How to configure Windows 365 Enterprise Cloud PC | Setup Guide

Configure of Windows 365 Cloud PC

Windows 365 is a cloud-based service from Microsoft that allows businesses and individuals to create and use Windows virtual desktops, known as “Cloud PCs.” It can be accessed from anywhere virtually from any device with an internet connection.

Types of Windows 365 Cloud PC license

Windows 365 Business Ready to use cloud PCs. For smaller companies up to 300 users. It has simple management options. Anytime access to cloud PCs.
Windows 365 Enterprise More management tools to customize cloud PCs. Full integration with MS Intune. Unlimited Users. Anytime access to cloud PCs.
Windows 365 Frontline Single license to provision up to three Cloud PCs for non concurrent use. Access Cloud 365 PCs only during shift hours.
Windows 365 Government Services that span across the regular US government community cloud GCC.

Create a Resource Group

How to create resource group in Azure

Create a Virtual Network

Create Virtual Network in Azure

Create Subnet under Virtual Network

Create a Virtual Machine

How to create Virtual Machine in Azure

Create Virtual Machine Networking in Azure

Once the VM is created, add a DNS name, this will be used to RDP into the device with a static endpoint: Not Configured

Add DNS Name to RDP into the device with a static endpoint

Now access your VM from RDP or Bastian Session.

Add role and features from Server Manager

Add role based or feature based installation

Install Active Directory Domain Services

Install AD roles and features

Now its time to Promote server as a DC.

Promote server in AD

Create new forest in DC

Create DNS Delegation

Change NetBIOS Name

Select SYSVOL, Log and NTDS Folder

Server Manager

Create organizational units for Cloud PCs and Synced Users

Create OU in Active Directory Server

Create OU for Windows 365

Add M365 domain as a domain suffix in AD

Open Active Directory Domains and Trusts
Right click on Active Directory Domains and Trust > Properties

Active Directory Domain and Trust domain suffix in AD

Add initial domain from M365 tenant

Create user account under “Synced Users” OU

Grant Enterprise admin rights to user

EnterPrise Admin Member

User password never expire

NOTE: At this point, sign out from the local computer admin account and sign in with your new Enterprise admin account.

Create Service Account under “Builtin” OU or you can create a new OU and name it anything ANCServiceAccout and add user there.

Create ANC user account

Password never expired

Add permissions to service account to create ANC

Delegate “Add Computer objects” permissions over the ANC service account
Right click Cloud PCs OU and Delegate Control

Cloud PC Delegation Control

Delegation Control Wizard

Add ANC user account under Delegation control

Create a custom delegation control

Delegation control Create seleted objects in this folder

Delegation control Create all child objects

Install Azure AD Connect
Download link: https://www.microsoft.com/en-us/download/details.aspx?id=47594

Microsoft Entra Connect Sync

Microsoft Entra Connect Sync Use express settings

Login with Global Administrator

Login with Enterprise Admin

Microsoft Enter Sign in configration

Microsoft Entra Connect Sync Configure

Microsoft Entra Connect Sync Configuration complete

Configure sync scope in Azure AD Connect

Open Azure AD Connect

Microsoft Entra Connect customize synchronization options

Connect to Microsoft Entra ID

Microsoft Enter Sign Connect your directories

Microsoft Enter Connect Domain & OU Filtering

Microsoft Enter Connect Sync

Microsoft Enter Connect Sync Configuration

Configure HAADJ SCP

Double click the icon on the desktop for Azure AD Connect

Azure AD Connect

Azure AD Connect Configure device options

Microsof Azure Active Directory Connect

Microsoft Entra Connect ID

Configure Hybrid Microsoft Entra ID Join

Microsoft Entra Connect Sync Device operating systems

Azure AD Connect Configure SCP Configrations

Admin Credentials

Microsoft Entra Connect sync ready

Change DNS servers on vNet to point to DC

Add DNS Name to RDP into the device with a static endpoint

On the vNet, click on “DNS servers” and select “Custom”
Add the DNS server as the “Private IP address” of your Domain Controller.

Add DC IP to VNet DNS Server record

Sync account, assign licenses and add admin roles
Go to: https://portal.office.com and check Active Users
Once the account syncs, add licenses for Windows 365 and E5
You may also set your account as a Global Admin
At this point, your environment should be ready to create your first ANC and provisioning policy.

==

Create ANC

Create Hybrid Microsoft Entra Join ANC

Configure Network Details in ANC

For OU, you need to add Distinguish name format

For that Open Server Manager > Tools > Active Directory Users and Computers > Click on view from top left side and select Advanced Features > Right Click and select Properties

AD Users and Computers Advanced Features

OU Distinguished Name format

Add domain under Hybrid Entra join connection inside ANC

Create a Hybrid Microsoft Entra Join Connection in Windows 365

Create ANC in windows 365 cloud PC

Create Provisioning policy

Create Provisioning policy

Create Provisioning policy General

Create Provisioning policy Select Image

Create Provisioning policy Configuration

Create Group in Azure

Create Groups

If you are using Hybrid Cloud PCs then you need Hybrid Users. So I went to by DC and add new users: Anshuman, Kuldeep and Sandeep. After creating Users open powershell and run Start-ADSyncSyncCycle -PolicyType Delta command to sync these create users instently.

Create new users in AD

Add Users in Group in AD

Add Users in Group in Windows 365 Provisioning policy

Windows 365 Provisioning policy

Windows 365 Provisioning policy created successfully

https://admin.microsoft.com/

Assign Licenses in Windows 365 Cloud PC

Once users are added to the group and the license is assigned, the Cloud PCs will begin provisioning automatically.

Provision Cloud PCs in Windows 365

Provisioning will take time 40-60 minutes. At the time of Provisioning CPCs you can see the Changes on VNets under connected Devices.

Azure VNet Connected Devices CPC

Windows 365 Cloud PCs

Windows 365 Cloud PCs Created

Leave a Comment