When connecting to Azure Virtual Desktop via a Windows-based Remote Desktop client (e.g. the native Microsoft Windows App) from a Windows endpoint, the user’s Microsoft Entra Primary Refresh Token (PRT) is handed off into the AVD session. This enables in-session single sign-on to Entra ID-integrated applications (e.g. automatic sign-in in Microsoft Edge) without any additional user interaction.
When connecting to the exact same AVD host pool and session host with the IGEL Azure Virtual Desktop app (currently v1.4.2, Build 1.0) from an IGEL OS endpoint (12.8.3 LTS), this PRT handoff does not happen. Even though:
enablerdsaadauth enabled, andapplications inside the session (e.g. Edge) have no per-user PRT available and cannot perform implicit/automatic sign-in. Users are forced to manually enter their email address every time.
IGEL support confirmed:
Microsoft Entra Primary Refresh Token (PRT) handoff into an AVD session is currently not supported with IGEL AVD/IGEL for Windows. This is due to an architectural limitation - modern Microsoft/Entra applications rely on MSAL and require an OS-level PRT with a true per-user execution context. Additional development would be required to support this scenario, and there is currently no ETA.
Requested feature:
Add support for Microsoft Entra PRT handoff (True SSO) into AVD/Windows 365 sessions launched from IGEL OS, so that in-session applications relying on Entra ID (Microsoft Edge, Office apps, etc.) can perform automatic sign-in — matching the behavior already available with the native Windows Remote Desktop client.
Benefit: