Session time limit for Windows 365 Frontline

In the previous post in the blog, Dominiek showcased how you setup Windows 365 Frontline which is a great license model if you e.g. use Windows 365 Cloud PCs for your shift workers. However, we need to add some additional layers of configuration to make operations as smooth as possible, and especially to make sure that we use the licenses in the best way possible.

With Windows 365 Frontline, each license is reserved as long as the user has the session running. This means that users could potentially have active sessions but are idle which would result in them locking one license.

 
Since users might forget to end the session, you can configure a policy that will end idle sessions for the end-user.

Create the policy

To create the policy, head over to Intune (https://intune.microsoft.com) and navigate to Devices > Windows > Configuration profiles and select “+ Create profile“.

Select the profile type to be Settings catalog and press Create.

Give your profile a name that makes sense to you and your organisation, I will go with something that follow my name standard for my environment that indicates it’s for Windows 365 Frontline and what the profiles does. When you have given the profile a name, press Next.

Select “+ Add setting” to open the settings picker.

In the settings picker, search for session time limits and select the category for Session Time Limits.

In the settings name section, check the box for “End session when time limits are reached and “Set time limit for active but idle Remote Desktop Services sessions“, and your setting will appear in the policy. Once you have selected the setting name, close the fly-out settings picker.

Enable the settings and choose the time limit that matches your needs and corporate policies. In this example I’ve selected 1 hour, which is good value to start with. Once you have enabled these settings, press Next.

Unless you use Scope tags you can skip this section and move right to Assignments where we will deploy this towards all our Windows 365 Frontline devices. I’m doing this by assigning the policy to the built in All devices group and applying a filter I’ve created for Windows 365 Frontline.

The rule syntax you want to use when creating a filter for Windows 365 Frontline machines is at least this one, but it can of course have additional lines depending on your needs:

(device. Model -startsWith "Cloud PC Frontline")

Once you have made the assignments as needed, press Next and then Create.

Your policy will now assigned to all your Windows 365 Frontline Cloud PCs and you can track the progress in Intune by looking at the policy.

Conclusion

There are a lot of great things you can use to control your Cloud PC sessions, to make sure that your user has as great of an experience as possible, but still giving you as an admin all the controls.

Controlling the session time will make it easier to control how the licenses are consumed and you don’t need to worry as much about licenses being locked up on idle Cloud PC sessions. 

Licenses are of course released automatically once the session is closed even without these settings, but this gives you the control of how long that time should be before the user gets kicked out, and the time suggested in the post is of course only an example of the timing you can use. This is totally up to your needs in your environment!

 

I hope you enjoyed the post!

Author

  • Ola Ström

    Ola Ström is a Microsoft MVP for Windows 365 from Sweden and he is one of the first expert contributors in this community. Make sure to follow him as he guides us in the world of Windows 365 and Microsoft Intune!

    View all posts

Leave a Reply

Your email address will not be published. Required fields are marked *