|
1 | 1 | ---
|
2 |
| -title: Microsoft Purview forensic evidence for Azure Virtual Desktop |
3 |
| -description: Learn about Microsoft Purview forensic evidence for Azure Virtual Desktop. |
| 2 | +title: Onboard Azure Virtual Desktop session hosts to forensic evidence from Microsoft Purview Insider Risk Management |
| 3 | +description: Learn how to onboard Azure Virtual Desktop session hosts to forensic evidence. When using Azure Virtual Desktop with forensic evidence, you can set policies to trigger recordings of desktop and RemoteApp sessions automatically. |
4 | 4 | ms.topic: how-to
|
5 | 5 | author: sipastak
|
6 | 6 | ms.author: sipastak
|
7 |
| -ms.date: 07/09/2024 |
| 7 | +ms.date: 08/13/2024 |
8 | 8 | ---
|
9 | 9 |
|
10 |
| -# Microsoft Purview forensic evidence for Azure Virtual Desktop |
| 10 | +# Onboard Azure Virtual Desktop session hosts to forensic evidence from Microsoft Purview Insider Risk Management |
11 | 11 |
|
12 | 12 | [Forensic evidence](/purview/insider-risk-management-forensic-evidence) is an opt-in add-on feature in Microsoft Purview Insider Risk Management that gives security teams visual insights into potential insider data security incidents. Forensic evidence includes customizable event triggers and built-in user privacy protection controls, enabling security teams to better investigate, understand and respond to potential insider data risks like unauthorized data exfiltration of sensitive data.
|
13 | 13 |
|
14 | 14 | You set the right policies for your organization, including what risky events are the highest priority for capturing forensic evidence, what data is most sensitive, and whether users are notified when forensic capturing is activated.
|
15 | 15 |
|
16 |
| -When using forensic evidence for Azure Virtual Desktop, you can set policies to trigger recordings of application and desktop sessions automatically. Forensic evidence capturing is off by default and policy creation requires dual authorization. |
| 16 | +When using Azure Virtual Desktop with forensic evidence, you can set policies to trigger recordings of desktop and RemoteApp sessions automatically. Forensic evidence capturing is off by default and policy creation requires dual authorization. |
17 | 17 |
|
18 | 18 | ## Prerequisites
|
19 | 19 |
|
20 | 20 | Before you can use forensic evidence for Azure Virtual Desktop, you need:
|
21 | 21 |
|
22 |
| -- A personal desktop host pool with direct assignment. |
| 22 | +- A personal desktop host pool with direct assignment. Pooled host pools aren't supported. |
23 | 23 |
|
24 |
| -- Session hosts running Windows 11, version 23H2, and using a VM SKU with minimum 8 vCPU and 16 GB of RAM such as [Standard D8as v5](../virtual-machines/dasv5-dadsv5-series.md). |
| 24 | +- Session hosts running Windows 11 Enterprise, version 23H2, and using a VM SKU with minimum of 8 vCPU and 16 GB memory, such as [Standard D8as v5](../virtual-machines/dasv5-dadsv5-series.md). |
25 | 25 |
|
26 |
| -- Session hosts must be Microsoft [Entra ID-joined](/entra/identity/devices/concept-directory-join) or [Entra ID hybrid-joined](/entra/identity/devices/concept-hybrid-join) and enrolled with Intune. |
| 26 | +- Session hosts must be Microsoft [Entra ID-joined](/entra/identity/devices/concept-directory-join) or [Entra ID hybrid-joined](/entra/identity/devices/concept-hybrid-join) and enrolled with Microsoft Intune. |
27 | 27 |
|
28 | 28 | - Microsoft 365 E5 license, which contains both Intune and Insider Risk Management licenses.
|
29 | 29 |
|
30 |
| -## Configure forensic evidence |
| 30 | +## Onboard session hosts to forensic evidence |
31 | 31 |
|
32 |
| -To configure forensic evidence for Azure Virtual Desktop: |
| 32 | +To onboard your session hosts to forensic evidence: |
33 | 33 |
|
34 |
| -1. Ensure a user is assigned to a personal desktop using direct assignment. For more information, see [Configure direct assignment](configure-host-pool-personal-desktop-assignment-type.md#configure-direct-assignment). |
| 34 | +1. Ensure a user is assigned to a personal desktop using direct assignment. Follow the steps in [Configure direct assignment](configure-host-pool-personal-desktop-assignment-type.md#configure-direct-assignment) to assign a user to a personal desktop. |
35 | 35 |
|
36 | 36 | 1. You need to onboard your session hosts to Purview. Follow the steps in [Onboard Windows devices into Microsoft Purview](/purview/device-onboarding-overview) to onboard your session hosts.
|
37 | 37 |
|
38 |
| -1. To install the Purview client and configure forensic evidence, follow the steps in [Get started with insider risk management forensic evidence](/purview/insider-risk-management-forensic-evidence-configure?tabs=purview-portal) . |
| 38 | +1. Install the Purview client and configure forensic evidence. Follow the steps in [Get started with insider risk management forensic evidence](/purview/insider-risk-management-forensic-evidence-configure) to install the Purview client and configure forensic evidence. |
39 | 39 |
|
40 | 40 | ## Related content
|
41 | 41 |
|
42 |
| -- [Manage insider risk management forensic evidence](/purview/insider-risk-management-forensic-evidence-manage?tabs=purview-portal) |
| 42 | +- [Manage insider risk management forensic evidence](/purview/insider-risk-management-forensic-evidence-manage) |
0 commit comments