Parallels RAS 20 Administrator's Guide
ProductsSupportPartnersDocumentation
English
English
  • Parallels RAS 20 Administrator’s Guide
    • Introduction
      • Parallels RAS release history
      • About Parallels RAS
      • About this guide
      • What's new
      • Terms and abbreviations used in this guide
    • Installing Parallels RAS
      • System requirements
        • Hardware requirements
        • Software requirements
        • Microsoft license requirements
      • Install Parallels RAS
      • Log in and activate Parallels RAS
    • Getting Started with Parallels RAS
      • The Parallels RAS Console
      • Set up a basic Parallels RAS Farm
        • Add an RD Session Host
        • Publish applications
        • Invite users
        • Azure Virtual Desktop
        • Conclusion
    • Farm and Sites
      • Connecting to a Parallels RAS Farm
      • About Sites
      • Sites in the RAS Console
      • Adding a Site to the Farm
      • Replicating Site settings
      • Managing Licensing Site
      • Managing administrator accounts
        • Adding an administrator account
        • Administrator account permissions
        • Managing administrator accounts
        • Configure RAS Console idle sessions
        • Using instant messaging
        • Joining Customer Experience Program
    • RAS Connection Broker
      • Configuring RAS Connection Brokers
      • Secondary Connection Brokers
      • Managing Secondary Connection Brokers
      • Using computer management tools
    • RAS Secure Gateway
      • Overview
      • Adding a RAS Secure Gateway
      • Manually adding a RAS Secure Gateway
      • Checking the RAS Secure Gateway status
      • Configuring a RAS Secure Gateway
        • Enable or disable a Secure Gateway
        • Set public address
        • Set IP addresses for client connections
        • Site defaults (Secure Gateways)
        • Gateway mode and forwarding settings
        • Gateway network options
        • SSL/TLS encryption
          • SSL server configuration
        • Configure User Portal
          • Using Site defaults
          • Enable or disable User Portal
          • Client settings
          • Network load balancers access
        • Wyse ThinOS support
        • Secure Gateway security
        • Web request load balancing
      • Secure Gateway tunneling policies
      • Configure logging
      • Viewing Secure Gateway summary and metrics
      • Using computer management tools
    • RD Session Hosts
      • RD Session Host types
      • Add an RD Session Host
        • Installing the agent manually
      • Add a template-based RD Session Host
      • Manage RD Session Hosts
        • Manage host pools (RD Session Hosts)
          • Add host pools (RD Session Hosts)
          • Upgrading Agents (RD Session Hosts)
        • Manage templates (RD Session Hosts)
          • Creating an RD Session Host template
          • Assigning a template to a host pool (RD Session Host)
          • Managing RD Session Hosts based on a template
        • Manage hosts (RD Session Hosts)
          • Viewing RD Session Hosts
          • Check an RD Session Host Agent status
          • Change RD Session Host Site assignment
          • View and modify RD Session Host properties
            • Using default settings
            • General
            • Agent settings
            • User profile
            • Application Packages
            • Optimization
            • Desktop access
            • RDP printer
          • User profile
            • User Profile Disks
            • FSLogix
              • Configure managing existing profiles by Parallels RAS
              • FSLogix antivirus exclusions
          • Optimization
          • Drive redirection cache
          • Configure logging
        • Manage sessions (RD Session Host)
        • Using scheduler (RD Session Hosts)
      • Planning for high availability
      • Managing logons
      • Using computer management tools
      • Publishing from an RD Session Host
      • Viewing published resources
    • Virtual Desktop Infrastructure (VDI)
      • Supported providers
      • Add a provider
        • RAS Provider Agent information
          • RAS Provider Agent installation options
        • Add a hypervisor provider
        • Add a cloud Provider
          • Microsoft Azure
            • Introduction and prerequisites
            • Create Microsoft Entra ID application
            • Add Microsoft Azure as a Provider
            • Microsoft Azure and templates
          • Amazon Web Services
            • Introduction and prerequisites
            • Design considerations
            • Step 1. Creating an IAM user for programmatic access
            • Step 2. Adding AWS as a Provider
      • Manage VDI
        • Manage providers (VDI)
          • Installing RAS Provider Agent using the installer
          • Checking the RAS Provider Agent status
          • Using a Provider in multiple farms
        • Manage host pools (VDI)
          • Add host pools (VDI)
          • Delete host pools (VDI)
          • Add and delete host pool members
          • Using a wildcard to filter VMs
          • Managing hosts in pools
          • Upgrading Agents (VDI)
        • Manage templates (VDI)
          • Virtual desktop templates
          • Multi-provider template distribution
          • Creating a VM template
            • Step 1: Check and install the Agent
            • Step 2: Configure the template
              • Properties
              • Distribution
              • Advanced
              • Preparation
              • Optimization
              • License keys
              • Summary
              • Host naming
            • Parallels Test Template Wizard
            • Modifying template properties
          • How hosts are created from a template
          • Manually adding a host
          • Assigning a template to a host pool (VDI)
          • Template maintenance
          • Template status
          • Managing multi-provider template distribution
          • Managing template-based hosts
        • Manage hosts (VDI)
          • Persistent hosts
          • Configuring hosts to interact with RAS Provider Agent in a different subnet
        • Manage sessions (VDI)
        • Using scheduler (VDI)
      • Configure logging
      • Enabling high availability for VDI
      • Site defaults (VDI)
      • Using computer management tools
      • Viewing Provider summary
      • Remote PC pools in VDI
        • Adding a Provider
        • Adding Remote PCs to a Provider
        • Adding Remote PCs to a pool
        • Managing Remote PCs in a pool
        • Persistent Remote PCs
        • RAS Guest Agent installation options
    • Azure Virtual Desktop
      • Introduction
      • Prerequisites
      • Deploy Azure Virtual Desktop
        • Enable Azure Virtual Desktop and add a provider
        • Add workspaces
        • Add host pools (Azure Virtual Desktop)
      • Manage Azure Virtual Desktop
        • Manage providers (Azure Virtual Desktop)
        • Manage workspaces (Azure Virtual Desktop)
        • Manage host pools (Azure Virtual Desktop)
          • Upgrading Agents (Azure Virtual Desktop)
        • Manage templates (Azure Virtual Desktop)
          • Create a template
          • Manage existing templates
          • Assigning a template to a host pool (Azure Virtual Desktop)
        • Manage hosts (Azure Virtual Desktop)
        • Manage sessions (Azure Virtual Desktop)
        • Using scheduler (Azure Virtual Desktop)
      • Site defaults (Azure Virtual Desktop)
        • Site defaults for single-session hosts
        • Site defaults for multi-session hosts
      • Using Parallels Client with Azure Virtual Desktop
      • Verify the deployment
    • Remote PCs
      • Overview
      • Manage host pools (Remote PC)
      • Manage hosts (Remote PC)
        • Adding a Remote PC to a Farm
          • Admin-initiated Remote PC enrollment
          • Self-service Remote PC enrollment
        • Configuring a Remote PC
      • Viewing Remote PC summary
      • Using computer management tools
    • Publishing
      • Overview
      • Publishing a desktop
      • Publishing an application
      • Publishing local applications
      • Publishing an application with MSIX app attach
      • Publishing a web application
      • Publishing a network folder
      • Publishing a document
      • General management tasks
      • Manage published applications
      • Manage published desktops
      • Manage published documents
      • Manage folders
      • Site defaults (Publishing)
      • Using filtering rules
      • Configuring preferred routing
      • Understanding session prelaunch
      • Checking effective access
      • Specifying client settings
      • Quick keypad
    • Session Management
      • Overview
      • Session information
      • Monitoring settings
      • Managing sessions
      • The Resources tab
    • SSL Certificate Management
      • Generating a self-signed certificate
      • Generating a certificate signing request (CSR)
      • Let's Encrypt certificates
        • Requesting a Let's Encrypt Certificate
        • How Parallels RAS requests certificates from Let's Encrypt
      • Importing a certificate
      • Exporting a certificate
      • Assigning a certificate to Secure Gateways and HALBs
      • Auditing certificates
      • Permissions to manage certificates
      • Upgrading from an older RAS version
    • Connection and Authentication Settings
      • RAS Connection Broker connection settings
      • Remote session settings
      • Logon hours settings
      • Restricting access by Parallels Client type and build number
      • Multi-factor authentication
        • Adding an MFA provider
        • Using RADIUS
          • Connection
          • Attributes
          • Automation
          • Advanced
          • Configuring Azure MFA
          • Configuring Duo
        • Using TOTP
          • Configuring TOTP
          • Configuring Google Authenticator
          • Configuring Microsoft Authenticator
        • Configuring email OTP
        • Using Deepnet DualShield
          • Supported tokens
          • Configuring DualShield 5.6+ Authentication Platform
          • Configuring Parallels RAS to use the DualShield Authentication Platform
          • Connect to a RAS Farm
        • Using SafeNet
          • Configuring SafeNet
        • Configuring MFA rules
      • Allowing users to change domain password
      • Allowing users to discover RAS connections via email address
    • Load Balancing and HALB
      • Resource based & round robin load balancing
        • Configure CPU optimization
      • High availability load balancing (HALB)
        • Prerequisites
        • Deploying a Parallels HALB appliance
        • Adding a HALB virtual server
        • HALB Device status and version number
        • HALB maintenance
        • HALB connection and session information
        • Changing the HALB appliance password
    • RAS Multi-Tenant Architecture
      • Overview
      • Architecture description
        • Implementation overview
        • User connection flow
      • Deploying Tenant Broker and Tenants
        • Deploying Tenant Broker
        • Deploying a Tenant
          • Join a Tenant to Tenant Broker
          • Joining with a secret key
          • Verify join status
          • Configure network
          • Assign a public domain address
          • Configure an SSL certificate
          • Set up routing for incoming traffic
        • User authentication
        • Unjoining from Tenant Broker
      • Managing Tenants
        • Tenant configuration
        • Deleting a Tenant object
        • Opening a Tenant console
      • Shared Gateways
      • Third-party network load balancers
      • Web Client and Themes
      • Monitoring Tenants
      • Tenant Broker compatibility and updates
      • Upgrading from an older RAS version
      • Configuring notifications
      • Communication ports
    • SAML SSO Authentication
      • Introduction
      • System requirements
      • SAML basics
      • SAML configuration
        • Prerequisites
        • IdP side configuration
        • SP side configuration (RAS side)
        • Active Directory user account configuration
        • Configure certificate authority templates
          • Create an Enrollment Agent template
          • Create a smartcard logon certificate template
        • RAS Enrollment Server configuration
        • RAS Enrollment Server high availability
        • SAML integration examples and tips
          • User account attributes
          • Security tip
      • Parallels Client configuration
      • Parallels client policy configuration
      • Test the SAML SSO deployment
      • Error messages
    • Parallels Web Client and User Portal
      • Configure Web Client
      • Configure Themes
        • General settings
        • Access settings
        • Message settings
        • Web Client settings
          • URLs
          • Branding
          • Colors
          • Language bar
          • Messages
          • Input prompt
          • Gateway
          • Legal policies
        • Parallels Client for Windows settings
        • General Theme tasks
        • Delegating session management permissions
      • Open Parallels Web Client
      • Main menu options
      • Running remote applications and desktops
        • Using drag and drop functionality
        • Native clipboard experience
        • Other useful features
      • Auto login
      • Direct App access
      • Using the toolbar
        • Using the toolbar on desktop computers
        • Using the Toolbar on Mobile Devices
        • Using the remote clipboard
        • Hiding toolbar items
    • Universal Printing
      • Managing Universal Printing Settings
      • Universal Printing drivers
      • Font management
    • Universal Scanning
      • Managing Universal Scanning
      • Adding scanning applications
    • User Device Management and Client Policies
      • Inviting users to connect to Parallels RAS
      • Mass configuring user devices
      • Enabling Help Desk support for users
      • Enabling Help Desk support for custom administrators
      • Monitoring devices
        • Getting additional device information
      • Windows device groups
      • Managing Widows devices
        • Windows desktop replacement
      • Scheduling Windows devices & groups power cycles
      • Client policies
        • Add a new client policy
        • Configure session settings
          • Appearance
          • Connection
          • Display
          • Printing
          • Scanning
          • Audio
          • Keyboard
          • Local devices and resources
          • Experience
          • Network
          • Server authentication
          • Advanced settings
        • Configure client policy options
        • Configure control settings
        • Configure Gateway redirection
        • Client policy backward compatibility
        • Policy information in Parallels Client
      • Configuring remote file transfer
        • Configure file transfer to a server
        • Configure file transfer in User Portal
        • Configure file transfer for a client policy
    • Reporting
      • System requirements
      • Install Microsoft SQL Server
        • Install Microsoft SQL Server 2016 or earlier
        • Install Microsoft SQL Server 2017 or 2019
        • Install Microsoft SQL Server 2022
      • Install Parallels RAS Reporting
      • Running Parallels RAS Reports
      • GDPR compliance
    • Performance monitor
      • Overview
      • Install RAS Performance Monitor
      • Using Parallels RAS Performance Monitor
      • Configure RAS Performance Monitor security
      • Updating RAS Performance Monitor
    • Common Management Tasks
      • Recovery – add a root administrator
      • Host name resolution
      • Computer management tools
      • Site information
      • Site settings
      • Using MSIX application packages
      • Using template versions
      • Settings audit
      • Upgrading RAS agents
      • Licensing
      • Configure HTTP proxy settings
      • System event notifications
        • Configuring notification handlers
        • Configuring notification scripts
        • Configuring SMTP server connection for event notifications
      • RAS session variables
      • Resolving z-order issues
      • Maintenance and backup
        • Importing and exporting Farm settings from the command line
      • Problem reporting and troubleshooting
      • Logging
      • Suggest a feature
    • Parallels RAS Management Portal
      • Overview
      • Prerequisites
      • Installation
      • Log in to RAS Management Portal
      • Configure RAS Web Administration Service
      • RAS Management Portal user interface
    • Parallels RAS APIs
      • RAS PowerShell API
      • RAS REST API
        • Installation
        • Permissions
        • Getting started
        • Logging in and sending requests
        • More information
      • RAS Web Client API and Parallels Client URL scheme
    • Appendix
      • Microsoft license requirements in Parallels RAS
      • Port reference
        • Parallels Client
        • Web browsers
        • HALB
        • RAS Secure Gateway
        • RAS Connection Broker
        • RAS Console
        • SSRS
        • RAS Reporting
        • RAS Web Administration Service (REST/Management Portal)
        • RAS PowerShell
        • RAS Provider Agent
        • RAS Enrollment Server
        • RAS RD Session Host Agent
        • RAS Guest Agent
        • RAS Remote PC Agent
        • Tenant Broker
        • Active Directory and Domain Services ports
        • Azure Virtual Desktop
      • RAS performance counters
Powered by GitBook

© 2025 Parallels International GmbH. All rights reserved.

On this page
  • Microsoft Azure subscription
  • Azure Virtual Desktop user license entitlement
  • Permissions and Azure resource providers
  • Microsoft Entra ID application
  • Active Directory
  • Other
  • Additional notes

Was this helpful?

Export as PDF
  1. Parallels RAS 20 Administrator’s Guide
  2. Azure Virtual Desktop

Prerequisites

The below highlights the prerequisites required to use Azure Virtual Desktop and configuration in Parallels RAS environment.

Important: If you are using Azure Virtual Desktop in Parallels RAS 19.3, you need to update Parallels Client to version 19.3.

Microsoft Azure subscription

You need a Microsoft Azure subscription, including:

  • An Azure Tenant ID.

  • An Azure subscription with sufficient credit.

Azure Virtual Desktop user license entitlement

Customers with the licenses listed below are entitled to use Azure Virtual Desktop at no additional charge apart from Azure compute, storage, and network usage billing.

To run Windows 10 and Windows 11 with Azure Virtual Desktop you need to have one of the following per user license:

  • Microsoft 365 F3, E3, E5, A3, A5, Student Use Benefits or Business Premium

  • Windows 10 Enterprise E3, E5

  • Windows 10 Education A3, A5

  • Windows 10 VDA per user

To run Windows Server 2012 R2, 2016, 2019, 2022:

  • Per user or per device Remote Desktop Services (RDS) Client Access License (CAL) with active Software Assurance (SA).

Permissions and Azure resource providers

The below highlights permissions and resource providers to be registered in the subscription:

  • Permissions to enable resource providers on your Azure subscription and create virtual machines (VMs).

  • The necessary Microsoft Azure resource providers (Azure Portal > Subscription > Resource Providers) must be enabled, including Microsoft.ResourceGraph, Microsoft.Resources, Microsoft.Compute, Microsoft.Network, Microsoft.DesktopVirtualization.

Microsoft Entra ID application

Once an Microsoft Entra ID Application is created, give the application the following API permissions in the Microsoft Azure Portal (Microsoft Entra ID > App Registrations > API permissions > Add a permissions > Microsoft.Graph > Application permission):

  • Group > Group.Read.All

  • User > User.Read.All

Note: Please make sure that when adding Graph API permissions, User and Group, the permission type is "Application" not "Delegated".

Give the application read and write access to resources:

Roles and permissions for the application should include:

  • "User Access Administrator" role for the application from Subscription > Access Control (IAM).

  • "Contributor" role at the Resource group level from Resource group > Access Control (IAM).

If a resource group creation is required, also assign contributor role at the subscription level Subscription > Access Control (IAM).

Note: If you would like to also view/read resources outside the resource group make sure that the application is also given read access at the subscription level.

Active Directory

  • Azure AD Connect — AD must be in sync with your Microsoft Entra ID, so users can be associated between the two.

  • The user must be sourced from the same Active Directory that's connected to Microsoft Entra ID. Azure Virtual Desktop does not support B2B or MSA accounts.

  • The user configured in the Parallels client with access to Azure Virtual Desktop resources must exist in the Active Directory domain the session host it is joined to.

Other

  • Azure Virtual Network providing session hosts connection to the domain.

  • Session hosts must be domain-joined to Active Directory.

  • (optional) Site-to-site VPN or ExpressRoute is required if hybrid Parallels RAS deployment is used.

  • (optional) Shared network location to be used for FSLogix Profile Containers which may run on Azure Files or Azure NetApp Files.

Note: At the time of writing, Windows 7 is not supported by Parallels RAS as an Azure Virtual Desktop session host.

Additional notes

Please also note the following Provider and Azure Application requirements for different RAS Farm and RAS Site scenarios:

  • Same RAS Farm, same RAS Site: The same Farm, Site, and Application ID is possible to be used for both VDI and Azure Virtual Desktop. Build the guest VM list with Azure Virtual Desktop tags for Azure Virtual Desktop provider and guest VMs with VDI tags (or no tags) for Azure Provider.

  • Same RAS Farm, same RAS Site: It is recommended to use different Azure Applications for multiple providers of the same type. For example, multiple Azure Virtual Desktop or multiple Providers but not mixed.

  • Same RAS Farm, different RAS Sites or different RAS Farms: The point above applies. Alternatively, different RAS Farms or Sites can (and must in this case) reside in different virtual networks with no communication to common set of VMs.

Important: It is recommended that Parallels RAS managed Azure Virtual Desktop objects are managed through the Parallels RAS console. Configuration changes outside Parallels RAS console may result in a broken state of Azure Virtual Desktop objects. For such cases, Parallels RAS provides the ability to repair objects. For example, auto created friendly names and associated tags for workspaces and host pools can also be viewed from the Microsoft Azure portal, however they are not to be edited as these are used to ensure proper functionality.

PreviousIntroductionNextDeploy Azure Virtual Desktop

Was this helpful?

For further information, please refer to Microsoft licensing requirements at .

For a detailed information about creating an Microsoft Entra ID application, please see .

The Microsoft Entra ID application that you created must have read and write access to Azure resources as described in . Look for "Give the application read and write access to resources".

A Server Active Directory environment or Azure Active Directory Domain Services (AADDS). See .

https://docs.microsoft.com/en-us/azure/virtual-desktop/overview
Create a Microsoft Entra ID application
Create a Microsoft Entra ID application
https://azure.microsoft.com/services/active-directory-ds/