Entra · Knowledgebase · Security

KB - Enable Single Sign On for Windows 365 Cloud PC

· 2 min read · Entra, Knowledgebase, Security

This short tutorial explains how to enable Single Sign-On for Windows 365 Cloud PC using the Graph Explorer.

On Microsoft Learn, we can already find instructions for using PowerShell, but I’m a big fan of using the Graph API and Graph Explorer.

To enable SSO using Microsoft Entra ID authentication, there are four tasks we must complete:

  1. Enable Microsoft Entra authentication for Remote Desktop Protocol (RDP).
  2. Configure the target device groups.
  3. Review your Conditional Access policies.
  4. Turn on SSO for all Cloud PCs in your account.

However, in my test tenant, this instruction did not work, as the Windows Cloud Login service principal did not exist. That’s why we start with checking if the service principal is already present in Entra.

Graph API
GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=appId eq '270efc09-cd0d-444b-a71f-39af4910ec45'

In my tenant, the application did not exist, so let’s create it first.

Graph API
POST https://graph.microsoft.com/v1.0/servicePrincipals

{
  "appId": "270efc09-cd0d-444b-a71f-39af4910ec45"
}

Screenshot showing Windows 365 Cloud PC single sign-on configuration (step 1)

Copy the ID from the response, as we need it in the next step to fetch information about the remote desktop configuration.

Graph API
GET https://graph.microsoft.com/v1.0/servicePrincipals/5d44efdc-f48d-4643-82ab-6affdf202b21?$expand=remoteDesktopSecurityConfiguration

Screenshot showing Windows 365 Cloud PC single sign-on configuration (step 2)

Now, we need to enable the feature:

Graph API
PATCH https://graph.microsoft.com/v1.0/servicePrincipals/5d44efdc-f48d-4643-82ab-6affdf202b21/remoteDesktopSecurityConfiguration

{
  "isRemoteDesktopProtocolEnabled": true
}

Now we need to assign a device group to the service principal configuration. This group can also be a dynamic group that holds all your Cloud PC’s. For this demo, I created a new group and added my test device to it.

Screenshot showing Windows 365 Cloud PC single sign-on configuration (step 3)

For our next Graph API call, we need the group’s object ID.

Graph API
POST https://graph.microsoft.com/beta/servicePrincipals/5d44efdc-f48d-4643-82ab-6affdf202b21/remoteDesktopSecurityConfiguration/targetDeviceGroups

{
  "@odata.type": "#microsoft.graph.targetDeviceGroup",
  "id": "f43eab10-ea35-41e8-8dfe-f77fcab84ca3",
  "displayName": "Cloud PC Groups for SSO"
}

Screenshot showing Windows 365 Cloud PC single sign-on configuration (step 4)

When you fetch the updated information, it should look like this:

Screenshot showing Windows 365 Cloud PC single sign-on configuration (step 5)

The last step is to enable SSO for all Cloud PCs using the admin center.

  1. Sign in to windows365.microsoft.com with an account that has the Windows 365 Administrator role.
  2. Select Your organization’s Cloud PCs, and then select Update organization settings.
  3. Select the Single sign-on option under Cloud PC settings.

Screenshot showing Windows 365 Cloud PC single sign-on configuration (step 6)

If all goes well, the experience using the Windows App should look like this, and the user should not be prompted.

More info: remoteDesktopSecurityConfiguration resource type - Microsoft Graph v1.0 | Microsoft Learn

Comments

Comments load when you scroll here.