Owners and admins

Set up the organisation

Work through the eight-step wizard: organisation, Azure, host pools, team, optional SSO, policies, then go live.

What you need first

Create a dedicated Entra app registration for Azure collection. Grant Desktop Virtualization Reader and Desktop Virtualization Contributor on the Azure subscription that holds your host pools. Directory.Read.All is optional and only used for name lookups.

If you want Entra SSO or SCIM, prepare those separately before the Access step. SSO needs an OIDC app registration with a web redirect URI. SCIM needs a provisioning endpoint and bearer token, then group mappings in Settings after the first sync.

Nothing is live for operators until you finish Go live. You can change pools, team, and policies later.

  1. 1
    Welcome

    Read the checklist. Owners and admins already need authenticator MFA.

  2. 2
    Organisation

    Confirm the name people see in the portal and emails, and pick a timezone for timestamps.

  3. 3
    Connect Azure

    Paste tenant ID, application ID, and client secret for the Azure collection app. The wizard validates Microsoft login, lists subscriptions, and discovers host pools before the secret is stored. Use the Azure connection guide if validation fails.

  4. 4
    Host pools

    Tick the pools that should appear in the console. Unchecked pools are ignored: sessions are not collected, and operators cannot act on them through AvdControl.

  5. 5
    Team

    Invite at least one colleague for day-one access, or skip if you will use SCIM. Manual invites get organisation-wide access during setup; narrow them to specific pools later from Team.

  6. 6
    SSO and SCIM

    Configure Entra sign-in, mint a SCIM token, or skip until later. Use the SSO and SCIM guide for redirect URI, token, provisioning, and group-mapping steps.

  7. 7
    Policies

    Decide whether every operator needs app MFA and whether ticket references are off, optional, or required on disconnect, message, and log off. Add prefixes only if your ticketing system has a fixed format.

  8. 8
    Go live

    Mark the console live when operators should use the dashboard. This unlocks normal console use but does not notify AVD end users or change Azure host pools.

Setup wizard on the Connect Azure step with tenant ID, application ID, and client secret fields after a successful check
The wizard checks the app and lists subscriptions before the client secret is stored.

Azure app registration checklist

In Entra, create an app registration used only for AvdControl Azure collection. Add a client secret, copy the Tenant ID, Application (client) ID, and the secret value, then grant the Azure subscription roles on the subscription or resource group that contains the host pools.

Use the least scope that still covers the host pools you plan to manage. If discovery succeeds but no pools appear, check the subscription scope and whether Azure Virtual Desktop resources live in another subscription.

Secrets

The client secret is encrypted only after the subscription check succeeds. After save, the console never shows it again. Edit the connection on Connect Azure to rotate the secret or change the app IDs; you cannot read the old value back. Removing a connection deletes its host pools and session data from the console, not from Azure.

Before you go live

Confirm at least one host pool is managed, at least one non-owner can sign in, and a safe operator role has been tested against a real session. If you are using SCIM, check group mappings before Go live so provisioned users do not arrive with no usable access.

Go live changes AvdControl's setup state. It does not email operators, change AVD assignments, or alter the host pools in Azure.