Windows 365 Boot Dedicated - Physical device access

Vottero Carlotta 0 Punti di reputazione
2026-07-16T16:28:28.5666667+00:00

The device is configured with Windows 365 Boot Dedicated, allowing users to sign in directly to their Cloud PC.

The Return to Physical Device option is enabled through Intune to allow local Windows access only to selected administrative accounts.

These accounts:

  • are correctly configured in Microsoft Entra ID;

belong to the group targeted by the physical device access policy;

appear to have received the policy;

intentionally have no Cloud PC or VDI assigned.

Observed behavior

The following procedure is used:

A user with an assigned Cloud PC signs in through Windows 365 Boot.

From the error screen or Ctrl+Alt+Del, Return to Physical Device is selected.

On the local sign-in screen, credentials for an administrative account without a Cloud PC are entered.

The device still attempts to start a Windows 365 session for that account. Since no Cloud PC is assigned, sign-in fails and access to the local operating system is denied.

However, entering the credentials of an account with an assigned Cloud PC allows access to the physical device.

This suggests that Return to Physical Device may not support local sign-in with an account that does not have a Cloud PC, even when the account is an administrator included in the relevant policy.

Questions

1. Local access without a Cloud PC

Can an administrative account without an assigned Cloud PC access the local operating system after selecting Return to Physical Device?

Or is this option limited to users who already have an assigned Cloud PC?

2. Expected behavior or configuration issue

Is the attempt to start a Cloud PC session for an account intended for local sign-in expected behavior?

Is this a product limitation, or could it indicate an incorrect policy configuration?

3. SID or UPN configuration

It has been suggested that administrative accounts must be explicitly configured by SID or UPN to access the physical device without a Cloud PC.

Please clarify:

where this must be configured in Intune;

which policy, setting, or CSP supports SID or UPN entries;

why this is required when the accounts already exist in Microsoft Entra ID and belong to the targeted group.

An official Microsoft documentation reference would be appreciated.

4. Licensing requirements

Do administrative accounts without a Cloud PC require:

Microsoft Entra ID P1;

Microsoft Intune Plan 1;

or both;

to receive and apply the policies required for physical device access?

Objective

The goal is to allow local operating system access only to selected administrative accounts, while keeping those accounts without an assigned Cloud PC.

Please confirm whether this scenario is officially supported and, if so, provide the required configuration and licensing details.The device is configured with Windows 365 Boot Dedicated, allowing users to sign in directly to their Cloud PC.

The Return to Physical Device option is enabled through Intune to allow local Windows access only to selected administrative accounts.

These accounts:

are correctly configured in Microsoft Entra ID;

belong to the group targeted by the physical device access policy;

appear to have received the policy;

intentionally have no Cloud PC or VDI assigned.

Observed behavior

The following procedure is used:

A user with an assigned Cloud PC signs in through Windows 365 Boot.

From the error screen or Ctrl+Alt+Del, Return to Physical Device is selected.

On the local sign-in screen, credentials for an administrative account without a Cloud PC are entered.

The device still attempts to start a Windows 365 session for that account. Since no Cloud PC is assigned, sign-in fails and access to the local operating system is denied.

However, entering the credentials of an account with an assigned Cloud PC allows access to the physical device.

This suggests that Return to Physical Device may not support local sign-in with an account that does not have a Cloud PC, even when the account is an administrator included in the relevant policy.

Questions

1. Local access without a Cloud PC

Can an administrative account without an assigned Cloud PC access the local operating system after selecting Return to Physical Device?

Or is this option limited to users who already have an assigned Cloud PC?

2. Expected behavior or configuration issue

Is the attempt to start a Cloud PC session for an account intended for local sign-in expected behavior?

Is this a product limitation, or could it indicate an incorrect policy configuration?

3. SID or UPN configuration

It has been suggested that administrative accounts must be explicitly configured by SID or UPN to access the physical device without a Cloud PC.

Please clarify:

where this must be configured in Intune;

which policy, setting, or CSP supports SID or UPN entries;

why this is required when the accounts already exist in Microsoft Entra ID and belong to the targeted group.

An official Microsoft documentation reference would be appreciated.

4. Licensing requirements

Do administrative accounts without a Cloud PC require:

Microsoft Entra ID P1;

Microsoft Intune Plan 1;

or both;

to receive and apply the policies required for physical device access?

Objective

The goal is to allow local operating system access only to selected administrative accounts, while keeping those accounts without an assigned Cloud PC.

Please confirm whether this scenario is officially supported and, if so, provide the required configuration and licensing details.

Windows per le aziende | Windows 365 Enterprise
0 commenti Nessun commento

1 risposta

Ordina per: Più utili
  1. Hoang Le 1,045 Punti di reputazione Consulente indipendente
    2026-07-16T16:53:39.1733333+00:00

    Ciao Vottero Carlotta,

    Con Windows 365 Boot la logica di accesso è strettamente vincolata alle policy configurate e al fatto che l'utente abbia o meno un Cloud PC assegnato. Quando un account amministrativo senza Cloud PC tenta di usare l’opzione “Torna all’accesso del PC fisico”, il comportamento che descrive è coerente: il sistema prova comunque ad avviare la sessione VDI e fallisce, perché la policy di accesso fisico è legata all’utente che ha già avviato la sessione. In altre parole, l'accesso fisico non è disponibile in modo generico a qualsiasi account, ma solo al profilo che ha iniziato la sessione Windows 365 Boot.

    Per consentire l'accesso fisico esclusivamente agli account amministrativi, devi configurare la policy di Windows 365 Boot in modo che include esplicitamente quei SID/UPN e non dipende dal mapping Cloud PC. Microsoft ha chiarito che gli account che devono ricevere la policy di accesso al dispositivo fisico devono comunque essere gestiti da Entra ID e Intune. Non è necessaria una licenza Cloud PC, ma sì: serve almeno Microsoft Entra ID P1 per l'applicazione delle Conditional Access policy e Microsoft Intune Plan 1 per distribuire e applicare le adesivo di accesso. Senza queste licenze, gli account amministrativi non ricevono le policy e Windows 365 Boot li tratta come utenti non conformi.

    Se la mia risposta ti è utile, premi Accetta la risposta per supportarmi.

    Grazie,

    HL.

    La risposta è stata utile?


Risposta

Le risposte possono essere contrassegnate come "Accettata" dall'autore della domanda e "Consigliata" dai moderatori, in modo da consentire agli utenti di sapere che la risposta ha risolto il problema dell'autore.