Step #2: Desktop Images

Once Nerdio Manager is installed, the next step is to prepare the desktop images your host pools will be built from - whether you're importing existing images or letting Nerdio Manager manage new ones for you.

Desktop Images

This section discusses topics related to desktop images. We will discuss the various import and lifecycle management options, as well as different ways to automate certain tasks in more advanced scenarios.

After creating a new Workspace, the next step in building out an AVD environment is to create one or multiple host pools housing your virtual machines (see Host Pools for more information). Virtual machines are created based on a desktop image, which holds the operating system, your applications, and anything else you might want to add. For this to work, we first need to create at least one desktop image.

Before we continue, it is important to understand that images can be created or imported in different ways. Even when there are no images imported into Nerdio Manager, the custom Azure images part of your subscription can be used to build new host pools and re-image existing host pools in exactly the same way as with imported images.

If you do choose to import your images into Nerdio Manager, you can take advantage of many different management features otherwise not available.

In addition, when images are imported into Nerdio Manager all of your management and lifecycle activities are done using a single management portal.

Once an image is created or imported, regardless of the type of image (we'll explain in more detail going forward), creating new host pools and re-imaging existing host pools is done in the same way. In the sections below we will walk you through it step by step.

Management and lifecycle tasks for imported desktop images

No matter where your desktop images are imported from, their management and lifecycle tasks are the same.

Typical desktop image lifecycle

The typical desktop image lifecycle is as follows:

  1. Import the desktop image.

    See any of the following for detailed information:

  2. Power on the desktop image:

    1. Navigate to Cloud Desktops > Desktop Images.

    2. Locate the desktop image you wish to power on.

    3. Select Power on.

  3. Use the VM's IP address or name to connect to it using RDP and make all the desired changes.

  4. Select Power off & set as image.

    See Desktop Images Set as Image for details.

    Note

    An extensive automation process begins that commits the changes to an image object. This includes many tasks you would have had to do manually like Sysprep and sealing the image.

    You can see the job's progress in the logs. See Desktop Images Change Log Feature for details about the logs.

  5. Once the image is set, you can use it to build new host pools or re-image an existing host pool.

    For details, see:

Endpoint management software integration

Nerdio Manager allows you to use the power of an endpoint management tool (for example, Microsoft's Endpoint Configuration Manager or Ivanti's Endpoint Manager) to leverage its power to work with Nerdio Manager.

Example of endpoint management software integration

Patch Tuesday, when Microsoft releases its monthly software updates, occurs on the second Tuesday of each month at about 10 AM Pacific Standard Time. You can use your endpoint management tool, along with Nerdio Manager, to fully automate applying the Windows Updates to the desktop image and re-imaging the host pools with the updated desktop image.

Note

This is just one example of the many things you can do using these built-in automation tools.

  • In Nerdio Manager, when you perform the Set as image function, be sure to select the Leave desktop image VM running option. This leaves the VM running after the Set as image task completes and the endpoint management tool can access the VM and change the image.

  • In the endpoint management tool, create a recurring scheduled job/runbook on Patch Tuesday to apply the Windows Updates.

  • In Nerdio Manager, configure the Set as image function for the desktop image to be a recurring job that starts shortly after the endpoint management tool's job completes. See Desktop Images Set as Image for details about configuring the job.

  • In Nerdio Manager, configure the Re-image Hosts function for the host pool to be recurring job that starts shortly after the Set as image process completes. See Resize/re-image a host pool for details about configuring the job.

So, by creating three recurring scheduled jobs you can apply the Windows Updates to the VM, set the VM image, and then update the host pool with the updated desktop image every month.

Import an Existing VM

You can import an existing VM as an image into Nerdio Manager. For example, you can take a custom VM from another virtual desktop deployment, that has all your applications installed, and use it as a custom image in your Nerdio Manager AVD deployment.

Note

For this to work, your VM needs to be based on a Managed Disk. That is, you need to generate the accompanying SAS URL directly from the Azure portal, as explained below.

To import an image:
  1. In Azure, navigate to the virtual machine.

    Warning

    Make sure that the VM is powered off.

  2. Navigate to Settings > Disks.

  3. Select the OS disk.

  4. Navigate to Settings > Disk Export.

  5. Select Generate URL.

    The URL is generated.

  6. Copy the generated URL to the clipboard.

  7. In Nerdio Manager, navigate to Cloud Desktops > Desktop Images.

  8. Select Add from Azure VM.

  9. Enter the following information:

    • SAS URL: Paste the URL from the clipboard.

    • Create image VM as Gen2: Select this option to create the VM as Gen2.

      Note

      By default, desktop image VMs are created as Gen1. To learn more about the differences between Gen1 and Gen2 VMs, see Support for Generation 2 VMs on Azure.

    • Security Type: From the drop-down list, select the security type.

      Note

      • Security type refers to the different security features available for a virtual machine. Security features like Trusted Launch and Confidential virtual machines improve the security of Gen2 VMs. However, additional security features have some limitations, which include not supporting back up, managed disks, and ephemeral OS disks. See the following Microsoft articles for more information:

      • Trusted launch for Azure virtual machines

      • About Azure confidential VMs

        • If you select Standard, Trusted launch virtual machines, or Confidential virtual machines, then the desktop image and session host VMs are created with the specific security type.

        • If you select one of the xxxx supported options, then the desktop image is created as Standard but the session host VMs can be deployed as Standard or the supported type(s). (Trusted Launch and/or Confidential)

    • Uninstall FSLogix app: Select this option if the FSLogix app is already installed in the base image and you want to remove it in order to allow Nerdio Manager to manage FSLogix.

    • Uninstall AVD agent: Select this option if you are creating an image from an existing AVD session host where the AVD agent has been previously installed.

    • Enter the information for the other fields. See Import Images from the Azure Library for detailed information.

  10. Once you have entered all the desired information, select OK.

    The desktop image import task starts.

Tip

Be sure to uninstall the AVD agent before you set this imported VM as a desktop image. See Desktop Images Manually Uninstall AVD Agent for details.

Import Custom Azure Managed Images

Nerdio Manager allows you to leverage your customized and managed Azure images and deploy them directly into Nerdio Manager.

To import an Azure custom image:
  1. Navigate to Cloud Desktops > Desktop Images.

  2. Select Add from Azure library.

  3. Enter the following information:

    • Azure Image: From the drop-down list, select the desired image.

      Note

      The list contains all the standard Azure Marketplace images. In addition, it contains all the custom images that are available inside your Azure subscription.

      Tip

      Hover over any unavailable (grayed out) custom image to see why it is unavailable.

    • Enter the information for the other fields. See Import Images from the Azure Library for detailed information.

  4. Once you have entered all the desired information, select OK.

    The desktop image is created. This may take up to an hour to complete.

Import images from the Azure library

Nerdio Manager allows you to import a desktop image from the Azure library into a workspace.

To import an image from the Azure library:
  1. Navigate to Cloud Desktops > Desktop Images.

  2. From the bottom-right of the page, select New from Azure library.

  3. Enter the following information:

    Note

    For several of the required parameters, you may filter the available choices by using the resource selection rules. For example, you may filter the VM size or OS disk choices for Intel RAM-optimized VMs only. See Resource Selection Rules Management for details.

    • Name: Enter the desktop image's name.

    • Description: Enter the description.

    • Network: From the drop-down list, select the network to which the VM connects.

      Note

      The VM is created in the Azure region associated with the network.

    • Azure Image: From the drop-down list, select the desired image.

      Note

      • Select the image based on your Windows OS requirements, as supported by AVD. For example: Windows 11 EVD Multi-Session (EVD = Enterprise Virtual Desktop).

      • Images labeled Microsoft 365 Apps include a pre-installed version of Microsoft 365 Apps for enterprise. The apps are activated when licensed users sign in to the desktop.

    • VM Size: From the drop-down list, select the size.

    • OS Disk: From the drop-down list, select the disk. You can also select the performance tier.

    • Resource Group: From the drop-down list, select the resource group to contain the network interface cards of the VM.

    • Security type: From the drop-down list, select the security option that best suits your desktop image VM.

      Note

      • Standard is set by default. Additional security options are only available for generation 2 VMs with the Geographic distribution & Azure compute gallery option enabled.

      • The Trusted launch and Confidential virtual machines security options help improve the security of Azure generation 2 virtual machines. However, additional security features they provide also have some limitations, such as the lack of support for backup, managed disks, and ephemeral OS disks. To learn more, see:

    • The following options are available only when the Trusted launch virtual machines option is selected as the Security type:

      • Secure Boot: Select this option to enable Secure Boot, which helps protect your VMs against boot kits, rootkits, and kernel-level malware.

      • vTPM: Select this option to enable Virtual Trusted Platform Module (vTPM), which is TPM 2.0 compliant and validates your VM boot integrity apart from securely storing keys and secrets.

      • Integrity Monitoring: Select this option to enable cryptographic attestation and verification of VM boot integrity along with monitoring alerts if the VM didn't boot because the attestation failed with the defined baseline.

    • Join to AD: Deselecting this means the VM is not joined to AD during the creation process. This prevents AD GPOs from applying to the image before it is created. Be sure to specify local administrator credentials below to be able to connect to the VM, since it won't be a member of the AD domain.

    • Do not create image object: Select this option to create only a desktop image VM but not an image object.

      Note

      You need to create the image object. Select Power off and set as image after the VM is created before this desktop image can be used for session host creation. If you skip image creation, you can make changes to the VM before it is converted to an image.

    • Skip removal of local profiles: Select this option to bypass this step and not remove local user profiles before running Sysprep.

      Note

      During the image creation process, Nerdio Manager removes all local user profiles. This increases the likelihood of Sysprep success. Selecting this option bypasses this step. If there are any partially installed APPX apps on the image VM, Sysprep will fail to remove them.

    • Enable time zone redirection: Select this option to enable time zone redirection on the image. This allows each user to see their local device's time zone inside of their AVD desktop session.

    • Set time zone: Select this option to set the time zone of the VM and then, from the drop-down list, select the time zone.

    • Remove FSLogix apps: Select this option to remove the FSLogix agent if it's found on the image.

      Note

      The FSLogix agent is not required on the desktop image. The latest FSLogix agent will be installed automatically on session hosts that are created from this desktop image.

    • Install App Attach certificates: Select this option to install all the stored certificates on the VM, if applicable.

      Note

      To view the stored certificates, navigate to App Attach > Certificates.

    • Enable App-V client service: Select this option if the VM will use App Attach packages that contain App-V packages.

    • Optimize disk type when desktop image is stopped: Select this option to downgrade the OS disk type when the desktop image is stopped in order to save money. When the VM starts, the OS disk type is changed back to the selected one.

    • Enable Boot Diagnostics: Select this option (enabled by default) to collect and store diagnostic logs and screenshots while the VM boots.

    • Boot diagnostic storage account: Applies only if the boot diagnostics feature is enabled. Leave this field set to Managed Storage Account (recommended) to store boot diagnostic logs in an Azure-managed storage account, or select a user-managed storage account from the drop-down list.

    • Enable encryption at host: Select this option to provide end-to-end encryption for your VM data at rest and in transit, starting with the Azure hosts.

    • Provide custom credentials for a local administrator user: Toggle this option On to enter the admin username and password.

    • Geographic distribution & Azure compute gallery: Select this option to store the image in Azure Compute Gallery and automatically distribute it to the selected Azure regions.

      • Azure Compute Gallery: From the drop-down list, select an existing Azure Compute Gallery or create a new one.

        Note

        Only one Azure Computer Gallery can be selected. The existing Azure Compute Gallery must be in a linked resource group in the same Azure subscription as the image VM.

      • Azure Regions: From the drop-down list, select Azure regions where the Desktop Image version should be replicated.

        Note

        The current Azure region must be part of the selection.

      • Specialized image: Select this option if the image is a specialized image.

        Note

        • Generalized images have had machine and user-specific information removed by running a command on the VM.

        • Specialized images retain this information and have not gone through the generalization process.

      • Hibernation supported: Select this option if you want to allow the VM to hibernate.

        Note

        Hibernation provides the ability to deallocate your virtual machine while persisting the memory contents. This allows you to resume from where you left off the next time you start your VM. Note that hibernation cannot be enabled or disabled after the image is created.

      • Replica Count (Per Region): Specify the number of replicas per region.

        Note

        • Azure Compute Gallery replicas support a maximum of 20 concurrent clone operations per replica.

        • Ensure that the number of replicas specified meets your deployment requirements. Up to 100 replicas per region are supported.

        • Replicas can only be deployed within the same subscription.

    • Run the following scripted actions: Toggle this option On to specify the scripts that run during creation.

      Note

      • Windows scripts are executed via the Azure Custom Script extension and run in the context of LocalSystem account on the clone of the desktop image VM before it is sysprepped. These commands do not run on the image VM itself.

      • Azure runbooks are executed via the Azure automation account and run in the context of Nerdio Manager app service principal.

      • Several variables are passed to the script and can be used in the PowerShell commands.

      • If necessary, provide the required parameters.

    • Pass AD credentials: Select this option to pass AD credentials that are specified on the Settings > Integrations > Active Directory page to the scripts being executed. In the script, reference them as $ADUsername and $ADPassword.

    • Applications Management: Toggle this option On to specify the applications to deploy during creation.

      • Applications: In the applications list, select Add new application, and then from the drop-down list, select the application to include in this policy.

        Note

        • You may add as many applications as desired.

        • Drag and drop an application in the list to change its order on the list.

        • Select the "X" next to an application to remove it from the list.

      • Install app: Select whether the deployment policy should install the selected applications.

        • From the drop-down list, select the app to be installed.

        • Optionally, select the following:

          • Reboot after installation: Select this option to reboot the clone of the desktop image VM after this application is installed. Subsequent application tasks will resume once the reboot is complete.

          • Show favorites only: Select this option to display only those applications that are marked as favorites. Otherwise, you may search the list of applications.

      • Uninstall app: Select whether the deployment policy should uninstall the selected applications.

        • From the drop-down list, select the app to be uninstalled.

        • Optionally, select Show favorites only.

      • Install group: Select this option to install an application group.

        • From the drop-down list, select the application group to be installed.

    • Apply tags: Optionally, enter the Name and Value of the Azure tag.

      Note

      You can specify multiple tags. The specified tags are applied to image VM, OS disk, network interface, image object, and Azure Compute Gallery image. For details about using tags to organize your Azure resources, see Use tags to organize your Azure resources and management hierarchy.

  4. Once you have entered all the desired information, select OK.

The desktop image is created. This may take up to an hour to complete.

Desktop images: set as image

Nerdio Manager provides a powerful tool that performs an extensive automation process to commit the desktop image changes to an image object. This includes many tasks you would have had to do manually like Sysprep and sealing the image. This would normally be done after you have made the updates to your image. Once you perform Set as image, the image object is created and is ready to be used either to build new host pools or to re-image existing host pools.

To set a desktop image:
  1. Navigate to Cloud Desktops > Desktop Images.

  2. Locate the desktop image you wish to work with.

  3. From the action menu, select Power off & set as image or Set as image (according to the power state of this desktop image).

  4. Enter the following information:

    • Run the following scripted actions before set as image: Toggle this option On to run scripted action(s) before the set as image.

      Note

      For example, you can run scripts to optimize the image, install software, or install updates.

      • From the drop-down list, select the scripted action(s) you wish to run.

      • Pass AD credentials: Select this option if you want to use them to run the scripted actions.

    • Applications Management: Toggle this option On to specify the applications to deploy during creation.

      • Applications: In the applications list, select Add new application, and then from the drop-down list, select the application to include in this policy.

        Note

        • You may add as many applications as you need.

        • Drag and drop an application in the list to change its order on the list.

        • Select the "X" next to an application to remove it from the list.

      • Install/Uninstall: Select whether the deployment policy should install or uninstall the selected applications.

      • Reboot after installation: Select this option to reboot the clone of the desktop image VM after this application is installed. Subsequent application tasks will resume once the reboot is complete.

      • Show favorites only: Select this option to display only those applications that are marked as favorites. Otherwise, you may search the list of applications.

    • Schedule: Toggle the Schedule option On to perform the operations at a selected time(s). See Manage Schedules for Tasks for details about creating a schedule.

    • Refresh image from Azure Marketplace: Toggle this option On to remove the existing image object and replace it with the latest version of the selected Azure Marketplace image.

      Note

      Enabling this option removes the existing desktop image VM and re-creates it from the latest version of the selected Azure Marketplace image.

    • Security type: This option is locked based on the selection made when the image was created or imported into Nerdio Manager.

      Note

      • Standard is set by default. Additional security options are available only for generation 2 VMs with the Geographic distribution & Azure compute gallery option enabled.

      • The Trusted launch and Confidential virtual machines security options help improve the security of Azure generation 2 VMs. However, additional security features they provide also have some limitations, such as the lack of support for backup, managed disks, and ephemeral OS disks. To learn more, see:

    • Geographic distribution & Azure compute gallery: Select this option to store the image in Azure Compute Gallery and automatically distribute it to the selected Azure regions.

      • Azure Compute Gallery: This option is locked based on the selection made when the image was created or imported into Nerdio Manager.

        Note

        Only one Azure Computer Gallery can be selected. The existing Azure Compute Gallery must be in a linked resource group in the same Azure subscription as the image VM.

      • Azure Regions: From the drop-down list, select Azure regions where the desktop image version should be replicated.

        Note

        The current Azure region must be part of the selection.

      • Version Increment Type: From the drop-down list, select one of the following options:

        • Major

        • Minor

        • Revision

        Note

        Version numbers are in the format Major.Minor.Revision. For example, when updating version 1.4.3, the up-level version would be numbered as follows, depending on the option you choose in the Version Increment Type dropdown:

        • Major: 2.0.0

        • Minor: 1.5.0

        • Revision: 1.4.4.

    • Specialized image: Select this option if the image is a specialized image.

      Note

      Generalized images have had machine and user-specific information removed by running a command on the VM. Specialized images retain this information and have not gone through the generalization process.

    • Hibernation supported: Select this option if you want to allow the VM to hibernate.

      Note

      Hibernation provides the ability to deallocate your virtual machine while persisting the memory contents. This allows you to resume from where you left off the next time you start your VM. Note that hibernation cannot be enabled or disabled after the image is created.

    • Stage new image as inactive: Select this option to create the new image version without setting it as active.

      Note

      Any existing configurations continue to use the current version of the image. See Stage Desktop Images for details about activating staged desktop images.

      • Activate staged image after: Select this option to automatically activate the image a number of days after staging. Any linked pools will have their associated image updated.

      • Current image action: Select one of the following:

        • Keep current version as backup: This option retains the current image version as a standalone object. This image version is not visible or manageable via Nerdio Manager, so be sure to delete it manually when no longer needed to avoid unnecessary Azure storage costs. You can still use prior versions of Azure Compute Gallery images in the Desktop image (template) menu, under Unmanaged ACG image versions.

        • Remove current version after activation: This option removes the current image version automatically after activation.

    • Replica Count (Per Region): Specify the number of replicas per region.

      Note

      • Azure Compute Gallery replicas support a maximum of 20 concurrent clone operations per replica.

      • Ensure that the number of replicas specified meets your deployment requirements. Up to 100 replicas per region are supported.

      • Replicas can only be deployed within the same subscription.

    • Backup Version Limit: Specify the maximum number of backup image versions that can be retained.

      Note

      When a new image version is created, and the old one is saved as a backup, the system automatically manages and limits the number of these backups according to the specified limit. If the limit is reached, the oldest versions are deleted. You can configure this setting in the desktop image settings, Manage versions option.

    • Save current image as a backup: Select this image to retain the existing image as a standalone object and not overwrite it with the new one.

      Note

      • This image is not visible or manageable via Nerdio Manager, so be sure to delete it manually when it is no longer needed to avoid unnecessary Azure storage costs.

      • If the current image is stored in Azure Compute Gallery, it is retained with an older version number. If the image is not stored in Azure Compute Gallery, you can find it in the Azure portal > Images. In Nerdio Manager's image selector lists, it is listed under Custom images.

    • Install App Attach certificates: Select this option to install all stored certificates on the image VM, if any.

    • Enable App-V client service: Select this option if the VM will use App Attach packages that contain App-V packages.

    • Skip removal of local profiles: Select this option to bypass removing all local user profiles.

      Note

      During the image creation process, Nerdio Manager removes all local user profiles. This increases the likelihood of Sysprep success. Selecting this option bypasses this step. If there are any partially installed APPX apps on the image VM, Sysprep does to remove them.

    • Enable for Cloud PCs: Select this option to make this image available in Windows 365 Cloud PC service.

      Note

      The image will be uploaded and tested for compatibility with Cloud PCs. This process can take a long time. There is a limit of 20 images that can be uploaded to Windows 365.

    • Leave desktop image VM running: Select this option to leave the VM running after the Set as image task completes.

      Note

      This is useful if you want to push OS and application updates to the running VM.

    • Change log: Type the list of changes made to the image.

    • Apply tags: Optionally, enter the Name and Value of the Azure tag.

      Note

      You can specify multiple tags. The specified tags are applied to image VM, OS disk, network interface, image object, and Azure Compute Gallery image. For details about using tags to organize your Azure resources, see Use tags to organize your Azure resources and management hierarchy.

  5. Once you have entered all the desired information, select Run now (not scheduled) or Save & close (scheduled).

    You can see the job's progress in the logs. For details about the logs, see Desktop Images Change Log Feature.

Desktop Images Scripted Actions

Nerdio Manager enables you to execute scripts on desktop images.

Note

You can execute a scripted action immediately or run it on a schedule.

To execute a scripted action:
  1. From the main menu, select Desktop Images.

  2. From the action menu, select Run script.

  3. Enter the following information:

    • Schedule: Toggle to turn the scheduler On/Off. See Manage Schedules for Tasks for details about creating a schedule.

    • Scripted Actions: From the drop-down list, select the script you wish to run.

      Note

      • Windows scripts are executed via the Azure Custom Script extension and run in the context of the LocalSystem account.

      • Azure runbooks are executed via the Azure automation account and run in the context of the Nerdio Manager app service principal.

      • The following variables are passed to the script and can be used in the PowerShell commands:

        • $AzureSubscriptionId

        • $AzureSubscriptionName

        • $AzureResourceGroupName

        • $AzureRegionName

        • $AzureVMName

        • $ADUsername (if passing AD credentials)

        • $ADPassword (if passing AD credentials)

        • $SATrigger = "RunOnce"

        • $SATriggerMode = "Manual" | "Schedule"

        • $DesktopImageVmName

        • $DesktopImageActiveVersion

        • $DesktopImageStagedVersion

    • Scripted actions input parameters: If necessary, provide the required parameters.

    • Pass AD credentials: Select to pass your AD credentials to the script being executed.

    • Restart VM after script execution: Select to restart the VM after script execution.

      Note

      It is preferable to select this option instead of restarting the VM in your PowerShell commands because the Custom Script extension fails if the script restarts the VM.

  4. Once you have entered all the desired information, select either Run now to execute immediately or Save & close to save the script and execute as per the schedule.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.