Assigning Desktops to Users

Prev Next

Workspot allows administrators to assign desktops to users either manually or automatically using directory groups (AD or Entra ID). This document outlines both methods, prerequisites, and entitlement behavior, and when each method should be used.

1. Overview of Assignment Methods

Workspot supports two primary ways to assign desktops:

  • Manual Assignment

  • Automatic Assignment Using Groups (AD or Entra ID)

2. Manual Assignment (Admin-Initiated)

2.1 Assigning a User to a Specific Desktop VM

  • Sign in to Workspot Control.

  • Navigate to Resources > VDI Pools.

  • Select the Pool > Desktops tab.

  • Locate the VM > Click “Assign User”.

  • Select the user and save it.

2.2 Assigning a Desktop Pool to a User

  • Go to Users in Workspot Control.

  • Select the user.

  • Under Entitlements

    • For Cloud Desktop > Desktop assignment > Add pool name in Cloud Desktop Pool Name

    • For Apps > App Assignment > Add App in App Name

  • Save.

3. Automatic Assignment Based on Groups

3.1 Active Directory and Entra Groups

Before users can receive desktops automatically, customers must add the user to the appropriate AD or Entra ID security group in their directory environment.

The customer’s Workspot Control configuration determines the group type used:

  • AD-based tenants use Active Directory Security Groups.

  • Entra-only tenants use Entra ID Groups.

Customers must create AD or Entra ID groups in their directory environment and add them to Control as described here: https://docs.workspot.com/v1/docs/ad-group for centralized and ease of management.

Once the desired groups are added and mapped to Pools or App bundles in Workspot Control, admins can simply assign users to these directory groups to provide the required resources. Please note that Workspot does not maintain a universal mapping between AD and Entra ID groups. Workspot only checks the groups for membership against the group added to the Workspot Control.

Assignment Flow

  • User signs into the Workspot Client for the first time.

  • Workspot queries the directory for group membership at client login

  • Workspot assigns the user to the appropriate Workspot Group based on the AD/Entra Group.

  • Workspot Group determines desktop pools, applications, and access policies.

  • Group membership verification occurs automatically every 24 hours at the next client login.

When to Use This Method

  • Large-Scale, Centralized, and Easy for User assignment, use AD or Entra ID groups.

  • Automated onboarding/offboarding requirements.

  • Users change departments or roles frequently.

  • Directory-driven lifecycle and policy enforcement.

3.2 Workspot Groups

Workspot Control allows the creation of “Groups” that are local to the Workspot Control. These groups define the users’ entitlements, such as:

  • Desktop Pools

  • Application Bundles

  • Access Policies

    When to Use This Method

  • Managing group membership without the AD/Entra setup, utilize Workspot Groups.

5. Additional Notes

Preview Groups exist in Workspot Control and are used only for granting access to preview pools created for template testing. Reference: https://docs.workspot.com/docs/using-workspot-templates#preview-the-template

Related Articles: