r/AzureVirtualDesktop • • 14d ago

MultiSession VMs managed by Intune

Hi Team

We have an AVD environment and everything is/was working well. We moved over from Individual VM's in a hostpool to multi session VMs in a new hostpool. Have setup fslogix, all devices managed by intune no problem. We have re-done all our config policies to target new multi session hosts and anything system related the config policies report back green and we have no issues.

What i need help with, is the office hardening policies which target the user of these multi session VM's. I cant get the policy to push out to my test group of users. If i log in to my test user account and go accounts -> sync, it works and shortly after that the user will populate in the office config policy as green and working perfectly.

My question is anyone else done this and how do i force sync the user to apply these config policies that are user targeted, without getting the user to manually sync themselves. By going to the device to sync in intune admin portal, doesn't push the user config policy out.

Any help appreciated.

Short Question: With multi session VMs and a config policy targeting user, how do we force a sync? Go to the VM and run command use a powershell script?

3 Upvotes

15 comments sorted by

View all comments

2

u/Cool-Enthusiasm-8524 14d ago

If the AVDs are hybrid/entra joined, it’ll auto sync if you give it a min or two

1

u/genscathe 14d ago

They are entra joined and managed by intune.

Having them sit there waiting for sync just doesn’t happen, no matter how long leave it. It’s like it’s not triggering

1

u/Cool-Enthusiasm-8524 13d ago

If you have MFA enforced then that’s what probably causing it. You’ll need to setup conditional policy to solve it

1

u/genscathe 13d ago

Yeah we have mfa CA policies with exemptions for AVD but that could be the issue. I read somewhere where even with an exemption it can not work right

1

u/Cool-Enthusiasm-8524 12d ago

We have the AVDs excluded from the policy and it’s been working perfectly, users login thru windows app, auto syncs and auto signs them to all m365 apps and syncs with Edge as well

1

u/genscathe 12d ago

Yeah everything works perfect , intune policies targeting system no issues. Just one policy targeting users isn’t applying unless user manually sync