A security tool that wasn’t even publicly released yet needed to protect thousands of virtual desktops from ever touching applications they weren’t authorized to reach. With almost no documentation to go on, this meant working daily alongside Microsoft’s own team.
Our client
The client runs thousands of Windows 365 virtual desktops for its workforce, each needing secure, isolated access to specific internal applications, without opening up broader access to the rest of the network. The client’s name is withheld at their request.
Challenge
The client needed virtual desktops isolated from internal applications they weren’t authorized to access, while still connecting securely to the ones they were. The tool best suited to the job, Microsoft Entra Private Access, wasn’t publicly available yet and had almost no documentation, meaning the project depended on close, daily collaboration with Microsoft’s team.
Solution
Our project had three main objectives:
- Show that Microsoft Entra Private Access could be used to connect Windows 365 virtual machines and various internal applications with different network protocols and latency needs.
- Make sure that Microsoft Entra Private Access fulfills all necessary security requirements, such as per-application access control and zero-trust network access.
- Build an MVP solution based on the client’s non-production environment requirements.
We worked directly with Microsoft to confirm the tool could meet the client’s exact security requirements, restricting access by user, by application, and keeping every connection encrypted end-to-end. We built and tested a working setup on the client’s own network, connecting virtual desktops securely to real internal applications, then confirmed it introduced no meaningful slowdown and held up under the client’s own security review. The project also qualified for Microsoft’s End Customer Investment Fund, which substantially reduced deployment costs, while our team handled the entire build independently.
Results
A Proven Setup, Ready to Roll Out Fleet-Wide.
The client came away with a working, tested security setup ready to scale across its full fleet of virtual desktops once Microsoft’s tool reaches general availability, reviewed and signed off by their own IT and security teams.
Technical Details
Deployed Microsoft Entra Private Access Connectors (Pre-GA) into the client’s non-production network, paired with the Entra Global Secure Access (GSA) client on test Windows 365 machines, using Microsoft Graph API and Azure Resource Manager for configuration and application registration. Validated per-application and per-user access control through Microsoft Entra, confirmed end-to-end encryption through Entra Edge Services, and tested latency and connectivity across FQDN-based internal applications.
What’s Next
The client plans to roll this out across its full fleet of Windows 365 desktops once Microsoft Entra Private Access reaches general availability. In the meantime, the project has already fed real feedback back to Microsoft’s own team, including requests for better integration with existing identity systems and more granular visibility into private access connections.
Piloting a Zero Trust Rollout of Your Own?
If you’re weighing a new security architecture, or trying to get ahead of a tool before it’s fully documented, we can help you get there with fewer surprises.
Date
6/2024
Languages
Java
JavaScript
Frameworks
Microsoft Entra PA (Pre GA)
Microsoft Graph API
Azure Resource Manager (ARM)
Tools
Visual Studio Code
Windows 365
Cloud
Azure
Discuss Your Project
Great things happen when good people connect. Leave us your details, and we’ll get back to you.
By sending the information in this form, you agree to have your personal data processed according to A-CX’s Privacy Policy and Cookie Policy to handle the request and respond to it.