Nerdio Manager uses Azure Files share technology to store App Attach packages and their associated metadata. You can use an existing Azure Files share or create a new one with Nerdio Manager.
Note
What you need to configure depends on how your session hosts are joined. Entra ID-joined hosts and AD DS-joined hosts have different, non-overlapping requirements. Work through the section that matches your hosts.
App Attach supports the following identity providers:
-
Microsoft Entra ID
-
Active Directory Domain Services (AD DS)
For background on App Attach itself, see the Microsoft article App attach and MSIX app attach in Azure Virtual Desktop.
Entra ID-joined hosts can use App Attach applications. The only requirements are on the storage account that holds the App Attach images:
-
It must be in the same subscription as the session hosts.
-
It must have a Reader and Data Access role assignment whose members include Azure Virtual Desktop and Windows Virtual Desktop ARM Provider.
Nerdio Manager creates that role assignment for you when you enable Entra ID host support on the storage account. You can do this on a new share or on a share you already have.
Note
The storage account can be joined to Active Directory, joined to Entra ID, or not joined at all. You do not need to configure share-level or NTFS permissions for Entra ID-joined hosts.
To enable Entra ID host support on an existing Azure Files share:
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Locate the Azure Files share that stores your App Attach images.
-
From the share's action menu, select Manage.
-
In the wizard that opens, go to the Storage account tab and select Entra ID host support.
-
Select SAVE to save.
Note
Enabling this option adds the Reader and Data Access role assignment, with Azure Virtual Desktop and Windows Virtual Desktop ARM Provider as members, to the storage account. If you would rather assign it yourself, add the role to the storage account under Access Control (IAM) in the Azure portal with those same two members.
All three of the following conditions are mandatory:
-
The storage account that stores the App Attach images is joined to AD DS.
-
App Attach NTFS permissions are configured on the file share.
-
Share-level permissions are configured.
Default file share NTFS permissions
-
BUILTIN\Administrators:(OI)(CI)(F) -
BUILTIN\Users:(RX) -
BUILTIN\Users:(OI)(CI)(IO)(GR,GE) -
NT AUTHORITY\Authenticated Users:(OI)(CI)(M) -
NT AUTHORITY\SYSTEM:(OI)(CI)(F) -
NT AUTHORITY\SYSTEM:(F) -
CREATOR OWNER:(OI)(CI)(IO)(F)
File share NTFS permissions for App Attach
-
BUILTIN\Users:(RX) -
BUILTIN\Users:(OI)(CI)(IO)(GR,GE) -
NT AUTHORITY\Authenticated Users:(OI)(CI)(M) -
CREATOR OWNER:(OI)(CI)(IO)(F)
Tip
Rather than setting these by hand, let Nerdio Manager apply them. In the Azure Files wizard, select Assign NTFS file-level permissions and then App Attach, which grants Authenticated Users Read permission to sub-directories in the share. This is the recommended option for shares containing App Attach applications.
Note
Assigning NTFS file-level permissions automatically creates a temporary VM to perform the permission assignment task.
Choose one of the following configurations.
Option 1: Read-only access for all authenticated identities
Set the default share-level permission on the storage account to at least Storage File Data SMB Share Reader for all authenticated identities.
In Nerdio Manager, use the Share-level permissions option in the Azure Files wizard to set this. SMB Share Reader gives all authenticated users read-only access to the share, which is what App Attach requires.
Option 2: Read-only access for domain computers
-
In Active Directory, create a new Global Security group in an Organizational Unit (OU) that is being synched to Entra ID with ADConnect.
-
Add Domain Computers to the new group.
-
In the Azure portal, open the file share's Access Control and add the new security group with at least the Storage File Data SMB Share Reader role.
Note
You may need to wait for the next sync cycle for new groups to be available in Entra ID.
Option 3: A custom configuration
Any configuration that gives the session host computer objects at least read access to the share is supported. Adapt the options above to suit your organization's security policies.
Comments (0 comments)