For the complete documentation index, see llms.txt. This page is also available as Markdown.

Stage 3: Management Portal & Remote Policy Setup

What this stage accomplishes

Creates the Golden Image and Policy that actually govern what Stage 1's group receives and what they're allowed to do.

Prerequisites

Stage 1 (group/sublicense) and Stage 2 (image, source choice, and/or provisioning package) done.

Steps

  1. Create the Golden Image. In the Management Portal's Golden Images page, click Create Golden Image and set Deployment method:

    • Declarative — choose Windows Enterprise or Custom ISO, set Installation options, and attach the provisioning package from Stage 2 if you built one.

    • VM image — enable the architecture(s) you need, provide the Download URL (Azure Storage picker or direct link) and the SHA-256 checksum from Stage 2.

  2. Create the Policy. In Policies, click Add and work through: General Information (name it, and under Policy applies to, select your group), Golden Image (assign the one you just created), then Security Controls and VM Settings. The table below shows what each scenario recommends for these last two:

Security Controls and VM Settings — pick from the available options. The table below shows what each scenario recommends:

Security controls:

  • Do not allow removing provisioned VMs

VM settings:

  • Clipboard/Drag-and-drop: Bidirectional

  • VM startup: Ready in background

  • Show Developer Tools: enabled

Security controls:

  • Limit users to provisioned VMs only

  • Do not allow removing provisioned VMs

  • Do not allow editing Parallels Desktop preferences

VM settings:

  • Clipboard/Drag-and-drop: Bidirectional

  • VM startup: Ready in background

  • Do not allow external devices

Security controls:

  • Encrypt VMs and lock them to the company's license

  • Limit users to provisioned VMs only

  • Do not allow removing provisioned VMs

VM settings:

  • Clipboard/Drag-and-drop: Disconnect (mandatory)

  • Other VM isolation settings: optional, evaluate case-by-case

Not applicable (See Scenario D for its Autodeploy Package configuration instead)

Security controls:

  • Do not allow upgrading to the next major Parallels Desktop version

  • Do not allow removing provisioned VMs

VM settings:

  • Clipboard/Drag-and-drop: Disconnect

  • Disable sharing Mac folders with VM

  • Disable sharing VM apps with Mac

  • VM startup: Ready in background

Toggle VM Settings for the current Golden Image and, optionally, for VMs from other sources.

spinner

Note: VM Settings configured here require client Parallels Desktop for Mac installations on 26.1 or newer.

Verification

The Golden Image card shows the deployment method and source you expect. The policy doesn't show as not applied, and its Policy applies to list contains the intended group.

Common issues

A group can only have one policy at a time — if it already has one, you'll need to edit that policy rather than create a second. The Golden Image's deployment method and installation source can't be changed once saved, so double-check before clicking Add.

Handoff to next stage

With the policy live, move to Stage 4 to get Parallels Desktop onto end-user Macs so the policy actually takes effect.

Last updated