Windows 365 Boot Dedicated – Local access for admin accounts without a Cloud PC

Vottero Carlotta 0 Punti di reputazione
2026-07-28T10:40:47.3266667+00:00

We have a device configured with Windows 365 Boot Dedicated. Users can sign in directly to their Cloud PC.

In Intune, we have also enabled the Return to Physical Device option. The goal is to allow only selected admin accounts to access the local Windows system.

These admin accounts will not have a Windows 365 Boot Dedicated device or a Cloud PC assigned. They only need to access the local device in case of technical problems.

The admin accounts:

  • are present in Microsoft Entra ID;
  • are members of the group used for the policy;
  • seem to receive the policy correctly;
  • do not have a Cloud PC or VDI assigned.

Even with this configuration, the following problem happens.

A user with a Cloud PC signs in through Windows 365 Boot.

Then, from the error screen or by using Ctrl+Alt+Del, the user selects Return to Physical Device.

On the local Windows sign-in screen, we enter the credentials of an admin account that does not have a Cloud PC.

However, the device still tries to start a Windows 365 session for this account. Because the account does not have a Cloud PC, the sign-in fails. The admin account cannot access the local Windows system.

If we use an account that has a Cloud PC, local access works correctly.

We would like to confirm the following points.

1. Local access without a Cloud PC

Can an admin account without a Cloud PC access the local Windows system after selecting Return to Physical Device?

Or does this option work only for accounts that already have a Cloud PC?

2. Expected behavior or configuration problem

Is it normal that the device tries to start a Cloud PC session for an account that should only access the local device?

Is this a limitation of Windows 365 Boot, or could there be a problem with the Intune policy?

Do admin accounts without a Cloud PC need:

  • Microsoft Entra ID P1;
  • Microsoft Intune Plan 1;
  • or both licenses?

Our goal is to allow local Windows access only to selected admin accounts, without assigning a Cloud PC to them.

Could you please confirm whether this configuration is supported and provide the correct setup and licensing requirements?We have a device configured with Windows 365 Boot Dedicated. Users can sign in directly to their Cloud PC.

In Intune, we have also enabled the Return to Physical Device option. The goal is to allow only selected admin accounts to access the local Windows system.

These admin accounts will not have a Windows 365 Boot Dedicated device or a Cloud PC assigned. They only need to access the local device in case of technical problems.

The admin accounts:

  • are present in Microsoft Entra ID;
  • are members of the group used for the policy;
  • seem to receive the policy correctly;
  • do not have a Cloud PC or VDI assigned.

Even with this configuration, the following problem happens.

A user with a Cloud PC signs in through Windows 365 Boot.

Then, from the error screen or by using Ctrl+Alt+Del, the user selects Return to Physical Device.

On the local Windows sign-in screen, we enter the credentials of an admin account that does not have a Cloud PC.

However, the device still tries to start a Windows 365 session for this account. Because the account does not have a Cloud PC, the sign-in fails. The admin account cannot access the local Windows system.

If we use an account that has a Cloud PC, local access works correctly.

We would like to confirm the following points.

1. Local access without a Cloud PC

Can an admin account without a Cloud PC access the local Windows system after selecting Return to Physical Device?

Or does this option work only for accounts that already have a Cloud PC?

2. Expected behavior or configuration problem

Is it normal that the device tries to start a Cloud PC session for an account that should only access the local device?

Is this a limitation of Windows 365 Boot, or could there be a problem with the Intune policy?

Do admin accounts without a Cloud PC need:

  • Microsoft Entra ID P1;
  • Microsoft Intune Plan 1;
  • or both licenses?

Our goal is to allow local Windows access only to selected admin accounts, without assigning a Cloud PC to them.

Could you please confirm whether this configuration is supported and provide the correct setup and licensing requirements?

Windows per il lavoro | Windows 365 Enterprise
0 commenti Nessun commento

1 risposta

Ordina per: Più utili
  1. Daphne Huynh (WICLOUD CORPORATION) 1,570 Punti di reputazione Personale Esterno Microsoft Moderatore
    2026-07-28T12:08:33.65+00:00

    Benvenuto nel forum Microsoft Q&A!

    Grazie per aver fornito informazioni così dettagliate.

    In base al comportamento che hai descritto e alla documentazione Microsoft attualmente disponibile, ciò che stai osservando è molto probabilmente il comportamento previsto di Windows 365 Boot Dedicated.

    1. Un account amministratore senza Cloud PC può accedere al dispositivo Windows locale?

    La funzionalità Return to physical device consente agli utenti selezionati di tornare alla schermata di accesso del dispositivo fisico da:

    • La schermata Ctrl+Alt+Canc
    • Le schermate di errore di Windows 365

    Dopo aver selezionato questa opzione, l'utente viene reindirizzato alla schermata di accesso di Windows locale.

    Tuttavia, Windows 365 Boot è progettato principalmente per consentire agli utenti di accedere direttamente al proprio Cloud PC piuttosto che al dispositivo fisico. Microsoft afferma che i dispositivi fisici configurati con Windows 365 Boot sono destinati a consentire agli utenti di interagire con il proprio Cloud PC senza interagire con il dispositivo fisico stesso e che l'obiettivo principale è impedire agli utenti di accedere al PC fisico.

    Attualmente, non esiste alcuna documentazione Microsoft che confermi esplicitamente il supporto all'utilizzo di un account Microsoft Entra ID senza un Cloud PC assegnato come account amministratore esclusivamente locale su un dispositivo Windows 365 Boot Dedicated.

    2. Perché il dispositivo continua comunque a tentare di avviare una sessione Cloud PC?

    Questo comportamento suggerisce che l'autenticazione venga ancora gestita attraverso l'esperienza di accesso di Windows 365 Boot. Il flusso di lavoro di Windows 365 Boot è il seguente:

    L'utente accede → Windows 365 Boot connette direttamente l'utente al Cloud PC assegnato.

    Se all'account non è assegnato alcun Cloud PC, Windows 365 Boot potrebbe comunque tentare di individuare un Cloud PC associato a tale identità. Poiché non ne esiste alcuno, l'accesso non riesce.

    Questo comportamento sembra essere maggiormente coerente con il modello di progettazione di Windows 365 Boot piuttosto che con un'errata configurazione dei criteri Intune.

    3. Sono necessarie licenze aggiuntive per questi account amministratore?

    • Windows 365 Boot è destinato agli utenti che dispongono di una licenza Windows 365 e di un Cloud PC assegnato.
    • L'impostazione Return to physical device viene distribuita tramite un profilo di configurazione Intune assegnato a gruppi di utenti Microsoft Entra.

    Tuttavia, non esiste alcuna documentazione che indichi che un account amministratore esclusivamente locale debba necessariamente disporre di:

    • Microsoft Entra ID P1
    • Microsoft Intune Plan 1
    • Oppure entrambi

    al solo scopo di utilizzare la funzionalità Return to physical device.

    Considerata l'assenza di indicazioni esplicite per questo scenario, consiglio di aprire un caso di supporto Microsoft tramite uno dei seguenti canali per verificare se l'accesso amministrativo esclusivamente locale senza assegnazione di un Cloud PC sia uno scenario supportato per Windows 365 Boot Dedicated, oppure se attualmente sia richiesto un Cloud PC assegnato per qualsiasi account Microsoft Entra che debba autenticarsi sul dispositivo.

    Vai a Tenant administration → Help and support → New support request.

    Vai a Support → Help & support → New service request.

    Per ulteriori informazioni, visita:

    Che cos'è Windows 365 Boot? | Microsoft Learn

    Risolvere i problemi di avvio di Windows 365 - Windows 365 | Microsoft Learn

    Scenario guidato di avvio di Windows 365 | Microsoft Learn

    Esplorare Windows 365 avvio - Training | Microsoft Learn

    La risposta è stata utile?

    0 commenti Nessun commento

Risposta

Le risposte possono essere contrassegnate come "Accettata" dall'autore della domanda e "Consigliata" dai moderatori, in modo da consentire agli utenti di sapere che la risposta ha risolto il problema dell'autore.