk enrollment). ||
181181
| You have Microsoft Entra ID P1 or P2. | ✅ <br/><br/> Windows Autopilot uses Automatic enrollment. Automatic enrollment requires Microsoft Entra ID P1 or P2. |
182182
| Devices are associated with a single user. ||

intune/intune-service/fundamentals/deployment-guide-platform-windows.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ Use Microsoft Intune to enable or disable Windows settings and features on devic
7878
|[Configure Wi-Fi profile](../configuration/wi-fi-settings-configure.md)|This profile enables people to find and connect to your organization's Wi-Fi network. For a description of the settings in this area, see the [Wi-Fi settings reference for Windows](../configuration/wi-fi-settings-windows.md).|
7979
|[Configure VPN profile](../configuration/vpn-settings-configure.md)|Set up a secure VPN option, such as Microsoft Tunnel, for people connecting to your organization's network. For a description of the settings in this area, see the [VPN settings reference](../configuration/vpn-settings-windows-10.md). |
8080
|[Configure email profile](../configuration/email-settings-configure.md)|Configure email settings so that people can connect to a mail server and access their work or school email. For a description of the settings in this area, see the [email settings reference](../configuration/email-settings-windows-10.md).|
81-
|[Restrict device features](../configuration/device-restrictions-configure.md)|Protect users from unauthorized access and distractions by limiting the device features they can use at work or school. For a description of the settings in this area, see the [device restrictions reference for Windows](../configuration/device-restrictions-windows-10.md) and [Windows 10 Teams](../configuration/device-restrictions-windows-10-teams.md). |
81+
|[Restrict device features](../configuration/device-restrictions-configure.md)|Protect users from unauthorized access and distractions by limiting the device features they can use at work or school. For a description of the settings in this area, see the [device restrictions reference for Windows](../configuration/device-restrictions-windows-10.md). |
8282
|[Configure custom profile](../configuration/custom-settings-configure.md)|Add and assign device settings and features that aren't built into Intune. For a description of the settings in this area, see the [custom settings reference](../configuration/custom-settings-windows-10.md).|
8383
|[Configure BIOS settings](../configuration/device-firmware-configuration-interface-windows.md)|Set up Intune so that you can control UEFI (BIOS) settings on enrolled devices, using the Device Firmware Configuration Interface (DFCI)|
8484
|[Configure Domain Join](../configuration/domain-join-configure.md)|If you're planning to enroll Microsoft Entra joined devices, be sure to create a domain join profile so that Intune knows which on-premises domain to join.|

0 commit comments

Comments
 (0)