Permissions
PSCloudPC calls Microsoft Graph, so the signed-in account or app registration needs the following Microsoft Graph permissions:
- Delegated permissions for interactive and device code sign-in.
- Application permissions for an app registration that uses a client secret or certificate.
| Permission | Used for |
|---|---|
CloudPC.ReadWrite.All | Cloud PCs, policies, images, network connections and remote actions |
DeviceManagementConfiguration.ReadWrite.All | Policy assignments and configuration |
DeviceManagementManagedDevices.ReadWrite.All | Managed device operations |
Directory.Read.All | Resolving users and groups |
Delegated sign-in
For interactive and device code sign-in, Connect-Windows365 requests the permissions above when you sign in. Depending on your tenant's consent settings, an administrator might need to grant consent once.
Delegated access is also limited by the signed-in user's role. Use a Microsoft Entra role that can manage Windows 365, such as Windows 365 Administrator or Intune Administrator.
App registration
To run PSCloudPC unattended:
- In the Microsoft Entra admin center, go to App registrations and create a new registration.
- Under API permissions, add the Microsoft Graph application permissions listed above.
- Select Grant admin consent.
- Under Certificates & secrets, upload a certificate (recommended) or create a client secret.
- Connect with the client certificate or client secret method, using the application (client) ID and your tenant ID.
Individual cmdlets list the Graph endpoint and permissions they use in the Notes section of their help, see the cmdlet reference.