Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
When you create a provisioning policy (agents), you can link either a Microsoft Entra security group or an Intune Autopilot Device preparation policy. You can select one option per Cloud PC agent pool.
Because a provisioning policy (agents) represents a Cloud PC agent pool, the terms are used interchangeably in this article.
Note
Cloud PC agent pool device grouping and preparation is currently in public preview.
Use cases for device grouping and preparation
As organizations deploy Cloud PC agent pools at scale, administrators need a way to:
- Target security and compliance policies to Cloud PCs for Agents
- Deploy required line-of-business (LOB) applications
- Ensure consistent device configuration across agent pools
- Manage Cloud PCs for Agents using existing Intune workflows
You can accomplish all of the above by either linking a device group or Autopilot device preparation policy to a Cloud PC agent pool.
Linking a Cloud PC agent pool to a device group is recommended when:
- You want the fastest provisioning experience.
- You don't require validation that applications are successfully installed before agents access Cloud PCs.
- You might be using custom images to provide required applications.
Using Autopilot device preparation is recommended when:
- Agents require specific applications when using Cloud PCs.
- You want to reduce reliance on custom images.
- You need a more predictable and validated provisioning experience.
Link a device group to a Cloud PC agent pool
When you link a Microsoft Entra security group to a Cloud PC agent pool, Windows 365 automatically adds all Cloud PCs in an agent pool to the specified Microsoft Entra security group.
To link a Microsoft Entra security group to a Cloud PC agent pool, when you create a provisioning policy (agents), in the Configuration step, you can either:
- Select an existing group.
- Create a group (only if you have permission to create security groups).
In both cases, the Microsoft Entra group must meet the following requirements:
- Group type is Security.
- Membership type is Assigned.
- Owners include Windows 365.
Add Windows 365 as a group owner
To add Cloud PCs to a security group, Windows 365 must be an owner of the group. To add Windows 365 as a group owner, create or select a security group. Under the group's Owners, select Add owners, search for and select Windows 365 with an AppId of 0af06dc6-e4b5-4f28-818e-e78e62d137a5.
Link an Autopilot device preparation policy to a Cloud PC agent pool
By using Windows Autopilot device preparation, you can make sure that required device-targeted apps and scripts are installed on Cloud PCs during the provisioning process before agents can check out Cloud PCs. To learn how to set up Autopilot device preparation for Windows 365, see the step-by-step tutorial.
Then, when you create a provisioning policy (agents), in the Configuration step:
- Select Link Autopilot device preparation policy.
- Select the policy to link.
- For Minutes allowed before device preparation fails, enter a value that allows adequate time to install the apps and scripts defined in your policy. If the apps and scripts aren't finished installing by this time, then device preparation and provisioning fail.
- Optionally, you can unselect Prevent connection to Cloud PC upon installation failure or time-out. By default, the provisioning result is Failed if there's a time-out or failure, and agents can't check out Cloud PCs. If the checkbox is not selected, then agents can check out Cloud PCs.
Monitor Autopilot device preparation
Autopilot device preparation tracks the installation progress of specified Intune applications and scripts during Cloud PC provisioning. To see the status of device preparation for Cloud PC provisioning, go to Devices > Enrollment > Monitor > Windows Autopilot device preparation deployment status.
Update device group or preparation for Cloud PC agent pools
To update the device group, Autopilot device preparation policy, or switch between the two options for a Cloud PC agent pool, you need to edit the provisioning policy (agents) and reprovision the pool.