Product
From connect to a cleared session
You connect an Entra app you own, pick host pools, then give help desk or the business a role on only those pools. They act in the console. They do not open the Azure Portal. They do not log a ticket.
1 · Connect Azure
Check the app before anything is stored
Create an Entra app, grant Desktop Virtualization roles, and paste the IDs. We list subscriptions first. The client secret is encrypted only after that check. You can rotate it later. We never show it again.
2 · Pick host pools
Choose what each person can see
We list the pools on the connection. You include teaching or exams and leave research or finance out. Scope can be a single pool, a resource group, a subscription, or the whole connection.
3 · Delegate
Help desk, or the people who run the pool
Invite anyone. Give them a role on only their pools. A faculty owner or a department lead can disconnect or message on their estate. They do not wait on IT. They do not get an Azure role.
4 · Act and audit
Clear a session, then see who did it
Active, idle, and disconnected in one table. Disconnect and message sit on help desk. Log off needs session admin. Confirm before log off. The audit row records the actor, the user, and the pool.
Roles
You can give any of these to any person, then tighten it to a pool.
| Role | What they can do |
|---|---|
| Viewer | See sessions and host pools in scope. |
| Help desk | Disconnect, send messages, and view Activity. Cannot log people off. |
| Session admin | Same as help desk, plus they can log users off. |
| Admin | Day-to-day config and invites. Not SSO or SCIM. |
| Tenant owner | Billing, SSO, SCIM, Azure connect, and the rest. |