Configure Azure Files Permissions for App Attach

Nerdio Manager uses Azure Files share technology to store App Attach packages and their associated metadata. You can use an existing Azure Files share or create a new one with Nerdio Manager.

Note

What you need to configure depends on how your session hosts are joined. Entra ID-joined hosts and AD DS-joined hosts have different, non-overlapping requirements. Work through the section that matches your hosts.

App Attach supports the following identity providers:

  • Microsoft Entra ID

  • Active Directory Domain Services (AD DS)

For background on App Attach itself, see the Microsoft article App attach and MSIX app attach in Azure Virtual Desktop.

Session hosts joined to Microsoft Entra ID

Entra ID-joined hosts can use App Attach applications. The only requirements are on the storage account that holds the App Attach images:

  • It must be in the same subscription as the session hosts.

  • It must have a Reader and Data Access role assignment whose members include Azure Virtual Desktop and Windows Virtual Desktop ARM Provider.

Nerdio Manager creates that role assignment for you when you enable Entra ID host support on the storage account. You can do this on a new share or on a share you already have.

Note

The storage account can be joined to Active Directory, joined to Entra ID, or not joined at all. You do not need to configure share-level or NTFS permissions for Entra ID-joined hosts.

To enable Entra ID host support on an existing Azure Files share:

  1. Navigate to Cloud Desktops > Storage > Azure Files.

  2. Locate the Azure Files share that stores your App Attach images.

  3. From the share's action menu, select Manage.

  4. In the wizard that opens, go to the Storage account tab and select Entra ID host support.

  5. Select SAVE to save.

Note

Enabling this option adds the Reader and Data Access role assignment, with Azure Virtual Desktop and Windows Virtual Desktop ARM Provider as members, to the storage account. If you would rather assign it yourself, add the role to the storage account under Access Control (IAM) in the Azure portal with those same two members.

Session hosts joined to AD DS

All three of the following conditions are mandatory:

  1. The storage account that stores the App Attach images is joined to AD DS.

  2. App Attach NTFS permissions are configured on the file share.

  3. Share-level permissions are configured.

App Attach NTFS permissions

Default file share NTFS permissions

  • BUILTIN\Administrators:(OI)(CI)(F)

  • BUILTIN\Users:(RX)

  • BUILTIN\Users:(OI)(CI)(IO)(GR,GE)

  • NT AUTHORITY\Authenticated Users:(OI)(CI)(M)

  • NT AUTHORITY\SYSTEM:(OI)(CI)(F)

  • NT AUTHORITY\SYSTEM:(F)

  • CREATOR OWNER:(OI)(CI)(IO)(F)

File share NTFS permissions for App Attach

  • BUILTIN\Users:(RX)

  • BUILTIN\Users:(OI)(CI)(IO)(GR,GE)

  • NT AUTHORITY\Authenticated Users:(OI)(CI)(M)

  • CREATOR OWNER:(OI)(CI)(IO)(F)

Tip

Rather than setting these by hand, let Nerdio Manager apply them. In the Azure Files wizard, select Assign NTFS file-level permissions and then App Attach, which grants Authenticated Users Read permission to sub-directories in the share. This is the recommended option for shares containing App Attach applications.

Note

Assigning NTFS file-level permissions automatically creates a temporary VM to perform the permission assignment task.

Share-level permissions

Choose one of the following configurations.

Option 1: Read-only access for all authenticated identities

Set the default share-level permission on the storage account to at least Storage File Data SMB Share Reader for all authenticated identities.

In Nerdio Manager, use the Share-level permissions option in the Azure Files wizard to set this. SMB Share Reader gives all authenticated users read-only access to the share, which is what App Attach requires.

Option 2: Read-only access for domain computers

  1. In Active Directory, create a new Global Security group in an Organizational Unit (OU) that is being synched to Entra ID with ADConnect.

  2. Add Domain Computers to the new group.

  3. In the Azure portal, open the file share's Access Control and add the new security group with at least the Storage File Data SMB Share Reader role.

Note

You may need to wait for the next sync cycle for new groups to be available in Entra ID.

Option 3: A custom configuration

Any configuration that gives the session host computer objects at least read access to the share is supported. Adapt the options above to suit your organization's security policies.

Was this article helpful?

0 out of 1 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Please sign in to leave a comment.