MFA policy
Owners and admins must use authenticator MFA. The organisation MFA policy extends that requirement to help desk, session admins, and viewers.
Turn this on before inviting a large help-desk group or before enabling SCIM for broad access. Users who have not enrolled MFA are sent to Settings after sign-in and cannot use the console until enrolment is complete.
- 1
Open SettingsGo to Settings -> Organisation policies. Owners and admins can also set the same policy in the setup wizard.
- 2
Enable MFA for everyoneTurn on Require MFA for help desk, session admins, and viewers, then save.
- 3
Check break-glass accessMake sure at least one owner has enrolled MFA and saved backup codes before requiring it for the wider team.
Ticket references
Ticket references can be off, optional, or required on Disconnect, Message, and Log off. When off, the field is hidden. Optional shows the field without blocking the action. Required blocks the action until a ticket is entered. The value is written to Activity with the session action so another admin can see why it happened.
Allowed prefixes are optional. Leave the list empty to accept any value, or add prefixes such as INC, SR-, or CHG when your service desk has fixed ticket formats.
When tickets are optional or required, you can also send an email after an action that includes a ticket. Add recipients and write the subject and body yourself. Placeholders such as {{ticketReference}}, {{user}}, {{hostPool}}, and {{action}} are replaced with the session and ticket details.
A bulk disconnect or log off sends one email for the whole action. {{user}} and {{sessionHost}} list every session affected and {{sessionCount}} gives the total. Placeholders that describe one session, such as {{state}} and {{startedAt}}, are left blank for bulk actions.
- 1
Choose a modeSettings -> Organisation policies -> Ticket references. Pick Off, Optional, or Required.
- 2
Add prefixesEnter one prefix per line or comma-separated. AvdControl accepts a ticket when it starts with one of those prefixes.
- 3
Optional emailTurn on ticket emails, add recipients, and edit the subject and body. Click a placeholder to insert it.
- 4
Test an actionOpen Sessions and try a low-risk Message action. The dialog should match the mode you saved.
How policies affect operators
Policies do not change Azure permissions. They only control AvdControl portal access and the checks AvdControl performs before it sends an allowed session action to Azure.
If an operator reports being blocked, check their MFA enrolment, their role, their host-pool scope, and whether the ticket prefix they entered matches the policy. Activity will show successful session actions, including the ticket reference.