Discover the Power of AVD SSO: What You Must Know!

If you’re managing Azure Virtual Desktop (AVD) environments, you’ve probably noticed how frustrating it can be for users to sign in twice, once to the AVD client and again to the session host. This extra step isn’t just annoying; it can lead users to save credentials in insecure ways. The good news? You can eliminate that second login by enabling Single Sign-On (SSO) using Microsoft Entra and Windows 11.

In this blog post and the accompanying YouTube video, you’ll learn how to configure SSO for AVD step-by-step, following Microsoft’s official documentation. Whether you’re working with Hybrid Joined or Entra ID Joined session hosts, this guide will help you streamline the login experience and improve security across your environment.

AVD SSO

In this blog post and the accompanying YouTube video, you’ll learn how to configure SSO for AVD step-by-step, following Microsoft’s official documentation. Whether you’re working with Hybrid Joined or Entra ID Joined session hosts, this guide will help you streamline the login experience and improve security across your environment.

Why Enable SSO in AVD?

SSO allows users to authenticate once and seamlessly access their AVD session without re-entering credentials. It improves user experience, reduces friction, and aligns with modern identity and access management practices. This is especially valuable in hybrid cloud setups where Windows AD and Entra ID coexist.

  • Creating a dynamic group for session hosts
  • Enabling Microsoft Entra Authentication for RDP
  • Hiding the consent prompt for trusted devices
  • Creating a Kerberos Server Object for hybrid environments
  • Reviewing and aligning Conditional Access Policies
  • Enabling SSO at the host pool level
  • Testing and verifying the setup

What You’ll Learn

The video walks through each configuration step with screen-recorded demos, including:

  • Creating a dynamic group for session hosts
  • Enabling Microsoft Entra Authentication for RDP
  • Hiding the consent prompt for trusted devices
  • Creating a Kerberos Server Object for hybrid environments
  • Reviewing and aligning Conditional Access Policies
  • Enabling SSO at the host pool level
  • Testing and verifying the setup

Requirements

To follow along, you’ll need:

  • Entra roles: Application Administrator or Cloud Application Administrator
  • Domain and Enterprise Admin rights (if using Windows AD)
  • Session hosts running Windows 11, Windows 10 Enterprise, or Windows Server 2022
  • Hosts must be Entra Joined or Hybrid Joined (Entra Domain Services is not supported)
  • Entra ID P1 or P2 licensing (recommended for dynamic groups and Conditional Access)

SSO is supported on the Windows App across Windows, macOS, iOS, and the web. The Remote Desktop Client is also supported but deprecated—so stick with the Windows App.

Links

Zero to Hero with Azure Virtual Desktop
https://www.udemy.com/course/zero-to-hero-with-windows-virtual-desktop/?referralCode=B2FE49E6FCEE7A7EA8D4

A Beginner’s Guide to the AZ-900
https://www.udemy.com/course/beginners-guide-az-900/?referralCode=C74C266B74E837F86969

Hybrid Identity with Windows AD and Azure AD
https://www.udemy.com/course/hybrid-identity-and-azure-active-directory/?referralCode=7F62C4C6FD05C73ACCC3

Windows 365 Enterprise and Intune Management
https://www.udemy.com/course/windows-365-enterprise-and-intune-management/?referralCode=4A1ED105341D0AA20D2E

Create a Dynamic Group
https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership?WT.mc_id=AZ-MVP-5004159

Enable Microsoft Entra Auth for RDP
https://learn.microsoft.com/en-us/azure/virtual-desktop/configure-single-sign-on?WT.mc_id=AZ-MVP-5004159#enable-microsoft-entra-authentication-for-rdp

Hide the Consent Prompt
https://learn.microsoft.com/en-us/azure/virtual-desktop/configure-single-sign-on?WT.mc_id=AZ-MVP-5004159#hide-the-consent-prompt-dialog

Create a Kerberos Server Object
https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-passwordless-security-key-on-premises?WT.mc_id=AZ-MVP-5004159#install-the-azureadhybridauthenticationmanagement-module

Review Conditional Access Policies
https://learn.microsoft.com/en-us/azure/virtual-desktop/set-up-mfa?tabs=avd&WT.mc_id=AZ-MVP-5004159#prerequisites

Enable Single Sign-On at the Host Pool
https://learn.microsoft.com/en-us/azure/virtual-desktop/configure-single-sign-on?WT.mc_id=AZ-MVP-5004159#configure-your-host-pool-to-enable-single-sign-on

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Click Here!
Scroll to Top