Azure Virtual Desktop and Okta SSO, Okta Device Trust

Ian-7293 5 Reputation points
2023-03-30T05:08:13.11+00:00

Hello,

I want to setup Azure Virtual Desktop for some of our users and ultimately I want to authenticate our Microsoft 365 accounts via Okta. I'm assuming that when the users enter their login credentials to login to their virtual machines it will simply redirect to Okta for authentication?

Second question. I want to configure Okta Device Trust so that users can only access certain applications via on Okta via a trusted (company) device. How will this work in conjunction with the Azure Virtual Desktop? From my understanding you'll we can just deploy a certificate to the device which is then authenticated via Okta. But since it's a VM the users would be authenticating via Okta to get into their device I'm curious if this would cause any issues.

Please let me know if there's anything that I'm missing here.

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,367 questions
{count} vote

1 answer

Sort by: Most helpful
  1. vipullag-MSFT 24,206 Reputation points Microsoft Employee
    2023-03-30T08:40:29.21+00:00

    Hello Ian-7293

    Welcome to Microsoft Q&A Platform, thanks for posting your query here.

    If Okta is federated with Azure AD, it will just forward the authentication to Okta.

    To authenticate Microsoft 365 accounts via Okta, you can use Azure AD as an identity provider in Okta. You can configure Azure AD as an identity provider in Okta and then configure Azure AD as an authentication method in Azure Virtual Desktop. When users enter their login credentials to login to their virtual machines, they will be redirected to Okta for authentication.

    Regarding your second question, Okta Device Trust can be used to restrict access to certain applications via Okta based on whether the device is trusted or not. To use Okta Device Trust with Azure Virtual Desktop, you can deploy a certificate to the device and then configure Azure Virtual Desktop to use that certificate for authentication. When users authenticate via Okta to access their virtual machines, Azure Virtual Desktop will check whether the device is trusted or not based on the certificate. This should not cause any issues as long as the certificate is properly deployed and configured.

    I'm curious if this would cause any issues?
    It would be better to confirm this with Okta. https://www.okta.com/services/self-service/community/

    Hope that helps.
    If the suggested response helped you resolve your issue, please 'Accept as answer', so that it can help others in the community looking for help on similar topics.

    0 comments No comments