October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Azure Monitor

Windows 365 August 2024 Update: Azure Monitor Agent and Remote Session Lock

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s Windows 365 service release 2408, announced for the week of August 26, 2024, introduced two separate changes: Azure Monitor Agent (AMA) support for Windows 365 Enterprise and Government Cloud PCs, and configurable remote-session lock behavior when Microsoft Entra single sign-on (SSO) is enabled. AMA gives administrators a way to collect selected Cloud PC operating-system telemetry; it does not monitor everything automatically. The lock setting lets administrators choose whether locking a remote session disconnects it or displays the remote lock screen.

The release note confirms the capabilities, while Microsoft’s configuration guidance supplies the lock-policy details. Because that guidance is shared with Azure Virtual Desktop, apply it to Windows 365 through the Cloud PC device-management policy—not by treating a Cloud PC as an Azure Virtual Desktop host-pool session host.

What changed in Windows 365 service release 2408?

Microsoft listed both changes in the week of August 26, 2024, under service release 2408. The announcement says AMA can be installed on Windows 365 Enterprise and Windows 365 Government Cloud PCs, and administrators can configure remote-session locking when Microsoft Entra SSO is enabled. These are distinct capabilities: one concerns guest operating-system monitoring, the other authentication behavior after a session is locked.

The date identifies when Microsoft announced the release; it does not mean every tenant received the changes at precisely the same time. The release note establishes availability, but it is not a complete deployment guide for AMA. Microsoft’s Windows 365 release notes

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Azure Monitor Agent does—and does not do

AMA is an agent installed on a machine to collect configured logs and metrics. Data Collection Rules (DCRs) determine what it collects and where that data is sent. For the log collection described here, the usual destination is a Log Analytics workspace, where administrators can query records and build monitoring workflows. Azure Monitor workspaces serve different scenarios, including Prometheus and OpenTelemetry metrics; they should not be treated as interchangeable with Log Analytics workspaces.

Installing AMA alone does not create a complete monitoring system. Administrators still need to choose data sources, configure DCRs, confirm destination and permissions, and validate that telemetry arrives. From there, selected data may support Azure Monitor alerts, workbooks, or Microsoft Sentinel workflows where those services and integrations are available.

AMA observes the Cloud PC guest operating system and the data sources configured for it. It does not automatically provide all Windows 365 service telemetry, and it does not replace Windows 365 service reports, Intune reporting, Cloud PC diagnostics, or Microsoft service health. Microsoft’s overview explains AMA, DCRs, and the distinction between monitoring workspaces: Azure Monitor overview.

Choose telemetry to answer a specific question

Start from an operational or security objective rather than enabling every available channel. These are examples to consider, not a Microsoft-prescribed universal collection set:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Microsoft Office Home 2024 | Classic Office Apps: Word, Excel, PowerPoint | One-Time Purchase for a single Windows laptop or Mac | Instant Download
  • Classic Office Apps | Includes classic desktop versions of Word, Excel, PowerPoint, and OneNote for creating documents, spreadsheets, and presentations with ease.
  • Install on a Single Device | Install classic desktop Office Apps for use on a single Windows laptop, Windows desktop, MacBook, or iMac.
  • Ideal for One Person | With a one-time purchase of Microsoft Office 2024, you can create, organize, and get things done.
  • Consider Upgrading to Microsoft 365 | Get premium benefits with a Microsoft 365 subscription, including ongoing updates, advanced security, and access to premium versions of Word, Excel, PowerPoint, Outlook, and more, plus 1TB cloud storage per person and multi-device support for Windows, Mac, iPhone, iPad, and Android.
  • Windows event logs: System, Application, Remote Desktop Services-related channels, and—when justified—Security or endpoint-security logs. Select specific channels based on the investigation or detection need.
  • Performance counters: CPU utilization, memory pressure, disk latency and queue behavior, free disk space, or network utilization. Process- or service-level indicators can help investigate a known issue.
  • Security and compliance signals: Decide whether equivalent data is already collected through Microsoft Defender for Endpoint or another approved service before adding another collection path.

Security events and other logs can contain sensitive information. Apply data minimization, retention rules, access controls, and applicable regional or government-cloud requirements. Broad event-channel and counter collection can create noise and increase ingestion and retention costs. Monitoring should serve a defined administrative purpose, not become indiscriminate employee surveillance.

Plan an AMA deployment for Cloud PCs

Microsoft’s release note confirms AMA support on Enterprise and Government Cloud PCs, but it does not establish one universal Windows 365-specific deployment path. Confirm the supported deployment method and current requirements for your tenant, operating system, Azure environment, and government-cloud configuration before rolling it out; avoid assuming a portal sequence that is not documented for your scenario.

Prerequisites to verify

  • Cloud PCs are in a supported Windows 365 Enterprise or Windows 365 Government environment, and the operating system and AMA version are supported.
  • You have administrative control over the Cloud PCs or their management plane and permissions to configure the agent, DCR, and destination.
  • You have selected a Log Analytics workspace for log collection, with the appropriate Azure subscription, access, and retention decisions.
  • The DCR defines the required collection and destination, and the Cloud PCs can reach the required Azure Monitor endpoints.
  • The chosen services and endpoints are supported in the relevant government-cloud environment. Do not infer that support for AMA means every dependent Azure service is available in every government environment.
  • You have checked for overlapping collection by legacy agents or security products.

Use a pilot-and-expand deployment

  1. Define the objective. Decide whether the goal is troubleshooting, security detection, capacity planning, or compliance retention, and select only the data needed for it.
  2. Select the destination. Create or identify a Log Analytics workspace suitable for the logs being collected; verify its region, access, and retention configuration.
  3. Build a narrow DCR. Specify the event channels, counters, and destination that match the use case. Avoid broad collection until data volume and value are understood.
  4. Deploy to a pilot group. Use the deployment method supported for your Windows 365 environment and check how it targets Cloud PCs.
  5. Validate agent and data health. Confirm the agent is present and running, the DCR is associated with the intended devices, and expected records arrive with correct timestamps and device identity.
  6. Review volume and cost. Look for unexpectedly high-volume channels, duplicate ingestion, or noisy counters before expanding the scope.
  7. Expand gradually. Add Cloud PCs in stages, then build alerts or workbooks only after confirming the data is useful and stable.
  8. Document operations. Record collection exclusions, retention, ownership, and how the agent and policy are reapplied or removed if a Cloud PC is reprovisioned.

Diagnose missing or unexpected data

  • Agent is installed, but no records arrive: Check DCR association, destination configuration, endpoint connectivity, workspace permissions, and whether the selected channels actually produce records.
  • Only some Cloud PCs report: Check targeting and group membership, provisioning timing, and differences in image or operating-system update level.
  • Ingestion is higher than expected: Narrow high-volume event channels and counters, review retention, and look for duplicate collection from another agent.
  • A reprovisioned Cloud PC stops reporting: Verify whether the agent and its policy are built into the image or are reapplied through the supported management process.
  • Government-cloud data does not arrive: Confirm that the destination, endpoints, and dependent services are supported in that environment rather than assuming commercial-cloud parity.

Choose what happens when a remote session is locked

The policy controls whether locking a remote session disconnects the session or shows the remote lock screen. It applies when the user locks the session or a policy locks it. Microsoft documents different defaults by authentication method:

Authentication scenario Documented default
Microsoft Entra single sign-on Disconnect the session
Legacy authentication protocols Show the remote lock screen

With Microsoft Entra SSO, disconnecting supports consistent Entra sign-in behavior, passwordless methods such as passkeys and FIDO2, and reevaluation of Conditional Access policies when the user reconnects. A user may reconnect without another authentication prompt if Conditional Access and other authentication conditions allow it; disconnecting does not guarantee a prompt-free return. Conditional Access can require multifactor authentication when its configured conditions call for it, but disconnecting alone does not force MFA.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disconnecting can strengthen the return-to-session authentication flow, but it interrupts the session and may add reconnection friction. The remote lock screen may suit a familiar lock-and-unlock workflow or legacy authentication, but it does not provide the same passwordless and Conditional Access behavior described for disconnecting. Neither option is universally right; choose according to authentication design, policy requirements, and user experience.

Windows update prerequisites

Microsoft’s session-lock guidance lists these minimum cumulative updates for the operating systems covered. The Windows 365 Cloud PC image must meet the applicable requirement; the August 2024 service release itself does not install these updates.

  • Windows 11, single-session or multi-session: May 2024 cumulative update KB5037770 or later.
  • Windows 10, single-session or multi-session, version 21H2 or later: June 2024 cumulative update KB5039211 or later.
  • Windows Server 2022: May 2024 cumulative update KB5037782 or later.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Configure the lock behavior with Intune

For Windows 365, deploy the policy to the device group containing the Cloud PCs that provide the remote sessions. Microsoft’s session-lock instructions use the Intune Settings Catalog path below. The Intune administrator needs the Microsoft Entra Policy and Profile manager built-in role.

  1. Sign in to the Microsoft Intune admin center.
  2. Create or edit a configuration profile for Windows 10 and later, using the Settings catalog profile type.
  3. In the settings picker, navigate to Administrative templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security.
  4. Select the policy that matches the authentication path: Disconnect remote session on lock for Microsoft identity platform authentication or Disconnect remote session on lock for legacy authentication.
  5. Set the selected policy to Enabled to disconnect the remote session when it locks, or Disabled to show the remote lock screen.
  6. Assign the profile to the group containing the relevant Cloud PC devices, then create or save the profile.
  7. After the policy applies, restart the Cloud PCs and test locking and reconnecting a session.

These are separate policies for Microsoft identity platform and legacy authentication. Configure the one or both that match the authentication methods in use; do not assume changing one setting controls every sign-in path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the lock behavior with Group Policy

Group Policy is an alternative for domain-managed environments. Target the relevant Cloud PCs and use the matching authentication-specific policy.

  1. Open Group Policy Management and create or edit a policy that targets the relevant machines.
  2. Navigate to Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security.
  3. Configure Disconnect remote session on lock for Microsoft identity platform authentication or Disconnect remote session on lock for legacy authentication.
  4. For Microsoft Entra authentication, set the policy to Enabled or leave it Not configured to disconnect; set it to Disabled to show the remote lock screen.
  5. For legacy authentication, set the policy to Enabled to disconnect; Disabled or Not configured shows the remote lock screen.
  6. Apply the policy, restart the relevant machines, and test session locking and reconnection.

If the policy definitions are missing, Microsoft says to copy C:WindowsPolicyDefinitionsterminalserver.admx and C:WindowsPolicyDefinitionsen-USterminalserver.adml to the domain controller or Group Policy Central Store. Replace en-US with the applicable language code when needed. See Microsoft’s session-lock configuration guidance for the policy behavior and prerequisites.

Test the policy and recover from a mismatch

A configured profile is not proof that the intended authentication behavior is active. Validate the actual Cloud PC and sign-in path after the policy applies.

  1. Confirm the Cloud PC has the required cumulative update and that the profile or Group Policy has applied.
  2. Restart the Cloud PC after policy application.
  3. Connect using the authentication path under test, then lock the remote session.
  4. Confirm that the session disconnects or displays the remote lock screen as configured.
  5. Reconnect and verify the expected Conditional Access and MFA result for the tenant’s policies.
  6. If behavior is wrong, check the authentication-specific policy, policy targeting, update level, restart, and whether the client is actually using Microsoft Entra SSO.
  7. To roll back or change behavior, update the same policy to the desired value for that authentication scenario, let it apply, restart, and repeat the test.

How the monitoring options differ

The following is an architectural comparison, not a claim that Microsoft positions every product as a direct substitute.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Option Strength Limitation
Azure Monitor Agent Collects configured guest-OS telemetry and integrates with Azure Monitor and DCRs. Requires collection design, workspace management, deployment validation, and ingestion-cost control.
Microsoft Defender for Endpoint Focuses on endpoint security and threat detection. Not a universal replacement for customized Azure Monitor event collection.
Intune reporting Supports device-management and compliance visibility. Not a general-purpose guest-OS log analytics platform.
Windows 365 reports and diagnostics Supports Cloud PC service-level administration. May not expose every guest-OS event or performance signal.
Third-party endpoint monitoring May provide cross-platform analytics or user-experience monitoring. Adds vendor, licensing, data-transfer, and agent-management complexity.

For session locking, Microsoft’s documentation is shared with Azure Virtual Desktop, but the Windows 365 deployment described here is an Intune or Group Policy configuration on the Cloud PC. It is not an Azure Virtual Desktop host-pool configuration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.