Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Mastering Azure Virtual Desktop

You're reading from  Mastering Azure Virtual Desktop

Product type Book
Published in Mar 2022
Publisher Packt
ISBN-13 9781801075022
Pages 734 pages
Edition 1st Edition
Languages
Author (1):
Ryan Mangan Ryan Mangan
Profile icon Ryan Mangan

Table of Contents (29) Chapters

Preface 1. Section 1: Introduction
2. Chapter 1: Introduction to Azure Virtual Desktop 3. Section 2: Planning an Azure Virtual Desktop Architecture
4. Chapter 2: Designing the Azure Virtual Desktop Architecture 5. Chapter 3: Designing for User Identities and Profiles 6. Chapter 4: Implementing and Managing Networking for Azure Virtual Desktop 7. Chapter 5: Implementing and Managing Storage for Azure Virtual Desktop 8. Section 3: Implementing an Azure Virtual Desktop Infrastructure
9. Chapter 6: Creating Host Pools and Session Hosts 10. Chapter 7: Configure Azure Virtual Desktop Host Pools 11. Chapter 8: Azure AD Join for Azure Virtual Desktop 12. Chapter 9: Creating and Managing Session Host Images 13. Section 4: Managing Access and Security
14. Chapter 10: Managing Access 15. Chapter 11: Managing Security 16. Section 5: Managing User Environments and Apps
17. Chapter 12: Implementing and Managing FSLogix 18. Chapter 13: Configuring User Experience Settings 19. Chapter 14: MSIX App Attach 20. Chapter 15: Configuring Apps on a Session Host 21. Section 6: Monitoring and Maintaining an Azure Virtual Desktop Infrastructure
22. Chapter 16: Planning and Implementing Business Continuity and Disaster Recovery 23. Chapter 17: Automate Azure Virtual Desktop Management Tasks 24. Chapter 18: Monitoring and Managing Performance and Health 25. Chapter 19: Azure Virtual Desktop's Getting Started Feature 26. Final Assessment 27. Other Books You May Enjoy Appendix: Microsoft Resources and Microsoft Learn

What's managed by Microsoft and what you manage

The following diagram shows what services Microsoft manages and what you manage:

Figure 1.1 – Services managed by Microsoft and you

Figure 1.1 – Services managed by Microsoft and you

What Microsoft manages

Azure Virtual Desktop provides a virtualization infrastructure as a managed service. Azure Virtual Desktop's core components are as follows:

  • Web client: The Web Access service within Azure Virtual Desktop management enables users to access virtual desktops and remote apps through the HTML5-compatible web browser, as they would with a local PC – from anywhere and on any device. In addition, you can secure Web Access by using MFA in Azure AD.
  • Diagnostics: Remote Desktop Diagnostics is an event-based aggregator service that's provided through Azure Virtual Desktop management that marks each user or administrator's action on the deployment as a success or failure. Administrators can query the aggregation of events to identify failing components.
  • Management: With this option, you can manage Azure Virtual Desktop configurations in the Azure portal, as well as manage and publish host pool resources. Azure Virtual Desktop also includes several extensibility components. You can manage Azure Virtual Desktop by using Windows PowerShell or with the provided REST APIs, enabling support from third-party tools.
  • Broker: The Connection Broker service manages user connections to virtual desktops and remote apps. This also handles load balancing and reconnecting to existing sessions.
  • Load balancing: This option provides session host load balancing by depth-first or breadth-first. The broker controls how new incoming sessions are distributed across the VMs in a host pool.
  • Gateway: The Remote Connection Gateway service connects remote users to Azure Virtual Desktop remote apps and desktops from any internet-connected device that can run an Azure Virtual Desktop client. The client connects to a gateway that then orchestrates a connection from the VM back to the same gateway.

Windows Virtual Desktop uses Azure infrastructure services for compute, storage, and networking.

What does the customer manage?

Now, let's look at what you, as the customer, manage. First, we'll look at the desktop and remote apps part of Azure Virtual Desktop.

Desktop and remote apps

With this option, you can create application groups to group, publish, and assign access to remote apps or desktops:

  • Desktop: Remote Desktop application groups give users access to a full desktop. You can provide a desktop where the session host's VM resources are shared or pooled. You can give dedicated personal desktops to those users who need to add or remove programs without impacting other users.
  • Apps: RemoteApp applications groups provide users access to the applications you individually publish to the application group. You can create multiple RemoteApp app groups to accommodate different user scenarios. For example, you can use RemoteApp to virtualize an app that runs on a legacy OS or needs secured access to corporate resources.
  • Images: When you configure session hosts for application groups, you have a choice of images. You should use a recommended image such as Windows 10 Enterprise multi-session and Office 365. Alternatively, you can choose an image in your gallery or an image provided by Microsoft or other publishers.

Management and policies

Now, let's look at the customer responsibilities for management and policies:

  • Profile management: Configure FSLogix profile containers with a storage solution such as Azure Files to containerize user profiles and provide users with a fast and stateful experience.
  • Sizing and scaling: Here, you can specify session host VM sizes, including GPU-enabled VMs, as well as specify depth or breath load balancing when you create a host pool. Finally, you can configure automation policies for scaling.
  • Networking policies: Define a network topology to access the virtual desktop and virtual apps from the intranet or internet based on the organizational policy.
  • Connect your Azure Virtual Network to your on-premises network by using a virtual private network. Alternatively, you can use Azure ExpressRoute to extend your on-premises networks into the Microsoft cloud platform over a private connection.
  • User management and identity: Use Azure AD and RBAC to manage user access to resources. Take advantage of Azure AD security features such as conditional access, MFA, and Intelligent Security Graph. Azure Virtual Desktop requires Active Directory Domain Services (AD DS). Domain-joined sessions host VMs on this service. You can also sync AD DS with Azure AD so that users are associated between the two. Once you've done this, you can use Azure AD Join to deliver virtual desktops to your users.
You have been reading a chapter from
Mastering Azure Virtual Desktop
Published in: Mar 2022 Publisher: Packt ISBN-13: 9781801075022
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}