Step #5: FSLogix and User Profile Management

With storage in place, the next step is to configure FSLogix, the profile management solution that lets user settings, data, and installed applications follow users between session hosts. This section covers setting up FSLogix, tuning its configuration per host pool, and managing which applications are available to users.

In this section:

  1. FSLogix and User Profile Management

FSLogix and User Profile Management

FSLogix is a user profile container technology that allows users to switch virtual desktop session hosts without losing access to their own customizations. With FSLogix, you can use OneDrive and the indexed search functionality in virtual desktops. This option was not available for legacy RDS User Profile Disks (UPDs).

FSLogix is integrated with AVD, and provides a seamless, on-demand seamless profile storage solution. The AVD for Business and SharePoint functionality level matches that of a stationary desktop - for example, on a physical PC or a laptop.

FSLogix supports active cache syncing in the AVD environment so that users get their updated files from any of the connected hosts.

FSLogix retains the user credentials. You do not need to sign in to OneDrive every time you start a session.

The Windows user profiles of AVD desktop users are encapsulated in VHD files and stored on a file server separate from the session host VMs. If a user is assigned to a pooled (i.e. non-persistent) desktop, the profile including Windows Search cache follows the user regardless of the virtual desktop VM they sign in to.

Nerdio Manager makes sure that setting up, configuring, and managing FSLogix Profile Containers is easy to do. You can create multiple FSLogix configuration profiles, and apply them on a per-host pool basis. This means you can have different FSLogix configurations where, for example, the storage locations are different, or where you have different registry parameters set at the per-host pool level.

Note

We ensure that the proper agent is installed on your image, or explain how to do it manually, and that the correct configuration profile is applied. This ensures that when a session host VM is joined to the host pool, or is re-imaged, all of this is automatically taken care of.

Related Topics

FSLogix Settings and Configuration

FSLogix settings and configuration

The FSLogix profile container is based on two components:

Nerdio Manager automatically installs the FSLogix application, by default, when a new session host VM is created, or an existing one is re-imaged. This is the most common use case.

Create an FSLogix profiles storage configuration

Nerdio Manager allows you to create FSLogix Profiles storage configurations.

To add an FSLogix Profiles storage configuration:
  1. Navigate to Cloud Desktops > Azure Virtual Desktop > Profiles Management.

  2. From the bottom right-hand side, select New profile, and from the menu options, select FSLogix

  3. In the FSLogix Profiles storage area, select Add.

  4. Enter the following information:

    • Name: Type the profile name.

    • Version From the drop-down list, select the FSLogix version.

    • Use Cloud Cache: Select this option to enable FSLogix Cloud Cache.

      Tip

      For performance reasons, it is strongly recommended that you use Premium SSD and Ephemeral OS disks when Cloud Cache is enabled. (Standard SSD disks might be sufficient in very small environments or a testing scenarios.)

      Note

      See the following Microsoft article for more information about FSLogix Cloud Cache.

      Cloud Cache allows you to specify multiple profile storage location. It asynchronously replicates the profiles and makes the profiles available in multiple storage locations at the same time. So, if one of the locations is not available, the session host automatically fails over to one of the alternate locations.

    • Configure session hosts registry for Entra ID joined storage: Select this option to enable Entra ID Kerberos functionality and Entra ID account credentials loading.

      Note

      See this Microsoft article for more information.

    • Exclude the local admin accounts from FSLogix: Select this option to prevent local admins profiles creation in FSLogix storage location.

    • Exclude domain account from FSLogix: Select this option to prevent domain account profiles from being created in the FSLogix storage location, and then enter the domain details in the box below.

      Note

      When FSLogix is having issues on a session host, there is still a way to sign in with an excluded user for troubleshooting purposes.

    • Manage App Service settings: Select this option to edit the FSLogix App Service Registry settings.

    • Manage Log settings: Select this option to manage log settings.

    • FSLogix Profiles path (VHDLocation): From the drop-down list, select an Azure Files share. Alternatively, type in a UNC path.

      Note

      You can specify up to 4 paths. In addition, use the arrows to change the order of the paths. The profiles are created in all of these locations.

    • FSLogix Registry Options: From the Edit mode drop-down list, select whether you want to work with All settings or Advanced.

      • For All settings:

        • In the Configuration column, enter the setting's value.

        • Select Clear to set a specific setting to Not configured.

        • Select Clear all to set all the settings to Not configured.

      • For Advanced:

        • You can add DWORD values in the format: "ValueName":dword:ValueData. For example: "ProfileType"=dword:00000003.

        • You can add string values in the format: "ValueName":"ValueData". For example: "VolumeType":"vhdx".

    • Configure Office Container to redirect Microsoft Officer user data: Toggle on this option to redirect only areas of the profile that are specific to Microsoft Office.

      Note

      Office Containers separate Microsoft Office data (for example, OST files) from the overall user profile for easier troubleshooting. Office Containers and Profile Containers are stored in separate VHDX files can be stored on different file shares. See this Microsoft article for details.

      • FSLogix Office Container path (VHDLocation): Modify as needed.

      • FSLogix Office Container Registry Options: From the Edit mode drop-down list, select whether you want to work with All settings or Advanced, and then configure the settings as required.

    • Redirections: Toggle this option on if you want to include Redirections in the global profile for re-use across customers.

      Note

      See this Microsoft article for more information about redirections.

    • Force the installation of FSLogix apps even if already installed: Select this option to force the re-installation of the FSLogix agent and applications.

  5. Once you have entered all the desired information, select OK.

Set an FSLogix profiles storage configuration as default

Nerdio Manager allows you to set one FSLogix Profiles storage configuration as the default.

To set Nerdio Manager to install the FSLogix application automatically:
  1. Navigate to System > Settings > Integrations.

  2. In the FSLogix Profiles storage area, add, change, and remove the profiles as needed.

    Note

    Be sure to select the following options for FSLogix profiles linked to hybrid host pools.

    • Use Cloud Cache: Select this option to enable FSLogix Cloud Cache in the host pools, and the session hosts within those host pools, that use this FSLogix profile.

    • Use Azure page blobs: Select this option to use storage account blob containers to store users profiles. These containers are accessed using storage account access keys.

  3. Locate the desired FSLogix Storage configuration profile and select set default.

Note

  • If you set the Use FSLogix Profiles option to Off, the FSLogix app is installed automatically when new hosts are created or re-imaged.

  • Each host pool's FSLogix settings can be customized.

  • FSLogix is not installed on the desktop image.

  • The FSLogix registry settings are not set on the desktop image.

  • Session hosts should not receive conflicting FSLogix configurations from GPOs.

Related Topics

FSLogix and User Profile Management

FSLogix Per-Host Pool Customization

Which FSLogix Profile storage option should I choose?

FSLogix per-host pool customization

You can configure FSLogix with Nerdio Manager and apply its settings to each host pool in the AVD deployment.

For more information refer to Host Pools.

Adding a server includes installing FSLogix and applying the necessary settings that were selected for the host pool. You can use the global default settings or customize the settings for each host pool.

To configure customized FSLogix settings for a host pool:

Note

Any settings configured here are applied only to newly created or re-imaged hosts in this pool.

  1. Navigate to the list of host pools and locate the host pool you wish to change.

  2. Select the more options More options.png menu, and then select Settings .

  3. From the menu options on the left-hand side, select FSLogix.

  4. Enter the following information:

    • Enable FSLogix profiles: Select the toggle to enable FSlogix profiles.

      Note

      If this option is not enabled, Nerdio Manager does not install the FSLogix profile container application on newly created VMs when they are deployed in this host pool. Existing VMs are not affected.

    • From the drop-down list, select an existing profile name. Alternatively, select Custom to create a custom profile for this host pool.

      Note

      If you select an existing profile then this will automatically complete the configuration with the detail in the selected profile, which cannot be edited. If you select Custom you can configure the profile as required.

    • Version From the drop-down list, select the FSLogix version.

    • Configure session hosts registry for Entra ID joined storage:

    • Exclude the local admin accounts from FSLogix:

    • Exclude domain accounts from FSLogix:

    • FSLogix profiles path (VHDLocation).

    • Configure Office Container to redirect Microsoft Office user data (ODFC):

      • FSLogix Office Container path (VHDLocation):

    • Use Cloud Cache: Select this option to enable FSLogix Cloud Cache.

      Tip

      For performance reasons, it is strongly recommended that you use Premium SSD and Ephemeral OS disks when Cloud Cache is enabled (standard SSD disks might be sufficient in very small environments or a testing scenario).

      Note

      See the following Microsoft article for more information about FSLogix Cloud Cache.

      Cloud Cache allows you to specify multiple profile storage location. It asynchronously replicates the profiles and makes the profiles available in multiple storage locations at the same time. So, if one of the locations is not available, the session host automatically fails over to one of the alternate locations.

    • Manage App Service settings: Select this option to edit the FSLogix app service registry settings.

    • Manage Log settings: Select this option to manage log registry settings.

    • FSLogix registry options: From the Edit mode drop-down list, select whether you want to work with All settings or Advanced.

      • For All settings:

        • From the tabs, select the component you want to configure. Select from Profile Settings, ODFC Settings, Cloud Cache Settings, App Service Settings, or Log Settings.

        • In the Configuration column, type the setting's value. For example, to configure profile settings, select the Profile Settings area, select the box in the Configuration column, and enter the setting.

        • Select Clear tab configuration values to set all values for that particular component as Not configured.

        • Select Clear all configuration values to set all the settings to Not configured.

          • Optionally, in the Search settings by name box, you can filter the settings by entering the name or part of the name of the setting.

      • For Advanced:

        • You can add DWORD values in the format: "ValueName":dword:ValueData (example: "ProfileType"=dword:00000003).

        • You can add string values in the format: "ValueName":"ValueData" (example: "VolumeType":"vhdx").

    • Redirections: If you want to include redirections in the global profile for re-use across customers select the toggle to enable this feature.

      Note

      For more details, see Types of containers.

    • Force the installation of FSLogix apps even if already installed: Select this option to force the reinstallation of the FSLogix agent and applications.

    • Apply to existing hosts: Select this option to apply these changes to existing hosts. Otherwise, the change only effect new or re-imaged hosts.

      • Process Hosts in Groups Of: Type the number of concurrent actions to execute during this bulk operation.

      • Number Of Failures Before Aborting: Type the number of failures that causes the process to stop.

      • Messaging: To send messages to active users, select the toggle to enable this feature and enter the following details:

        • Delay: From the drop-down list, select the number of minutes to wait after sending the message before starting the process.

        • Message: Type the message you want to send to the users.

      • Schedule:To apply the changes at a selected time, select the toggle enable this feature and enter the following details:

        • Name: Enter a name for the schedule.

        • Description: Enter a description for the schedule.

        • Start Date: Select the Start Date box and from the calendar, select the desired start date..

        • Time Zone: From the drop-down list, select the time zone for the Start time.

        • Start Time: From the drop-down lists for hours and minutes, select the time to start.

        • Repeat: From the drop-down list, select the recurring schedule, if desired.

          Note

          The drop-down has the option After Patch Tuesday. This allows you to create a recurring schedule based on Patch Tuesday.

          • Days After: If you selected After Patch Tuesday, type the number of days after Patch Tuesday to run the scheduled task.

  5. Once you have entered all the desired information, select Save or Save & close.

Related topics

Host Pools

Manage Installed Applications on Host Pools

Nerdio Manager allows you to leverage FSLogix App Masking technology to automatically discover applications installed on a host pool and configure rules to determine which users can access which applications. User access can be controlled at the individual application level and can be assigned by user or security group. Multiple applications can be grouped together for consolidated access management. Simply install all the required applications on the desktop image, update the session hosts, and define which users can access which applications.

Note

FSLogix App Masking is currently not supported in AAD joined host pool scenarios.

Note

This process does not work by simply hiding shortcuts. It actually hides all the components of the application. For example, if you create a rule to hide Chrome from all users:

  • The Chrome folder in Program Files appears to the user to be empty. In fact, the folder is not empty, it is just hidden from the user.

  • Chrome is unpinned from the taskbar, if necessary.

  • The Chrome desktop shortcut is removed, if necessary.

  • The user does not find Chrome when performing a Cortana search.

The following steps must be performed in order to manage the installed apps:

  • Discover and edit installed applications: The discovery is automatically performed whenever a host pool is created or re-imaged. In addition, it is also runs every few days in order to find applications that may have been added (not through a re-image process). Alternatively, the discovery can be run manually.

  • Create rule sets: Create rule sets to determine which users have access to which applications.

  • Apply the rule sets to the session hosts VMs: Apply the selected rule sets to all the session host VMs. You can wait to perform this when a session host is created or re-imaged. Alternatively, you can manually apply the selected rule sets immediately.

These steps are discussed in detail below.

Discover and Edit Installed Applications

The first step to managing the installed applications is to discover the applications that are installed. In addition, Nerdio Manager allows you to edit and manually add applications.

To discover and edit the installed applications:
  1. Locate the host pool you wish to work with.

  2. From the action menu, select Applications> Installed apps.

  3. Note the date and time the discovery was last performed.

    Note

    If the host pool was created recently, you may not see any discovered applications because a discovery has not yet been performed yet. You may need to wait up to 48 hours or initiate a manual discovery.

  4. If desired, select (nn apps) to see a list of discovered applications and additional details.

  5. If desired, select Discover apps to perform a manual discovery.

    • Enter the following information:

    • Session Host VM: From the drop-down list, select the session host VM you want to use to perform the discovery.

    • Select Advanced to perform any of the following:

      • Select image150.png to remove a discovered application.

      • Edit the name or installation directory information for any discovered application, if desired.

      • Select image151.png to add an application and its installation directory. The discovery process looks for all the components of this application in this directory and automatically detects them.

    • Once you have entered all the desired information, select Run now.

    • Watch the discovery process's progress in the tasks pane. Be sure to wait for the task to finish before continuing.

      Note

      If the session host VM is powered off, the system powers on the VM to perform the discovery.

Create Rule Sets

The next step to managing the installed applications is to create rule sets. In essence, you determine which users have access to which applications.

To create rule sets:
  1. Locate the host pool you wish to work with.

  2. From the action menu, select Applications> Installed apps.

  3. Select Add rule set.

  4. Enter the following information:

    • Rule Set Name: Type the name of the rule set.

    • Enabled: Select this option to enable the rule set.

      Note

      Only rule sets that are enabled are applied to hosts.

    • Applications: From the drop-down list, select the discovered applications to add to the rule set.

      • If desired, expand the application to see its details.

      • Edit, add, or delete the application's components, as desired.

      • Rule Type: App Masking: This allows you to manage access of installed components.

      • Rule Type: Redirection: This enables you to dynamically redirect a folder, file , registry key, or value to an alternative based on the user or group. For example, as shown above, you can have an app use a different license file for the sales team.

      • Rule Type: App Container: This enables you to dynamically redirect a folder to another attached disk. For example, as shown above, redirect to another drive that contains the licenses for the sales team.

    • Apply to all users: When this option is selected (default), the applications are available only to users you specify in the Exclude users and groups field. The applications are hidden and unavailable for any other users.

      Note

      • Unselect this option if you need to make the applications available for all users.

      • If you still need to restrict access for some users or groups, include those in the Apply only the following users and groups field.

        Note that the Apply only the following users and groups field becomes available only when the Apply to all users option is disabled.

    • Exclude local administrators: Select this option to not apply this rule to the local administrators group.

    • Exclude users and groups: Select the users to exclude from the allowlist or the blocklist.

  5. Select Save & apply to save the rule and apply it immediately to all session host VMs. Select Save & close to save the rule.

    Note

    When you select Save & close, the rule is applied when a session hosts are created or re-imaged. Alternatively, you can manually apply the rule later on when desired.

Manage and Apply Rule Sets

Nerdio Manager allows you to manage rule sets. This includes applying rule sets, deleting, editing, etc.

To manage rule sets:
  1. Locate the host pool you wish to work with.

  2. From the action menu, select Applications> Installed apps.

  3. You may select multiple rules and then Select bulk action to perform a bulk action on the selected rules.

  4. From the action menu next to each rule set, you can:

    • Select Edit to edit the rule set.

    • Select Apply to hosts to immediately apply the rule set to all session hosts. (see below)

    • Select Disable to disable the rule set.

    • Select Delete to delete the rule set.

    • Select Assign to change the rule set assignments.

  5. In addition, you can:

    • Select Discover apps to immediately start the applications discovery process. (see above)

    • Select Add rule set to add a new rule set. (see above)

    • Select Apply all rule sets to immediately apply all the rule sets to all the session hosts. (see below)

To apply rule sets:
  1. Select Apply to hosts (for a single rule or selected rules) or Apply all rule sets (for all rules).

  2. Enter the following information:

    • How to apply: From the drop-down list, select how the rule set should be applied.

      • Clear all existing FSLogix rule sets on hosts: Select this option to clear all the FSLogix rule sets on the hosts before applying this rule set.

      • Clear only Nerdio Manager created rule sets on hosts: Select this option to clear all the rule sets that were created by Nerdio Manager on the hosts before applying this rule set.

      • Do not clear any rule sets, overwrite rule sets being applied only: Select this option to leave all the existing rule sets alone and only overwrite the rule set that is being applied.

    • Process hosts in groups of: Type the number of concurrent actions to execute during this bulk operation.

    • Number of failures before aborting: Type the number of failures that causes the process to stop.

    • Messaging: Toggle on the Messaging to send messages to active users.

      • Delay: From the drop-down list, select the number of minutes to wait after sending the message before starting the process.

      • Message: Type the message you want to send to the users.

  3. Once you have entered all the desired information, select OK.

    The rule set application process starts.

Export Rule Sets

Nerdio Manager allows you to export rule sets to either a JSON file or a host pool.

To export rule sets:
  1. Locate the host pool you wish to work with.

  2. From the action menu, select Applications> Installed apps.

  3. Select the rule set(s) you wish to export.

  4. From Select bulk action action menu, select Export rule sets.

  5. Enter the following information:

    • Export to: From the drop-down list, select the export destination.

      Note

      When exporting to a JSON file, the file is downloaded to the browser's default download folder.

    • Destination host pool: When exporting to a host pool, from the drop-down list, select the host pool.

  6. Once you have entered all the desired information, select OK.

    The rule set export process starts.

Import Rule Sets

Nerdio Manager allows you to import rule sets that were previously exported in a JSON file or from a host pool.

To import rule sets:
  1. Locate the host pool you wish to work with.

  2. From the action menu, select Applications> Installed apps.

  3. From the Add rule set action menu, select Import rule sets.

  4. Enter the following information:

    • Import from: From the drop-down list, select the import location.

    • Host pool: When importing from a host pool, from the drop-down list, select the host pool.

    • JSON file: When importing from a JSON file, select the file.

    • Activate imported rule sets: Select this option to activate the imported rule sets after they are imported.

  5. Once you have entered all the desired information, select Install.

    The rule set import process starts.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.