AAD VM Template Creation Process

Pre-requisites: 

  • The Control Account should be setup for AAD authentication for Desktop and Clients 

  • This document only focuses on the Additional Steps that are to be done on the template to enable AAD authentication on the Desktops 

  • Latest Version of Workspot Desktop Agent on the template – Preferably 3.0 and above 

Configuration Process: 

  1. Login to the template and complete all the regular template configurations like Installing Applications etc. if it is a custom template, make sure you install the latest Workspot Desktop Agent. 

  2. As a first step, Open Microsoft Store and Search for “Windows Configuration Designer” and click on GET button 

Graphical user interface, applicationDescription automatically generated
  1. This will download and configure the WCD automatically. No further action is needed to install it 

  2. To make sure it is configured properly, Open file explorer and navigate to C:\Program Files\WindowsApps and you should find 3 folders with their names staring with Microsoft. WindowsConfigurationDesigner 

Graphical user interface, text, applicationDescription automatically generated
  1. Open the last folder and locate “icd” folder and open it or copy the full path of the icd folder 

Graphical user interface, applicationDescription automatically generated
  1. Next, Open Start > System and search for Environment Variables for your account 

Graphical user interface, text, application, emailDescription automatically generated
  1. System Variable Window will appear, Double click on the path to add the icd folder path here 

Graphical user interface, text, applicationDescription automatically generated
  1. Click on New to add a new column and paste the folder path and click on OK 

RlT4HcBJVZmDBIYsFPgg5jln-sAwMWHfFrGFX9xHznJPU5j-HAjXCJUyDR3J1au-BtCwbrS2JjG6FXWYVT7IcurLzNhXcOXeEnGIrsViDDSYNU6AfqaMNVXdqngPUo-uyRZ-B_IHwUAUsvkRJFEjtKw
  1. Next, make sure the WokspotConfig.xml file is properly configured.

    1. First make sure the DoNotJoinAD section is set to 1 as highlighted below

    2. Also to enable user connections on the VM, add the local group “Authenticated Users” to the “Remote Desktop Users” group 

    3. If you wish to give Admin access to the users, you can add the Authenticated users group to the Administrators group. 

Graphical user interface, text, applicationDescription automatically generated
  1. The Template configuration is now complete. Move the template status to Preview and test the deployment before publishing it.