QuestionQ153

Plan and implement identity and security

You have the following:

  • A Microsoft 365 E5 tenant
  • An on-premises Active Directory domain
  • A hybrid Azure Active Directory (Azure AD) tenant
  • An Azure Active Directory Domain Services (Azure AD DS) managed domain
  • An Azure Virtual Desktop deployment

The Azure Virtual Desktop deployment includes personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune.

You need to configure the security settings for the Microsoft Edge browsers on the personal desktops.

Solution: You create and configure a Group Policy Object (GPO) in the on-premises Active Directory domain.

Does this solution meet the goal of configuring the security settings for the Microsoft Edge browsers on the personal desktops?

  • A Yes
  • B No
Explanation

The Azure Virtual Desktop personal session hosts are hybrid Azure AD joined, which means they remain members of the on-premises Active Directory domain in addition to being registered with Azure AD. Because they are still domain members, they receive Group Policy from on-premises domain controllers in the normal way. Microsoft Edge provides ADMX-based Group Policy templates that let administrators configure browser security settings, and linking a properly configured GPO in the on-premises domain to the organizational unit containing these session hosts will apply those Edge security settings to the personal desktops. This makes the solution valid for meeting the stated requirement.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!