A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
Hello @Andriy Vlasenko (International Supplier)
Thanks for reaching out, and I understand how blocking this is when you can't even open your clients' sites or install the VPN you need to work. The reassuring part: you haven't done anything wrong, and nothing is broken on your side.
On Azure Virtual Desktop, both web access and software installation are controlled centrally by your organization's IT policies. These can't be changed from inside the session which is exactly why the Local Group Policy Editor shows you have no rights: your account is a standard user, and editing local policy requires local Administrator membership (this is by design on AVD).
So this isn't something you can self-fix from the session but here's how to get unblocked quickly.
What's blocking you
- Websites – When every external site is blocked, it's a deliberate "deny-all outbound except approved" baseline, enforced by Azure Firewall (application rules / web categories), a proxy / secure web gateway, an NSG, or a GPO proxy setting. Your admins can add the specific sites you need to the allow-list.
- Azure VPN client install – This is blocked by application control (App Control for Business / AppLocker) and/or the lack of local admin rights. An admin can allow the app or deliver it for you via Intune.
Your fastest path: send your IT/AVD admin this request
"On our AVD host pool, please:1. Allow outbound access to these sites: [list the exact client URLs/domains].2. Allow installation of the Azure VPN client (business reason: [your reason]), or deploy it via Intune.I'm a standard user and can't change these from the session. Screenshots of the block messages are attached."
Links:
https://learn.microsoft.com/en-us/azure/firewall/protect-azure-virtual-desktop
https://learn.microsoft.com/en-us/azure/firewall/web-categories
https://learn.microsoft.com/en-us/azure/virtual-desktop/security-recommendations
Thanks,
Manish.