Enforce Microsoft Entra multifactor authentication for Azure Virtual Desktop using Conditional Access

Users can sign into Azure Virtual Desktop from anywhere using different devices and clients. However, there are certain measures you should take to help keep your environment and your users safe. Using Microsoft Entra multifactor authentication (MFA) with Azure Virtual Desktop prompts users during the sign-in process for another form of identification in addition to their username and password. You can enforce MFA for Azure Virtual Desktop using Conditional Access, and can also configure whether it applies to the web client, mobile apps, desktop clients, or all clients.

When a user connects to a remote session, they need to authenticate to the Azure Virtual Desktop service and the session host. If MFA is enabled, it's used when connecting to the Azure Virtual Desktop service and the user is prompted for their user account and a second form of authentication, in the same way as accessing other services. When a user starts a remote session, a username and password is required for the session host, but this is seamless to the user if single sign-on (SSO) is enabled. For more information, see Authentication methods.

How often a user is prompted to reauthenticate depends on Microsoft Entra Conditional Access adaptive session lifetime policies. While remembering credentials is convenient, it can also make deployments using personal devices less secure. To protect your users, you can make sure the client asks for Microsoft Entra multi-factor authentication credentials more frequently. You can use Conditional Access sign-in frequency to configure this behavior.

Learn how to enforce MFA for Azure Virtual Desktop and optionally configure sign-in frequency in the following sections.

Prerequisites

Here's what you need to get started:

Create a Conditional Access policy

Here's how to create a Conditional Access policy that requires multifactor authentication when connecting to Azure Virtual Desktop:

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.

  2. Browse to Protection > Conditional Access > Policies.

  3. Select New policy.

  4. Give your policy a name. We recommend that organizations create a meaningful standard for the names of their policies.

  5. Under Assignments > Users, select 0 users and groups selected.

  6. Under the Include tab, select Select users and groups and check Users and groups, then under Select, select 0 users and groups selected.

  7. On the new pane that opens, search for and choose the group that contains your Azure Virtual Desktop users as group members, then select Select.

  8. Under Assignments > Target resources, select No target resources selected.

  9. For the drop-down list Select what this policy applies to, leave the default of Resources (formerly cloud apps). Under the Include tab, select Select resources, then under Select, select None.

  10. On the new pane that opens, search for and select the necessary apps based on the resources you're trying to protect. Select the relevant tab for your scenario. When searching for an application name on Azure, use search terms that begin with the application name in order instead of keywords the application name contains out of order. For example, when you want to use Azure Virtual Desktop, you need to enter 'Azure Virtual', in that order. If you enter 'virtual' by itself, the search doesn't return the desired application.

    For Azure Virtual Desktop (based on Azure Resource Manager), you can configure MFA on these different apps:

    • Azure Virtual Desktop (app ID 9cdead84-a844-4324-93f2-b2e6bb768d07), which applies when the user subscribes to Azure Virtual Desktop, authenticates to the Azure Virtual Desktop Gateway during a connection, and when diagnostics information is sent to the service from the user's local device.

      Tip

      The app name was previously Windows Virtual Desktop. If you registered the Microsoft.DesktopVirtualization resource provider before the display name changed, the application will be named Windows Virtual Desktop with the same app ID as Azure Virtual Desktop.

    • Windows Cloud Login (app ID 270efc09-cd0d-444b-a71f-39af4910ec45), which applies when the user authenticates to the session host when single sign-on is enabled. We recommended you match conditional access policies between these apps and the Azure Virtual Desktop app, except for the sign-in frequency.

      Important

      • If you Connect to Azure Virtual Desktop with thin clients, contact your client's provider to confirm you should be using the Windows Cloud Login for Conditional Access policies for single sign-on connections.

      • Don't select the app called Azure Virtual Desktop Azure Resource Manager Provider (app ID 50e95039-b200-4007-bc97-8d5790743a63). This app is only used for retrieving the user feed and shouldn't have multifactor authentication.

  11. Once you selected your apps, select Select.

    A screenshot of the Conditional Access Cloud apps or actions page. The Azure Virtual Desktop app is shown.

  12. Under Assignments > Conditions, select 0 conditions select.

  13. Under Client apps, select Not configured.

  14. On the new pane that opens, for Configure, select Yes.

  15. Select the client apps this policy applies to:

    • Select Browser if you want the policy to apply to the web client.
    • Select Mobile apps and desktop clients if you want to apply the policy to other clients.
    • Select both check boxes if you want to apply the policy to all clients.
    • Deselect values for legacy authentication clients.

    A screenshot of the Conditional Access Client apps page. The user has selected the mobile apps and desktop clients, and browser check boxes.

  16. Once you selected the client apps this policy applies to, select Done.

  17. Under Access controls > Grant, select 0 controls selected.

  18. On the new pane that opens, select Grant access.

  19. Check Require multifactor authentication, and then select Select.

  20. At the bottom of the page, set Enable policy to On and select Create.

Note

When you use the web client to sign in to Azure Virtual Desktop through your browser, the log will list the client app ID as a85cf173-4192-42f8-81fa-777a763e6e2c (Azure Virtual Desktop client). This is because the client app is internally linked to the server app ID where the conditional access policy was set.

Tip

Some users may see a prompt titled Stay signed in to all your apps if the Windows device they're using is not already registered with Microsoft Entra ID. If they deselect Allow my organization to manage my device and select No, sign in to this app only, they may be prompted for authentication more frequently.

Configure sign-in frequency

Sign-in frequency policies let you configure how often users are required to sign-in when accessing Microsoft Entra-based resources. This can help secure your environment and is especially important for personal devices, where the local OS may not require MFA or may not lock automatically after inactivity. Users are prompted to authenticate only when a new access token is requested from Microsoft Entra ID when accessing a resource.

Sign-in frequency policies result in different behavior based on the Microsoft Entra app selected:

App name App ID Behavior
Azure Virtual Desktop 9cdead84-a844-4324-93f2-b2e6bb768d07 Enforces reauthentication when a user subscribes to Azure Virtual Desktop, manually refreshes their list of resources and authenticates to the Azure Virtual Desktop Gateway during a connection.

Once the reauthentication period is over, background feed refresh and diagnostics upload silently fails until a user completes their next interactive sign in to Microsoft Entra.
Windows Cloud Login 270efc09-cd0d-444b-a71f-39af4910ec45 Enforces reauthentication when a user signs in to a session host when single sign-on is enabled.

To configure the time period after which a user is asked to sign-in again:

  1. Open the policy you created previously.
  2. Under Access controls > Session, select 0 controls selected.
  3. In the Session pane, select Sign-in frequency.
  4. Select Periodic reauthentication or Every time.
    • If you select Periodic reauthentication, set the value for the time period after which a user is asked to sign-in again when performing an action that requires a new access token, and then select Select. For example, setting the value to 1 and the unit to Hours, requires multifactor authentication if a connection is launched more than an hour after the last user authentication.
    • The Every time option is only supported when applied to the Windows Cloud Login app when single sign-on is enabled for your host pool. If you select Every time, users are prompted to reauthenticate when launching a new connection after a period of 5 to 10 minutes since their last authentication.
  5. At the bottom of the page, select Save.

Note

  • Reauthentication only happens when a user must authenticate to a resource and a new access token is needed. After a connection is established, users aren't prompted even if the connection lasts longer than the sign-in frequency you've configured.
  • Users must reauthenticate if there is a network disruption that forces the session to be re-established after the sign-in frequency you've configured. This can lead to more frequent authentication requests on unstable networks.

When single sign-on is enabled for Azure Virtual Desktop, two Microsoft Entra applications are involved in the connection: the Azure Virtual Desktop app handles feed subscription and gateway authentication, and the Windows Cloud Login app handles session host sign-in. Both apps need Conditional Access policies that are aligned with each other, or users see multifactor authentication prompts at unexpected times.

Pre-configuration checklist

Complete these checks before enabling SSO on your host pool.

Verify app registrations:

  • Confirm the Azure Virtual Desktop app (ID: 9cdead84-a844-4324-93f2-b2e6bb768d07) exists in your tenant.
  • Confirm the Windows Cloud Login app (ID: 270efc09-cd0d-444b-a71f-39af4910ec45) exists in your tenant.
  • Don't add the Azure Virtual Desktop Azure Resource Manager Provider (ID: 50e95039-b200-4007-bc97-8d5790743a63) to any Conditional Access policy. This app is for feed retrieval only and must not have multifactor authentication enforced.

Check for conflicts:

  • List all Conditional Access policies that target All cloud apps. These policies apply to Azure Virtual Desktop SSO sessions and can block access unexpectedly.
  • Check whether any policy requires device compliance. Entra-joined Azure Virtual Desktop session hosts may not satisfy compliance policies designed for user endpoints.
  • Check whether any policy applies location-based restrictions. For the Azure Virtual Desktop app, location-based policies evaluate against the user's client IP. For the Windows Cloud Login app (SSO to session host), the IP address seen by Conditional Access may differ from the user's client IP depending on network routing. Test location-based policies against both apps before enforcing.
  • Verify no policy blocks the Windows Cloud Login app.
  • Verify no policy blocks the Windows 365 app (0af06dc6-e4b5-4f28-818e-e78e62d137a5). The Windows App authenticates to both the Azure Virtual Desktop and Windows 365 apps, even if the user only has Azure Virtual Desktop resources. A Conditional Access policy blocking the Windows 365 app causes sign-in failures for Azure Virtual Desktop users.

Disable legacy per-user multifactor authentication:

Important

If per-user multifactor authentication is enabled alongside Conditional Access policies, users on Microsoft Entra joined session hosts see "The sign-in method you're trying to use isn't allowed" errors. Disable per-user multifactor authentication and use Conditional Access policies exclusively.

In the Microsoft Entra admin center, go to Identity > Users > All users, then select Per-user MFA from the toolbar. Confirm per-user multifactor authentication is Disabled for all Azure Virtual Desktop users. For more information, see Microsoft Entra joined session host VMs.

Note

Conditional Access policies require Microsoft Entra ID P1 or P2 licensing and can't be used when Security Defaults are enabled. If your tenant uses Security Defaults, disable Security Defaults before creating the Conditional Access policies described below.

Two-policy structure

Create two separate policies rather than one combined policy.

Policy 1 - Azure Virtual Desktop service authentication:

Setting Value
Target app Azure Virtual Desktop (9cdead84-a844-4324-93f2-b2e6bb768d07)
Users Azure Virtual Desktop user group
Grant Require multifactor authentication
Sign-in frequency Per your organization's security requirements
Client apps Browser + Mobile apps and desktop clients

Policy 2 - Session host SSO authentication:

Setting Value
Target app Windows Cloud Login (270efc09-cd0d-444b-a71f-39af4910ec45)
Users Same Azure Virtual Desktop user group
Grant Require multifactor authentication
Sign-in frequency Match or exceed Policy 1. The Every time option is supported only on this app.
Client apps Browser + Mobile apps and desktop clients

Note

The Azure Virtual Desktop app handles feed subscription and gateway authentication. The Windows Cloud Login app handles session host sign-in when SSO is enabled. Different sign-in frequency settings between the two can cause multifactor authentication prompts at unexpected times.

Authentication flow

When a user connects, the two apps are evaluated at different points:

  1. The user's Windows App authenticates to the Azure Virtual Desktop app. Policy 1 is evaluated. A token is issued.
  2. The Windows App contacts the Azure Virtual Desktop Gateway using the token.
  3. The Gateway initiates session host SSO through the Windows Cloud Login app. Policy 2 is evaluated.
  4. The Windows Cloud Login app issues a Microsoft Entra token for the session host.
  5. The session host accepts the token and the session is ready.

Policy 1 controls step 1. Policy 2 controls step 3. When both are configured correctly, users see a single multifactor authentication prompt (if required) and enter the session seamlessly.

Common misconfigurations

Misconfiguration Symptom Resolution
Legacy per-user multifactor authentication enabled alongside Conditional Access "The sign-in method you're trying to use isn't allowed" Disable per-user multifactor authentication; use Conditional Access policies exclusively
Conditional Access targets "All cloud apps" with device compliance Sign-in fails because session host doesn't meet compliance policy Exclude Windows Cloud Login and Azure Virtual Desktop apps from "All apps" policy; create separate Azure Virtual Desktop-specific policies
Windows Cloud Login app missing from Conditional Access User gets a multifactor authentication prompt twice, once for Azure Virtual Desktop service and once for session host Add Windows Cloud Login to the SSO Conditional Access policy
Sign-in frequency mismatch between the two Azure Virtual Desktop apps Unexpected reauthentication mid-session or on reconnect Align sign-in frequency across both policies
Every time sign-in frequency set on Azure Virtual Desktop app instead of Windows Cloud Login Constant multifactor authentication prompts on feed refresh and diagnostics upload Every time is only supported on the Windows Cloud Login app

Post-configuration verification

After enabling SSO and configuring Conditional Access policies:

  1. Connect to Azure Virtual Desktop using the Windows App.
  2. Confirm you authenticate once (with multifactor authentication if required) and enter the session without a second credential prompt.
  3. In the Microsoft Entra admin center, go to Identity > Monitoring & health > Sign-in logs and filter by your test user. Verify:
    • Azure Virtual Desktop: Status: Success, correct Conditional Access policy applied.
    • Windows Cloud Login: Status: Success, correct Conditional Access policy applied.
  4. If either shows Failure, select the entry and check the Conditional Access tab to identify which policy blocked the sign-in.

If users still see repeated sign-in prompts, see Troubleshoot single sign-on and Conditional Access for Azure Virtual Desktop.

Microsoft Entra joined session host VMs

For connections to succeed, you must disable the legacy per-user multifactor authentication sign-in method. If you don't want to restrict signing in to strong authentication methods like Windows Hello for Business, you need to exclude the Azure Windows VM Sign-In app from your Conditional Access policy.

Next steps