What this connection does
The Azure connection lets AvdControl discover AVD host pools, collect session state, and send supported session actions to Azure. It is separate from Entra SSO and SCIM. Do not reuse the SSO app registration unless you deliberately want the same lifecycle and owners.
Create the app registration in the same Entra tenant that owns the Azure subscription or can access it. AvdControl stores the client secret only after Microsoft validation succeeds.
Create the Entra app
In Entra admin center, create an app registration for AvdControl Azure collection. Copy the Directory (tenant) ID and Application (client) ID, then create a client secret and copy the secret value.
In Azure, grant the app Desktop Virtualization Reader and Desktop Virtualization Contributor on the subscription or resource group that contains the host pools. Use the narrowest scope that still covers every pool you want AvdControl to manage.
- 1
Register the appEntra admin center -> App registrations -> New registration. A single-tenant app is usually enough.
- 2
Create the secretCertificates & secrets -> New client secret. Copy the Value immediately; the Secret ID is not accepted by AvdControl.
- 3
Assign Azure rolesAzure subscription or resource group -> Access control (IAM) -> Add role assignment. Add Desktop Virtualization Reader and Desktop Virtualization Contributor for the app.
- 4
Optional name lookupGrant Graph Directory.Read.All only if you want Entra names to resolve from directory data. AVD collection works without it.
- 5
Validate in AvdControlSetup -> Connect Azure. Paste tenant ID, client ID, and secret, then Validate and save.
Discovery and host pools
After validation, AvdControl lists subscriptions and discovers host pools. Discovery can take a short while; a pending status means the background refresh is still running.
If no pools appear, check the app has roles on the subscription that actually contains the AVD resources, not only on a management subscription. If validation passes but action buttons fail later, confirm the Contributor role is present as well as Reader.
Troubleshooting validation
Invalid tenant, client, or secret usually means one of the three copied values is from the wrong place. The secret value is only visible when you create it; copying the secret ID will fail.
Permission errors usually mean the app registration exists but the Azure role assignment is missing, assigned at the wrong scope, or has not propagated yet. Wait a few minutes after adding roles, then retry discovery.
Edit, rotate, or remove
Use Edit on the Connect Azure step to rename a connection, change IDs, or rotate the secret. Leave the secret blank only when you want to keep the saved one.
Refresh from Azure reruns discovery without changing credentials. Remove connection deletes the connection, discovered host pools, and cached session data from AvdControl. It does not delete Azure resources or sign users out.