Skip to main content

2 settembre 2026

Using Microsoft Entra ID with App Volumes

App Volumes integrates with the identity provider configured for your Horizon Cloud environment to manage application access and entitlements. When using Microsoft Entra ID as the identity provider, there are important differences in how identity and access are handled compared to environments that use Active Directory.

High-Level Workflow

To use Microsoft Entra ID with App Volumes in Horizon Cloud, complete the following high-level steps:

  1. Configure Microsoft Entra ID as the identity provider in Horizon Cloud. For more information, see Connecting your Identify Provider.

  2. Grant the necessary Microsoft Graph API permissions and ensure admin consent is provided. For more information, see Apply Permissions to Allow Horizon cloud to Manage Microsoft Entra ID Joined Machines and Grant tenant-side admin consent to an application (Microsoft Learn).

  3. Configure appropriate access and permissions for users and administrators using Microsoft Entra ID and Azure RBAC. For more information, see Azure built-in roles (Microsoft Learn) and To Use a Custom Role for Horizon Cloud App Registration.

  4. Create or configure desktop pools using Microsoft Entra ID as the identity provider where applicable. For more information, see Create a Pool.

  5. Assign App Volumes applications to users or groups from Microsoft Entra ID through the Horizon Universal Console.

  6. Ensure Azure Storage access is correctly configured for App Volumes package delivery, including private endpoints and appropriate storage access configuration. For more information, see Azure Private Endpoint for an App Volumes Application Storage Account.

    Note: Storage configuration is independent of whether Microsoft Entra Id (HID) is used as the identity provider. This requirement applies to both Entra ID and non-Entra ID environments.

Identity and Entitlements

App Volumes application entitlements are assigned to users and groups sourced from Microsoft Entra ID.

  1. User and Group Management

    • Users and groups are managed in Microsoft Entra ID.

    • Users must be assigned to appropriate access groups and roles such as Virtual Machine User Login to access desktops.

    • Administrative Units can be used for scoped delegation.

  2. Application Entitlements

  3. Token and Session Behaviour

    • Changes to user or group membership depend on token refresh and session lifecycle.

    • Logoff and logon is typically required for entitlement updates. For more information on group management, see Manage Microsoft Entra groups and group membership (Microsoft Learn).

  4. Identity Provider Integration

Differences from Active Directory-Based Environments

In environments that use Microsoft Entra ID, identity and access management differ from traditional Active Directory-based environments in the following ways:

  1. No Organizational Units (OUs)

  2. Role-Based Access Control (RBAC)

    • Identity and access control rely on role-based access control (RBAC) rather than traditional Active Directory structures.

    • RBAC is used to govern access to virtual machines and Horizon Cloud operations. For more information, see the What is Azure role-based access control (Azure RBAC)? (Microsoft Learn).

  3. Policy-Based Authentication

    • Authentication is governed by Microsoft Entra ID policies, such as Conditional Access.

    • These policies define how and when users can access applications and desktops. For more information, see What is Conditional Access? (Microsoft Learn).

  4. Identity Model

    • Identity is attribute-based (for example, UPN) rather than SID-based.

    • This affects how users are identified and managed across services. For more information, see What is Microsoft Entra? (Microsoft Learn).

Permission Model Overview

Application delivery with App Volumes in Horizon Cloud on Azure requires alignment across three permission layers.

  1. Identity Permissions (Microsoft Entra ID / Microsoft Graph)

  2. Platform Permissions (Azure RBAC)

    Azure RBAC controls access to compute resources and Horizon Cloud operations.

    Permissions should be assigned at the appropriate scope (subscription or resource group) to allow users and administrators to access and manage resources.

    Note: The exact roles and permissions required depend on the deployment configuration and supported capabilities. For more information, see To Use a Custom Role for Horizon Cloud App Registration.

  3. Storage Access (Private Endpoint and Storage Configuration)

    App Volumes application packages are stored in Azure Storage accounts.

    Storage access should be configured to allow Horizon Cloud and session hosts to access application packages. This may include:

    • Configuring network access (such as Azure Private Endpoints)

    • Ensuring appropriate permissions are in place for accessing storage resources

    Azure Private Endpoints can be used to:

    • Ensure traffic remains within the private network

    • Restrict access to storage resources

    Note:

    • Storage access configuration is independent of the identity provider (Microsoft Entra ID or otherwise).

    • The specific permission model and access mechanism may vary depending on platform capabilities. Explicit role assignments may not be required in all current deployments.

    For more information, see Azure Private Endpoint for an App Volumes Application Storage Account.

Summary

Using Microsoft Entra ID with App Volumes requires proper configuration across identity, platform, and storage layers.

  • Application access is managed through Microsoft Entra ID users and groups.

  • Identity permissions, platform access controls, and storage access should be configured appropriately based on the deployment model and supported capabilities.

  • Microsoft Graph API permissions enable Horizon Cloud to read user and group information for entitlement mapping.

  • Azure RBAC is used to govern access to desktops and platform operations.

  • Storage configuration, including private endpoints and appropriate access configuration, ensures App Volumes application packages can be delivered.

  • Token lifecycle and session behaviour can affect when entitlement changes take effect.

Note: Misconfiguration in any of these areas can prevent users from accessing desktops or receiving assigned applications.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…