Entra ID Template Creation Process

Prev Next

This article describes how to create templates for Windows desktops that use Entra ID-only authentication instead of the more typical Active Directory authentication.

Prerequisites

  • Control should be configured for Entra ID (Azure AD) authentication for both Desktop and Clients  (“Entra ID only”).

  • This document only focuses on the steps to enable Entra ID authentication on the Desktops. See Configuring an Entra-ID-Only (Azure-AD-Only) Control Account for other aspects of this feature.

Configuration Process

  1. Log into the draft-mode template and complete all the regular template configuration, such as Installing applications.

  2. If it is a custom template, make sure you install the latest Workspot Desktop Agent. 

  3. As a first step, Open the Microsoft Store and Search for “Windows Configuration Designer” and click on GET button. This will download and configure the WCD automatically. No further action is needed to install it.

Graphical user interface, applicationDescription automatically generated

  1. Open file explorer and navigate to C:\Program Files\WindowsApps and you should find three folders with names staring with “Microsoft. WindowsConfigurationDesigner.” 

Graphical user interface, text, applicationDescription automatically generated

  1. Open the last folder and locate “icd” subfolder, open it, and copy the full path of the icd folder. 

Graphical user interface, applicationDescription automatically generated

  1. “Open Start > System” and search for “Environment Variables” for your account 

Graphical user interface, text, application, emailDescription automatically generated

  1. In the list of “System Variables,” Double click on “Path.”

Graphical user interface, text, applicationDescription automatically generated

  1. Add the icd folder path to the bottom of the Path list as follows:

    a. Click on “New” to add a new row.

    b. Paste the folder path into the new row.

    c. Click “OK.”

RlT4HcBJVZmDBIYsFPgg5jln-sAwMWHfFrGFX9xHznJPU5j-HAjXCJUyDR3J1au-BtCwbrS2JjG6FXWYVT7IcurLzNhXcOXeEnGIrsViDDSYNU6AfqaMNVXdqngPUo-uyRZ-B_IHwUAUsvkRJFEjtKw

  1. Make sure the Agent’s WokspotConfig.xml file is properly configured.

    1. Make sure the “DoNotJoinAD” section is set to 1 as highlighted below.

    2. To enable user connections on the VM, add the local group “Authenticated Users” to the “Remote Desktop Users” group 

    3. If you wish to give Admin access to the users, also add the “Authenticated Users” group to the “Administrators” group. 

Graphical user interface, text, applicationDescription automatically generated

  1. The Template configuration is now complete. Move the template status to “Preview” and test the deployment before publishing it. 

Related Documents