Owners and admins

Policies

Require MFA for operators and set ticket references to off, optional, or required before session actions.

MFA policy

Owners and admins must use authenticator MFA. The organisation MFA policy extends that requirement to help desk, session admins, and viewers.

Turn this on before inviting a large help-desk group or before enabling SCIM for broad access. Users who have not enrolled MFA are sent to Settings after sign-in and cannot use the console until enrolment is complete.

  1. 1
    Open Settings

    Go to Settings -> Organisation policies. Owners and admins can also set the same policy in the setup wizard.

  2. 2
    Enable MFA for everyone

    Turn on Require MFA for help desk, session admins, and viewers, then save.

  3. 3
    Check break-glass access

    Make sure at least one owner has enrolled MFA and saved backup codes before requiring it for the wider team.

Ticket references

Ticket references can be off, optional, or required on Disconnect, Message, and Log off. When off, the field is hidden. Optional shows the field without blocking the action. Required blocks the action until a ticket is entered. The value is written to Activity with the session action so another admin can see why it happened.

Allowed prefixes are optional. Leave the list empty to accept any value, or add prefixes such as INC, SR-, or CHG when your service desk has fixed ticket formats.

When tickets are optional or required, you can also send an email after an action that includes a ticket. Add recipients and write the subject and body yourself. Placeholders such as {{ticketReference}}, {{user}}, {{hostPool}}, and {{action}} are replaced with the session and ticket details.

A bulk disconnect or log off sends one email for the whole action. {{user}} and {{sessionHost}} list every session affected and {{sessionCount}} gives the total. Placeholders that describe one session, such as {{state}} and {{startedAt}}, are left blank for bulk actions.

  1. 1
    Choose a mode

    Settings -> Organisation policies -> Ticket references. Pick Off, Optional, or Required.

  2. 2
    Add prefixes

    Enter one prefix per line or comma-separated. AvdControl accepts a ticket when it starts with one of those prefixes.

  3. 3
    Optional email

    Turn on ticket emails, add recipients, and edit the subject and body. Click a placeholder to insert it.

  4. 4
    Test an action

    Open Sessions and try a low-risk Message action. The dialog should match the mode you saved.

How policies affect operators

Policies do not change Azure permissions. They only control AvdControl portal access and the checks AvdControl performs before it sends an allowed session action to Azure.

If an operator reports being blocked, check their MFA enrolment, their role, their host-pool scope, and whether the ticket prefix they entered matches the policy. Activity will show successful session actions, including the ticket reference.