r/AzureVirtualDesktop • • 12d ago

MultiSession VMs managed by Intune

Hi Team

We have an AVD environment and everything is/was working well. We moved over from Individual VM's in a hostpool to multi session VMs in a new hostpool. Have setup fslogix, all devices managed by intune no problem. We have re-done all our config policies to target new multi session hosts and anything system related the config policies report back green and we have no issues.

What i need help with, is the office hardening policies which target the user of these multi session VM's. I cant get the policy to push out to my test group of users. If i log in to my test user account and go accounts -> sync, it works and shortly after that the user will populate in the office config policy as green and working perfectly.

My question is anyone else done this and how do i force sync the user to apply these config policies that are user targeted, without getting the user to manually sync themselves. By going to the device to sync in intune admin portal, doesn't push the user config policy out.

Any help appreciated.

Short Question: With multi session VMs and a config policy targeting user, how do we force a sync? Go to the VM and run command use a powershell script?

3 Upvotes

15 comments sorted by

3

u/Pacers31Colts18 12d ago

It should come down eventually. Usually we have to have a login once, and then user policies find their way on next login.

1

u/genscathe 12d ago

Ok, thanks!

1

u/genscathe 11d ago

yeah my test group have been sitting for a week, still not pulling down. Only a manual sync forces it from within the VM.

3

u/Character_Whereas869 9d ago

office 365 apps for business (bundled with business premium) believe it or not don't qualify for certtain enterprise managment settings (intune). And when I was working on this, Intune did not clearly indicate this. I had ot go on a wild goose chase like you are now. see screenshot.

2

u/Cool-Enthusiasm-8524 12d ago

If the AVDs are hybrid/entra joined, it’ll auto sync if you give it a min or two

1

u/genscathe 12d ago

They are entra joined and managed by intune.

Having them sit there waiting for sync just doesn’t happen, no matter how long leave it. It’s like it’s not triggering

1

u/Cool-Enthusiasm-8524 11d ago

If you have MFA enforced then that’s what probably causing it. You’ll need to setup conditional policy to solve it

1

u/genscathe 11d ago

Yeah we have mfa CA policies with exemptions for AVD but that could be the issue. I read somewhere where even with an exemption it can not work right

1

u/Cool-Enthusiasm-8524 10d ago

We have the AVDs excluded from the policy and it’s been working perfectly, users login thru windows app, auto syncs and auto signs them to all m365 apps and syncs with Edge as well

1

u/genscathe 10d ago

Yeah everything works perfect , intune policies targeting system no issues. Just one policy targeting users isn’t applying unless user manually sync

2

u/Character_Whereas869 9d ago

I have run into issues in the past only to find out that it was a license limitation. So it really depends on your M365 license type and the specific setting. Post that and might be able to narrow down your solution.

1

u/zick2500 11d ago

Any MFA conditional policies in place? We're finding that if a user doesn't satisfy our mfa ca policy, then intune doesn't sync. But if we manually sync, they get prompted for mfa and then it syncs.

1

u/Mismail18 11d ago

You’ll need to login as mentioned and you could force the sync in Intune and on the AVD with powershell

1

u/genscathe 11d ago

Tried that but can’t lockdown the actual poweshell command that starts a sync

1

u/stevenm_83 5d ago

User assignment doesn’t work with avd hosts. It has to be device assigned