Skip to content
Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users

Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users

Written By Anoop C Nair
Last Updated August 3, 2023
Posted In Windows 365
SHARE

Let’s quickly check Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users. Microsoft released new settings with Windows 365 July 2023 update that end users can reset their Cloud PC devices themselves.

Let’s have a quick look at the option to provide admin access to Windows 365 Cloud PC using Intune user settings policy. Windows 365 service delivers personalized desktops in the cloud. Microsoft announced the general availability of Windows 365 on the 2nd of August 2021.

You can use the user settings policy to add assigned users to the local administrator on all their cloud PCs. The admin access might be required to support some of the developer use case scenarios. If you have a use case to add a generic admin account to Cloud PCs, you can deploy PowerShell scripts using Intune.

Now you can grant end-users permission to reset (reprovision) their own Cloud PC. This would eliminate a lot of headaches for IT admins and the helpdesk.

Patch My PC

Deploy User Settings Policy to Windows 365 Cloud PC

You can deploy the user settings policy to Windows 365 cloud PC. Let’s have a quick walkthrough of this policy to add users to the local administrator group on their Cloud PCs.

  • Log in to the Microsoft Intune portal.
  • Navigate to Devices -> Windows 365 node.
  • Click on +Add button to create user settings policy.
Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users Fig. 1
Windows 365 Cloud PC User Settings Policy to Provide Admin and Reset Permissions to End Users Fig. 1

Enabling this settings, policy elevates end users to a local administrators on all their cloud PCs. On the settings page, you have two options.

  • Enter the Name of the User Settings Policy.
  • Select the option to enable or disable local admin policy.
    • On option is selected.
  • Click on Next button to continue.
Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users Fig. 2
Windows 365 Cloud PC User Settings Policy to Provide Admin and Reset Permissions to End Users Fig. 2

I have added the W365 Users Azure AD group, where I have two users as members. I used the same group during the Windows 365 provisioning guide. You can click on the Next button to continue to the validation and confirmation page.

Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users Fig. 3
Windows 365 Cloud PC User Settings Policy to Provide Admin and Reset Permissions to End Users Fig. 3

As you can see in the below screenshot, the validation is passed for the user settings policy. Click on Create button to complete the user settings creation process from Intune MEM portal.

Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users Fig. 4
Windows 365 Cloud PC User Settings Policy to Provide Admin and Reset Permissions to End Users Fig. 4

Reset (reprovision) their own Cloud PC Permissions to End users

Empowering the Power Users with this feature! This is very promising for Power Users like developers or the Application Packaging Teams. They have the requirements such as resetting the Cloud PCs twice or 3 times a day.

Windows 365 2307 New Features and Updates Fig.2
Windows 365 2307 New Features and Updates Fig.2

Results

The following is the screenshot from a Cloud PC before applying the user settings policy to add assigned users to the local administrative group on their Cloud PCs. So, you can’t see any user added to the local administrator’s group.

Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users Fig. 5
Windows 365 Cloud PC User Settings Policy to Provide Admin and Reset Permissions to End Users Fig. 5

After applying the user settings policy, you can see that MEMCM/anoopb user is added to the local administrator’s group. This user got admin access on the assigned Cloud PC. The policy to elevate admin permissions for an assigned user on the respective Cloud PC is useful.

Windows 365 Cloud PC User Settings Policy to provide Admin and Reset Permissions to End Users Fig. 6
Windows 365 Cloud PC User Settings Policy to Provide Admin and Reset Permissions to End Users Fig. 6

Further Clarifications

W365 Users – Every user in that group with a Cloud PC license assigned will receive a Cloud PC provisioned based on the image and on-premises network connection configuration.

This group(W365 Users) is not with local admin users. In this post, I was trying to explain the scenario Cloud PC assigned user will get administrator access on that CLoud PC (Windows 365).

This is the idea behind the User Settings Policy workflow. This is why you see Anoopb added to the local admin group.

The other workflow to achieve what you want to do add admin groups into local admin is to Manage Local Admins Using Intune Local User Group Membership Management Policy

Resources

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 3 comments

  1. StaffW365 Users – Every user in that group with a Cloud PC license assigned will receive a Cloud PC provisioned based on the image and on-premises network connection configuration.

    This group(W365 Users) is not with local admin users. In this post, I was trying to explain the scenario Cloud PC assigned user will get administrator access on that CLoud PC (Windows 365).

    This is the idea behind the User Settings Policy workflow. This is why you see Anoopb added to the local admin group.

    The other workflow to achieve what you want to do is https://www.anoopcnair.com/manage-local-admins-using-intune-group-mgmt/

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Add Windows 365 Cloud Apps from File Path using Microsoft Intune

Key Takeaways In this article, I’ll explain how to add Windows 365 Apps from a file path using Microsoft Intune. Windows 365 admins can now manually add Cloud Apps by specifying an application’s executable file path. This Public Preview feature allows admins to publish apps that don’t appear in the Start Menu, giving them greater […]

VK Vaishnav K 6 min read
Microsoft 365

Purchase Windows 365 Flex High Performance Cloud PC Free Trial License

Key Takeaways In this article, I will explain how to purchase a Windows 365 Flex High Performance Cloud PC Free Trial License. Microsoft now offers a Windows 365 Flex 32 vCPU, 128 GB RAM, 2 TB Storage Cloud PCs free trial, giving organisations an excellent opportunity to evaluate one of the most powerful Cloud PC […]

VK Vaishnav K 6 min read
Intune

Publish Microsoft Teams Windows 365 Cloud App using Intune

Key Takeaways In this article, I’ll explain how to publish the Microsoft Teams Windows 365 Cloud App using Intune. Microsoft has enhanced Windows 365 Cloud Apps with support for .appx and .msix packaged applications. This means admins can now discover and publish apps like Microsoft Teams and the new Outlook directly through the existing Cloud […]

VK Vaishnav K 7 min read
Intune

Best way to Uninstall 3rd-Party Dev Tools from Windows 11 Dev Cloud PC using Intune

Key Takeways In this article, I’ll walk you through how to uninstall the 3rd-party Dev tools from Windows 11 Dev Cloud PC using the Microsoft Intune PowerShell Script. If you no longer require the preinstalled third-party developer tools included in the Windows 11 Developer Configuration image, Microsoft provides an uninstall script to remove them. This […]

VK Vaishnav K 16 min read