Windows 365 Frontline Shared is a new solution that expands Microsoft’s DaaS offering. It provides a temporary virtual machine to users, thus optimizing the cost of Windows 365 for those who do not work on it full-time.

This blog post will explain how to set up Windows 365 Frontline Shared within your organization, detailing each step of the process.

Article en Français

User Settings

This setting does not apply to Windows 365 Frontline Shared machines

Device Preparation group

Create the group to which apps and policies will be deployed

Add Intune Provisioning Client as an owner

Device Preparation Policy

In order to install the apps, apply the configs when provisioning the machine, it is necessary to create a device preparation policy.

  1. Go to Devices > Windows > Enrollment

  2. Select Device Preparation Policy

  3. Click Create > Automatic

  4. Click Next

  5. Choose a name

  6. Click Next

  7. Select the group you created earlier

  8. Click Next

  9. Click Add to select the apps and scripts to be applied during provisioning

  10. Click Add for each Note: Store applications must be in system context otherwise they are not installed during provisioning
  11. Click Save > Next

  12. Click Next

  13. Check that everything is good

  14. Click Save

**/!\ ** Don ‘t forget to assign applications and scripts to the group, adding to the Preparation Policy only defines what needs to be followed.

Create Provisioning Profile

Now all that’s left to do is create the machine provisioning policy, go to Intune > Devices > Windows 356 > Provisioning Policies

  1. Cliquer sur Create Policy

  2. Enter a Name

  3. Select Frontline > Shared > Microsoft entered Joined

  4. Select Microsoft Hosted Network and the desired region

  5. Check Single Sign On and then Click Next

  6. Select the image to use

  7. Click Next

  8. Choose the language and configure the machine name template

**/! \ ** it is not possible to have a – somewhere other than at the end of the prefix

**/!\ ** The name must be exactly 15 characters long

**/! \ ** the prefix must be a maximum of 7 characters

  1. Then select the readiness policy, the time allotted and whether the user can log in in case of failure

  2. Click Next

  3. Click Next

  4. Select User Group

  5. Click Select > Next

  6. Select the CPC size, assignment name, and number

  7. Click Select > Next

  8. Check that everything is correct and then click Create

Provisioning du Cloud PC

You can now go to All Cloud PCs and see that provisioning is in progress

Provisioning can take a little over an hour, so be patient.

The machine is ready, all that’s left to do is connect

1st connexion

  1. Go to https://windows.cloud.microsoft

  2. Click on connect

Below you will find the different connection steps which are the same as for an Enterprise or Frontline Dedicated CPC

The machine is ready to use

**/!\ ** It ‘s a temporary machine, make users aware of how to store their documents on OneDrive

/!\ ** Any file created or modified in the profile will be lost

**/!\ ** Any application installed outside of the Device Preparation Policy will no longer be present at the next connection

Note: the modified files in some sections of the disk are maintained, it may be interesting to hide the C to prevent a user from storing personal data that would be accessible by a person who is not authorized to see them

Reporting

As the number of simultaneous connections is limited to the number of machines provisioned, it is important to be able to track usage and disconnect a user if necessary

Go to Intune > Reports

Select Connected Frontline Cloud

Here we can see that a provisioning profile has reached its limit

You can click on it to find out more

Here we see that the limit has been waited 2 times during a month

To find out who is logged in, click Connect

If you want to disconnect one or more users is simple, select the CPCs, click on Bulk device action > Restart

Contenu de l’article

Bugs

During my tests I encountered a bug, my machine got stuck during provisioning, adding a machine to the profile unlocked it (failed)

What’s strange is that the image change was not taken into account even though it was done before adding a 2nd machine.

Reprovisioning the two machines solved everything

Related articles