Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article explains the process of providing host pool access to external identities.
Prerequisites
Before providing host pool access, review the requirements and limitations for external identities.
Provide host pool access for external identities
To provide host pool access for external identities:
Follow the steps to Configure single sign-on for Azure Virtual Desktop using Microsoft Entra authentication to:
- Ensure that single sign-on is enabled in your tenant.
- (Optional) Hide the consent prompt.
Follow the steps to Deploy Microsoft Entra joined VMs with the following considerations:
- You can deploy Entra joined VMs to a new or existing host pool.
- Use an OS image running a supported OS (defined in the requirements and limitations for external identities).
- Ensure you make the following assignments with the Microsoft Entra user group containing the external identities:
- Assign the group to the application group.
- Assign the group either the Virtual Machine User Login or Virtual Machine Administrator Login Azure role-based access control (RBAC) role for each session host VM in the host pool. If you're using a session host configuration, this assignment isn't required.
Configure the host pool to enable single sign-on.
Note
You must enable single sign-on external identities to connect. Connection attempts using legacy authentication protocols will fail.
Note
Using FSLogix profile containers for external identities is in preview.
Connect to Azure Virtual Desktop resources with an external identity
Follow the steps to Manage user accounts in Windows App to sign in to a supported Windows App client with an external identity and connect to Azure Virtual Desktop resources.
Next steps
Learn how to Configure the session lock behavior for Azure Virtual Desktop.
If you encounter any issues, go to Troubleshoot connections to Microsoft Entra joined VMs.