


For example, if their Windows client device is registered with Azure AD, it will receive a Primary Refresh Token (PRT) to use for single sign-on (SSO) across applications. How often a user is prompted to reauthenticate depends on Azure AD session lifetime configuration settings.

You can enforce MFA for Azure Virtual Desktop using Conditional Access, and can also configure whether it applies to the web client, mobile apps, desktop clients, or all clients. Using Azure Active Directory (Azure AD) Multi-Factor Authentication (MFA) with Azure Virtual Desktop prompts users during the sign-in process for another form of identification in addition to their username and password. However, there are certain measures you should take to help keep yourself and your users safe. Users can sign into Azure Virtual Desktop from anywhere using different devices and clients. If you're visiting this page from the Azure Virtual Desktop (classic) documentation, make sure to return to the Azure Virtual Desktop (classic) documentation once you're finished.
