The device is configured with Windows 365 Boot Dedicated, allowing users to sign in directly to their Cloud PC.
The Return to Physical Device option is enabled through Intune to allow local Windows access only to selected administrative accounts.
These accounts:
- are correctly configured in Microsoft Entra ID;
belong to the group targeted by the physical device access policy;
appear to have received the policy;
intentionally have no Cloud PC or VDI assigned.
Observed behavior
The following procedure is used:
A user with an assigned Cloud PC signs in through Windows 365 Boot.
From the error screen or Ctrl+Alt+Del, Return to Physical Device is selected.
On the local sign-in screen, credentials for an administrative account without a Cloud PC are entered.
The device still attempts to start a Windows 365 session for that account. Since no Cloud PC is assigned, sign-in fails and access to the local operating system is denied.
However, entering the credentials of an account with an assigned Cloud PC allows access to the physical device.
This suggests that Return to Physical Device may not support local sign-in with an account that does not have a Cloud PC, even when the account is an administrator included in the relevant policy.
Questions
1. Local access without a Cloud PC
Can an administrative account without an assigned Cloud PC access the local operating system after selecting Return to Physical Device?
Or is this option limited to users who already have an assigned Cloud PC?
2. Expected behavior or configuration issue
Is the attempt to start a Cloud PC session for an account intended for local sign-in expected behavior?
Is this a product limitation, or could it indicate an incorrect policy configuration?
3. SID or UPN configuration
It has been suggested that administrative accounts must be explicitly configured by SID or UPN to access the physical device without a Cloud PC.
Please clarify:
where this must be configured in Intune;
which policy, setting, or CSP supports SID or UPN entries;
why this is required when the accounts already exist in Microsoft Entra ID and belong to the targeted group.
An official Microsoft documentation reference would be appreciated.
4. Licensing requirements
Do administrative accounts without a Cloud PC require:
Microsoft Entra ID P1;
Microsoft Intune Plan 1;
or both;
to receive and apply the policies required for physical device access?
Objective
The goal is to allow local operating system access only to selected administrative accounts, while keeping those accounts without an assigned Cloud PC.
Please confirm whether this scenario is officially supported and, if so, provide the required configuration and licensing details.The device is configured with Windows 365 Boot Dedicated, allowing users to sign in directly to their Cloud PC.
The Return to Physical Device option is enabled through Intune to allow local Windows access only to selected administrative accounts.
These accounts:
are correctly configured in Microsoft Entra ID;
belong to the group targeted by the physical device access policy;
appear to have received the policy;
intentionally have no Cloud PC or VDI assigned.
Observed behavior
The following procedure is used:
A user with an assigned Cloud PC signs in through Windows 365 Boot.
From the error screen or Ctrl+Alt+Del, Return to Physical Device is selected.
On the local sign-in screen, credentials for an administrative account without a Cloud PC are entered.
The device still attempts to start a Windows 365 session for that account. Since no Cloud PC is assigned, sign-in fails and access to the local operating system is denied.
However, entering the credentials of an account with an assigned Cloud PC allows access to the physical device.
This suggests that Return to Physical Device may not support local sign-in with an account that does not have a Cloud PC, even when the account is an administrator included in the relevant policy.
Questions
1. Local access without a Cloud PC
Can an administrative account without an assigned Cloud PC access the local operating system after selecting Return to Physical Device?
Or is this option limited to users who already have an assigned Cloud PC?
2. Expected behavior or configuration issue
Is the attempt to start a Cloud PC session for an account intended for local sign-in expected behavior?
Is this a product limitation, or could it indicate an incorrect policy configuration?
3. SID or UPN configuration
It has been suggested that administrative accounts must be explicitly configured by SID or UPN to access the physical device without a Cloud PC.
Please clarify:
where this must be configured in Intune;
which policy, setting, or CSP supports SID or UPN entries;
why this is required when the accounts already exist in Microsoft Entra ID and belong to the targeted group.
An official Microsoft documentation reference would be appreciated.
4. Licensing requirements
Do administrative accounts without a Cloud PC require:
Microsoft Entra ID P1;
Microsoft Intune Plan 1;
or both;
to receive and apply the policies required for physical device access?
Objective
The goal is to allow local operating system access only to selected administrative accounts, while keeping those accounts without an assigned Cloud PC.
Please confirm whether this scenario is officially supported and, if so, provide the required configuration and licensing details.