Workspot allows administrators to assign desktops to users either manually or automatically using directory groups (AD or Entra ID). This document outlines both methods, prerequisites, and entitlement behavior, and when each method should be used.
1. Overview of Assignment Methods
Workspot supports two primary ways to assign desktops:
Manual Assignment
Automatic Assignment Using Groups (AD or Entra ID)
2. Manual Assignment (Admin-Initiated)
2.1 Assigning a User to a Specific Desktop VM
Sign in to Workspot Control.
Navigate to Resources > VDI Pools.
Select the Pool > Desktops tab.
Locate the VM > Click “Assign User”.
Select the user and save it.
2.2 Assigning a Desktop Pool to a User
Go to Users in Workspot Control.
Select the user.
Under Entitlements
For Cloud Desktop > Desktop assignment > Add pool name in Cloud Desktop Pool Name
For Apps > App Assignment > Add App in App Name
Save.
3. Automatic Assignment Based on Groups
3.1 Active Directory and Entra Groups
Before users can receive desktops automatically, customers must add the user to the appropriate AD or Entra ID security group in their directory environment.
The customer’s Workspot Control configuration determines the group type used:
AD-based tenants use Active Directory Security Groups.
Entra-only tenants use Entra ID Groups.
Customers must create AD or Entra ID groups in their directory environment and add them to Control as described here: https://docs.workspot.com/v1/docs/ad-group for centralized and ease of management.
Once the desired groups are added and mapped to Pools or App bundles in Workspot Control, admins can simply assign users to these directory groups to provide the required resources. Please note that Workspot does not maintain a universal mapping between AD and Entra ID groups. Workspot only checks the groups for membership against the group added to the Workspot Control.
Assignment Flow
User signs into the Workspot Client for the first time.
Workspot queries the directory for group membership at client login
Workspot assigns the user to the appropriate Workspot Group based on the AD/Entra Group.
Workspot Group determines desktop pools, applications, and access policies.
Group membership verification occurs automatically every 24 hours at the next client login.
When to Use This Method
Large-Scale, Centralized, and Easy for User assignment, use AD or Entra ID groups.
Automated onboarding/offboarding requirements.
Users change departments or roles frequently.
Directory-driven lifecycle and policy enforcement.
3.2 Workspot Groups
Workspot Control allows the creation of “Groups” that are local to the Workspot Control. These groups define the users’ entitlements, such as:
Desktop Pools
Application Bundles
Access Policies
When to Use This Method
Managing group membership without the AD/Entra setup, utilize Workspot Groups.
5. Additional Notes
Preview Groups exist in Workspot Control and are used only for granting access to preview pools created for template testing. Reference: https://docs.workspot.com/docs/using-workspot-templates#preview-the-template
Related Articles: