Cloud PC Prerequisites
Requirements for provisioning or linking Cloud PCs in Change360
Introduction
Before you can use the Cloud PC feature in Change360, you’ll need to enable support for provisioning Cloud PCs, linking existing Cloud PCs, or both. This article explains the requirements for each capability.
In this Article
- Prerequisites to allow Change360 to provision Cloud PCs for you
- Prerequisites for linking existing Cloud PCs to your Change360 workspace
Prerequisites to allow Change360 to provision Cloud PCs for you
When Change360 provisions Cloud PCs for you the following is required:
- Permissions to create an Azure Network Connection for the Gateways Vnet
- Microsoft Admin Consent to create and configure Cloud PCs and associated resources
- Available Windows 365 licenses
Azure Role Assignments for the Windows 365 Service Principal
Windows 365 itself needs two Azure RBAC role assignments so it can attach network interfaces and use the Gateway's virtual network:
| Role | On |
| Windows 365 Network Interface Contributor | The resource group where the Cloud PC network resources are created, i.e. where the Gateway's Vnet is located. |
| Windows 365 Network User | The virtual network that Cloud PCs will use, i.e. the Gateway's Vnet. |
Microsoft Admin Consent
Change360 needs permission to provision and manage Cloud PCs in your Microsoft 365 tenant. When you enable the Cloud PC Task Runner feature you will be prompted to grant the following permissions:
|
Permission |
Description |
|
Application.Read.All |
Allow the service to validate that the Windows 365 Application has the correct role assignments |
|
CloudPC.ReadWrite.All |
Create Cloud PCs, read status, and manage lifecycle |
|
DeviceManagementManagedDevices.ReadWrite.All |
Read and write Microsoft Intune managed devices |
|
DeviceManagementScripts.ReadWrite.All |
Read and write Microsoft Intune device scripts |
|
Group.ReadWrite.All |
Read and write all groups for Cloud PC assignments |
|
Organization.Read.All |
Read organization / tenant details |
|
User.ReadWrite.All |
Read and write all users' full profiles |
You need to be Global Admin in your Microsoft 365 tenant to grant these permissions. If you are not a Global Admin and need to request these permissions, you will not be able to add or provision a Cloud PC Task Runner until they have been granted.
If no one with Global Admin rights has access to the Change360 workspace you can send them this Url instead:
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=b2e8c112-d91b-486e-bb11-d2e866dd42c2&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&redirect_uri=https%3A%2F%2Frimo3cloud.com%2FCloudPcFeatureEnablement%2FConsentCallback
Windows 365 Licenses
Ensure your tenant has Windows 365 licenses (e.g. Windows 365 Business or Enterprise) available. Users who are assigned a Cloud PC must have an appropriate Windows 365 license. The wizard will show available SKUs and allow you to assign a license when creating a new user or provisioning a Cloud PC.
Prerequisites for linking existing Cloud PCs to your workspace
What needs to be setup before linking a Cloud PC
Before linking a Cloud PC to your workspace you will need to provision it via Intune or a CI/CD pipeline. Most importantly any Cloud PC you want to link to your workspace will need to be able to access the Gateway, therefore they will need to be provisioned using an Azure Network Connection that is:
- Directly linked to the Gateway's Vnet, or
- Linked to a Vnet which is directly peered to the Gateway's Vnet
Even if you can "ping" the Gateway VM from the Cloud PC, e.g. from another spoke Vnet, the service cannot validate that indirect connection and therefore the Cloud PC will not appear as useable in the Link Cloud PC wizard.
Microsoft Admin Consent
When you are linking existing Cloud PCs to your workspace Change360 only needs to be able to read information about your Cloud PCs, specifically it looks for:
- Provisioning Policies
- Azure Network Connections associated with the Provisioning Policies, and whether they are:
- Directly linked to the the Gateways Vnet
- Linked to a Vnet which is peered with the Gateway's Vnet
- All Cloud PCs
| Permission | Description |
| CloudPC.Read.All | Read Cloud PC status and information |
| DeviceManagementManagedDevices.Read.All | Read Microsoft Intune managed devices |
You need to be Global Admin in your Microsoft 365 tenant to grant these permissions. If you are not a Global Admin and need to request these permissions, you will not be able to add or provision a Cloud PC Task Runner until they have been granted.
If no one with Global Admin rights has access to the Change360 workspace you can send them this Url instead:
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=3181b058-7986-4f91-961b-70f333f11d5a&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&redirect_uri=https%3A%2F%2Frimo3cloud.com%2FCloudPcFeatureEnablement%2FConsentCallback