Use an Intune Settings catalog device configuration policy to control which local resources can enter or leave a Windows 365 Cloud PC session. The policy supports both Microsoft Entra joined and Microsoft Entra hybrid joined Cloud PCs. Group Policy remains an option for hybrid-joined Cloud PCs, but it is not the equivalent management path for Entra-joined devices.
This current procedure updates the terminology and defaults found in the February 2022 HTMD guide. It focuses on host-side RDP redirection controls, not on editing an .rdp file or configuring a user’s Windows App alone.
What “Cloud PC RDP properties” controls
RDP redirection determines whether a local device resource is presented inside the Cloud PC session. A Cloud PC device configuration policy controls the host-side decision. It is different from:
- Windows App or Remote Desktop app configuration, which controls client behavior. Microsoft documents names such as
drivestoredirect,redirectclipboard, andcamerastoredirectfor that layer: Windows App redirection settings. - Windows 365 connection policies, which can affect connection context and experience.
- Group Policy, which Microsoft documents for hybrid-joined Cloud PCs.
The Intune settings are ADMX-backed Windows policies delivered through MDM. They are not a copy of a classic GPO, even though many names and registry mappings are familiar.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
Redirections you can manage
| Resource | Settings catalog control | Effect when blocking is enabled |
|---|---|---|
| Clipboard | Do not allow Clipboard redirection | Blocks copying and pasting between the local device and Cloud PC. |
| Local drives | Do not allow drive redirection | Prevents redirected local disks from appearing in the Cloud PC. |
| Printers | Do not allow client printer redirection | Hides local client printers from the session. |
| Camera | Do not allow video capture redirection | Blocks camera access through the RDP session. |
| USB and Plug and Play | Do not allow supported Plug and Play device redirection | Blocks supported redirected devices. |
| Smart cards | Do not allow smart card device redirection | Prevents smart-card redirection. |
| COM ports | Do not allow COM port redirection | Prevents serial-device redirection. |
| Location | Do not allow location redirection | Stops local location information being passed to the Cloud PC. |
| Microphone | Allow audio recording redirection | Controls local microphone/audio capture in the session. |
| Playback | Allow audio and video playback redirection | Controls audio and video playback to the local client. |
See Microsoft’s complete mapping in Manage device RDP redirections for Cloud PCs.
Current Windows 365 defaults
Microsoft currently documents clipboard, drive, opaque low-level USB, and printer redirection as disabled by default for newly provisioned and reprovisioned Cloud PCs. Existing machines can reflect older provisioning behavior, previous assignments, or tenant-specific configuration. An explicit policy is still valuable when you need a continuously enforced, auditable state or consistent treatment of older Cloud PCs.
Do not confuse a setting’s name with its value. For a control named Do not allow, set it to Enabled to block the feature. Set it to Disabled, or leave it unconfigured under your policy model, to permit it. Microsoft explains this inverse behavior for clipboard and drive redirection.
Rank #2
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
Plan the policy before creating it
Prerequisites
- A Windows 365 deployment with Cloud PCs enrolled and checking in to Intune.
- Intune permissions to create and assign device configuration profiles.
- A pilot device group or tested Intune filter containing only the intended Cloud PCs.
- A decision about exceptions for printing, meetings, smart-card authentication, accessibility, or support.
- An inventory of Windows 365 security baselines and other profiles that may configure the same settings.
The KB5005565 prerequisite mentioned in the February 4, 2022 HTMD article describes that historical lab context. Current Microsoft guidance does not make it a universal prerequisite.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose the control model
| Model | Best fit | Important limitation |
|---|---|---|
| Settings catalog | Focused controls, pilot groups, Entra-joined or hybrid-joined Cloud PCs, and Intune reporting. | Duplicate settings elsewhere can create conflicts. |
| Windows 365 security baseline | A broad Microsoft-recommended security posture managed together. | Less convenient when different Cloud PC populations need different exceptions. |
| Group Policy | Established Active Directory processes for hybrid-joined Cloud PCs. | Microsoft’s documented support does not extend this management route to Entra-joined Cloud PCs. |
Baseline version changes can make older Windows 365 baseline instances read-only until they are updated. Review the Windows 365 security baseline reference before assigning overlapping controls.
Create the Settings catalog profile
- Sign in to the Microsoft Intune admin center.
- Go to Devices > Configuration profiles.
- Select Create profile.
- Choose Windows 10 and later as the platform and Settings catalog as the profile type, then select Create.
- Name the profile for its scope and purpose, for example
W365 - Block Clipboard and Drive Redirection - Pilot. In the description, record the Cloud PC population, blocked resources, business reason, and rollback method. - Select Next, then Add settings.
- Search for Device and Resource Redirection under Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host.
- Select the required settings, configure their values, then continue through scope tags, assignments, review, and save.
Example: block clipboard and local drives
For a common data-loss-control policy, configure:
- Do not allow Clipboard redirection — Enabled
- Do not allow drive redirection — Enabled
Drive blocking has a wider effect than merely hiding mapped local disks. The RemoteDesktopServices Policy CSP states that, on supported Windows versions, enabling DoNotAllowDriveRedirection also prevents clipboard file-copy redirection. Treat these as separate test cases:
Rank #3
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
- Plain text from local device to Cloud PC and back.
- Images or rich text.
- Files copied through the clipboard.
- Local-drive mapping in File Explorer.
The drive policy CSP path is:
./Device/Vendor/MSFT/Policy/Config/RemoteDesktopServices/DoNotAllowDriveRedirection
The corresponding traditional policy mappings are fDisableCdm for drives and fDisableClip for clipboard under SOFTWAREPoliciesMicrosoftWindows NTTerminal Services. These mappings are documented in the ADMX_TerminalServer Policy CSP.
Assign only to Cloud PCs
- Create a dedicated Cloud PC device group, or use an Intune filter whose membership you have tested.
- Assign the profile to a small pilot first. Avoid a broad All devices assignment until the filter and exclusions are proven.
- Check the assignment preview and confirm that physical Windows devices are not included.
- Expand in stages, keeping an exclusion group for approved exceptions.
The 2022 HTMD example used an all-device assignment with a Cloud PC filter. The targeting principle remains useful, but current deployments should validate membership with present-day Intune reporting and labels.
Verify behavior in a real session
Wait for the Cloud PC to check in, then disconnect and reconnect the session. Test every client platform your organization supports; Windows App, browser, macOS, mobile, and other clients do not necessarily expose identical redirections.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
| Test | Expected result when blocked |
|---|---|
| Copy text in both directions | Paste is unavailable across the session boundary. |
| Copy a file through the clipboard | File transfer fails when the applicable clipboard or drive control blocks it. |
| Open File Explorer | Redirected local drives are absent; distinguish them from Cloud PC-local or network drives. |
| Local client printers are not listed. | |
| Camera and microphone | Only resources allowed by the configured capture policies work. |
| USB, smart card, COM port, and location | Each behaves according to its individual setting and client support. |
Troubleshoot noncompliance and conflicts
The profile does not apply
- Confirm Intune enrollment, recent check-in, platform eligibility, assignment, filter evaluation, and exclusions.
- Verify that the setting is configured, not merely selected in the picker.
- Review per-device and per-setting deployment reports.
- Reconnect after policy processing; an already-open session may retain its previous redirection state.
Clipboard still works
- Look for another profile that permits clipboard redirection, including a Windows App client configuration.
- Test text, images, rich text, and files separately.
- Check whether a newer directional clipboard policy is being used instead of a blanket block.
- Compare the exact client used for testing with the client used by the affected user.
The CSP documentation describes separate client-to-server and server-to-client clipboard restrictions, allowing more granular controls on supported Windows builds: RemoteDesktopServices Policy CSP.
Drives still appear
- Confirm that the observed drive is a redirected client drive, not a Cloud PC-local or network drive.
- Check the policy result and reconnect the session.
- Review the Windows 365 security baseline and every other profile configuring drive redirection.
Intune reports a conflict
Search all Settings catalog, Windows 365 baseline, Administrative Templates, imported ADMX, test profiles, overlapping groups, and filters. Select one authoritative location. For example, keep Block drive redirection in the baseline and remove the duplicate Settings catalog setting, or set the baseline control to Not configured and manage it in the dedicated profile. Do not assume a second “allow” profile will reliably override the first.
Use local diagnostics as supporting evidence
Inspect Event Viewer > Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin. Policy state may also appear under:
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
- 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
- Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
- 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
- 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
- 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
HKLMSOFTWAREMicrosoftPolicyManagercurrentdeviceADMX_TerminalServer HKLMSOFTWAREMicrosoftPolicyManagercurrentdeviceRemoteDesktopServices
Registry values and event details vary by Windows build. Intune reports, MDM diagnostics, and a real-session test are stronger evidence than a registry snapshot alone.
Use newer clipboard controls when appropriate
The blanket clipboard policy is not the only option. On supported Windows versions and update levels, newer RemoteDesktopServices policies can restrict direction and content type, such as allowing text in one direction while blocking files or images. Verify operating-system applicability and client support before deployment, and document the exact intended data flows.
Roll back safely
- Change a blocking setting to Disabled if you explicitly want to permit it, or remove the setting from the profile.
- Remove the assignment from the pilot group when testing a scoped rollback.
- Allow an Intune check-in, then disconnect and reconnect the Cloud PC session.
- Repeat the same real-session tests used for validation.
Resolve the original assignment or conflict before creating another policy. This avoids leaving contradictory controls in production.
Security and usability trade-offs
Blocking redirection reduces data-exfiltration paths, but it can also break legitimate work: copying commands, transferring files, printing, video meetings, smart-card authentication, scanners, cameras, USB peripherals, and accessibility or support tools.
Recommended Free Tools
- Block drives and file movement while permitting narrowly defined text clipboard use.
- Allow playback but block microphone capture for sensitive environments.
- Permit smart cards for privileged or regulated workflows.
- Use separate policies for finance, engineering, contractors, administrators, and other risk groups.
- Document exceptions, pilot them, and retest after Windows 365 or client updates.
When to consider alternatives
Windows 365 Enterprise with Intune is the natural fit when you want Microsoft-hosted dedicated Cloud PCs and centralized endpoint management. Azure Virtual Desktop offers more host-pool and infrastructure control but requires more Azure design and operations. Existing Active Directory and GPO processes can remain appropriate for hybrid-joined Cloud PCs. For complex rollouts, a Microsoft-certified provider can help with policy design, baseline alignment, migration, and rollback; discovery is available through Microsoft Solution Providers.
The Bottom Line
Build one clearly scoped Intune Settings catalog profile, enable the relevant Do not allow controls, assign it only to tested Cloud PC devices, and resolve duplicate baseline or policy settings before expanding deployment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




