JIT for RDP with Windows 11 AVD Pools

Ray German 0 Reputation points
2025-10-20T16:44:08.01+00:00

Hello,

I am a newbie and set up my first Azure testing environment to see if Azure Virtual Desktop Pools will work for a new company project.

I set up a Workspace pool and will need RDP access for testing and eventually for users if my tests are successful. All of the users would be accessing Windows 11 desktops via Pools.

Security is a concern with RDP, and for my specific need, which requires Multimedia Redirect, it appears my best option is JIT.

Can you suggest the best option to achieve RDP access via JIT for Windows 11 Desktops?

As I mentioned, the Microsoft Tenant I am using is a test tenant. I have a separate tenant for our business, which has a CSP Microsoft Apps for Business Subscription.

Let me know what you think.

Thanks,

Ray

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. hossein jalilian 13,280 Reputation points Volunteer Moderator
    2025-10-20T17:54:41.49+00:00

    Hi Ray German,

    Thanks for posting your question in the Microsoft Q&A forum.

    The most secure and practical way to allow RDP access to Azure AVD session hosts especially for testing or troubleshooting, is to use JIT VM access through Microsoft Defender for Cloud. By default, AVD doesn’t expose RDP ports to the internet because it uses a secure Reverse Connect method, so users connect safely through the AVD client.

    When you do need direct RDP, JIT temporarily opens port 3389 only for a limited time and only from specific IPs. This keeps the VMs protected from constant exposure and attacks. It works in both test and production environments as long as Defender for Cloud is enabled.


    Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.