Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Intune»Configure Windows 365 context-based redirections
    Intune

    Configure Windows 365 context-based redirections

    Peter KlapwijkBy Peter KlapwijkJune 22, 2026Updated:June 22, 20265 Mins Read

    Microsoft recently announced the public preview of context-based redirections for Windows 365 Cloud PCs and AVD. This new feature is a welcome addition to how we control redirections of things like clipboard copy/ paste from the local device to the Cloud PC. Until now redirections were configured as blocked or allowed. It was just black or white. We didn’t have an option to allow redirections from a compliant device and block redirections from an unmanaged or not compliant device. With the new context-based redirections this is changed!

    Context-based redirection lets us dynamically control whether redirection is allowed in a remote session based on the trust level of the connecting device, using authentication context and Entra Conditional Access policies.

    We can apply authentication context to control the redirection of clipboard, drive, printer and USB.

    This means that we can setup a configuration that on a managed, compliant device the user gets full clipboard, drive, printer and USB redirection, while a BYOD or non-compliant device gets those redirections blocked, automatically.

    A very welcome addition on how we can control these redirections!

    Let us briefly walk through the steps to set this all up.

    Configure Redirections

    By default redirection of clipboard, drive, printer and USB is blocked, even without configuring this yourself with a policy. Make sure these redirections are configured as Not configured or Enabled as the most restrictive policy wins, as described on the Microsoft Docs.

    In my example I want to allow redirection of clipboard and printers from a compliant device, but want these blocked from unmanaged devices. Therefore I need to deploy an Intune Setting Catalog profile in which I configure the redirection of clipboard and printers to make sure these are allowed.

    For this, sign in to the Intune Admin center.
    Navigate to Devices, Windows, Configuration.
    Press Create, New policy.
    As platform select Windows 10 and later.
    As Profile type select Settings Catalog and press Create.
    Provide a Name and description (optional).

    Add  the following two settings to the profile:
    Do not allow client printer redirection
    Do not allow Clipboard redirection

    Set them both to Disabled.

    Finish configuring the Settings Catalog profile and make sure your (test) CPC are targeted by this policy.

    Configure Authentication context and conditional Access policy

    The next step we need to take is create a new Authentication context. An authentication context is a sort of tag, to connect the Conditional Access policy and the Cloud PC Settings policy to each other.

    A Authentication context can be created from the Entra admin center.

    Navigate to Entra ID, Conditional Access. Under Manage we find Authentication Contexts.

    Press New Authentication context.

    Enter a name and description (optional) for the new authentication context.
    Make sure a checkmark is set next to Publish to Apps and select an ID.
    Press Save.

    The next step is to configure a Conditional Access policy to enforce the context based redirection.
    In the CA policy we select the previously created authentication context and we require a compliant device.

    In the Entra admin center, still in the Conditional Acces section, navigate to Policies.

    Press New policy.

    Provide a name for the new Conditional Access policy.
    In User or agents, select the user group you want the CA policy to apply to.
    In Target Resources select Authentication context under Select what this policy applies to.
    Set a checkmark next to the previously created authentication context.

    In Grant, select Require device to be marked a compliant.

    Make sure the toggle Enable policy is set to On.
    Click Create.

    Configure Cloud PC Settings

    The last step in our configuration is to create a Windows 365 Remote Connection Experience policy, which is a new Cloud PC Settings policy.

    In this policy we configure the device redirections to make use of the authentication context.

    In the Intune admin center navigate to Devices, Cloud PC Settings, under Manage Windows 365 Cloud PCs.

    Press Create, Remote Connection Experience.
    Enter a name and description (optional) for the new policy.

    Under Device redirections we select Authentication context: Context-based redirection for Clipboard and Printer redirection. And for both settings we select the previously created authentication context.

    Assign the policy to a device group that contains the Windows 365 Cloud PCs.

    The end user experience

    The end user experience is that the clipboard and printer redirections are blocked when the user connects to the Cloud PC from an none compliant (unmanaged) device.

    But when the same user connects to the CPC from a compliant device, these redirections are allowed.

    On a picture it is hard to show the clipboard functionality does work, but I’m able to copy the data from my compliant device (on the left) to my CPC (on the right).

    A better example is printer redirection.

    On the left we see the original printer, connected to the compliant device.
    On the right we see the same printer, redirected to the Cloud PC.

    That’s it for this blog post.

    This is a welcome addition to the option we had for device redirection. If Microsoft provides us some more information about the status of the context redirection this feature will be even better. Because the policy does work fine, but from an administrative perspective we are in the dark if the policy is active.

    Happy testing!

    Conditional Access Intune Security Windows 365
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Managing Windows 365 Link devices with Intune

    October 24, 2025

    Setup a Windows 10 Multi App Kiosk device with Microsoft Intune

    August 6, 2019

    Enable WD SmartScreen in your browser with Intune

    August 2, 2018
    Add A Comment
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Why ‘Never persistent’ isn’t really never persistent: understanding browser sessions in Microsoft 365 Web Apps

    February 21, 2026

    Change a Microsoft 365 Apps installation from 32-bit to 64-bit

    January 30, 2026

    Intune PowerShell script installer feature

    January 17, 2026

    Configuring the time zone with Intune, what are our options?

    January 9, 2026
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    • Bluesky 1.5K
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Defender Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Windows Windows 10 Windows10 Windows 11 Windows 365 Windows Autopilot Windows Update
    Awards
    Sponsor
    Follow me on Twitter
    Tweets by inthecloud_247
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Defender Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Windows Windows 10 Windows10 Windows 11 Windows 365 Windows Autopilot Windows Update
    Archives
    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • peter on Install an additional language pack on Windows 11 during Autopilot enrollment
    • LoX on Using Visual Studio with Microsoft Endpoint Privilege Management, some notes
    • Alec Dombrowski on Build your own user onboarding automation: Send a notification when Windows 365 provisioning is finished
    • Alec Dombrowski on Build your own user onboarding automation: Send a notification when Windows 365 provisioning is finished
    • Lucien K on Change a Microsoft 365 Apps installation from 32-bit to 64-bit
    most popular

    Application installation issues; Download pending

    October 1, 2024

    How to change the Windows 11 language with Intune

    November 11, 2022

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How I solved a strange Kerberos issue

    December 12, 2024
    Recent Comments
    • peter on Install an additional language pack on Windows 11 during Autopilot enrollment
    • LoX on Using Visual Studio with Microsoft Endpoint Privilege Management, some notes
    • Alec Dombrowski on Build your own user onboarding automation: Send a notification when Windows 365 provisioning is finished
    • Alec Dombrowski on Build your own user onboarding automation: Send a notification when Windows 365 provisioning is finished
    • Lucien K on Change a Microsoft 365 Apps installation from 32-bit to 64-bit
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

    Copyright © 2023 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved. No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand: Don’t pass off my work as yours, it’s not nice.

    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS Bluesky
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}