{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
        "slug": "dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/"
        },
        "title": "Check every app relationship's install context on multi-session desktops",
        "summary": "Why can a system-context Intune app still fail to install on an Azure Virtual Desktop multi-session VM?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:57+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 239,
        "potentially_affected": "Apply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune's multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.",
        "dse_recommendation": "Review the complete app relationship graph before changing the parent assignment.",
        "primary_source": {
            "name": "Using Azure Virtual Desktop multi-session with Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune requires apps for Windows Enterprise multi-session to install in system or device context and target devices. Only Required and Uninstall assignment intents are supported, not Available. A system-context Win32 app will not install if a dependency or supersedence relationship points to a user-context app. Microsoft recommends a separate system-context instance or making all dependencies system-context. <a href=\"https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune&#8217;s multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.</p>\n<h2>DSE recommendation</h2>\n<p>Review the complete app relationship graph before changing the parent assignment. List each dependency and superseded app with its configured install context. Identify the intended device group and assignment intent. If a user-context relationship is present, design and test the supported system-context package arrangement with the application owner. Do not assume that changing only the parent app&#8217;s context resolves its linked packages or preserves the intended application behavior.</p>\n<h2>Verification</h2>\n<p>In an approved multi-session test pool, confirm the effective assignments and the context of every linked app before checking installation results. Exercise the application with the intended users and retain the dependency outcomes, not only the parent&#8217;s status. Keep any separate package instance clearly identified in the handoff. If an app still fails, investigate its actual relationship and installation evidence before widening its target population.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Using Azure Virtual Desktop multi-session with Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nIntune requires apps for Windows Enterprise multi-session to install in system or device context and target devices. Only Required and Uninstall assignment intents are supported, not Available. A system-context Win32 app will not install if a dependency or supersedence relationship points to a user-context app. Microsoft recommends a separate system-context instance or making all dependencies system-context. Microsoft Learn.\nApplicability\nApply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune’s multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.\nDSE recommendation\nReview the complete app relationship graph before changing the parent assignment. List each dependency and superseded app with its configured install context. Identify the intended device group and assignment intent. If a user-context relationship is present, design and test the supported system-context package arrangement with the application owner. Do not assume that changing only the parent app’s context resolves its linked packages or preserves the intended application behavior.\nVerification\nIn an approved multi-session test pool, confirm the effective assignments and the context of every linked app before checking installation results. Exercise the application with the intended users and retain the dependency outcomes, not only the parent’s status. Keep any separate package instance clearly identified in the handoff. If an app still fails, investigate its actual relationship and installation evidence before widening its target population.\nOfficial references\nMicrosoft Learn: Using Azure Virtual Desktop multi-session with Microsoft Intune.",
        "content_markdown": "## Source facts\n\nIntune requires apps for Windows Enterprise multi-session to install in system or device context and target devices. Only Required and Uninstall assignment intents are supported, not Available. A system-context Win32 app will not install if a dependency or supersedence relationship points to a user-context app. Microsoft recommends a separate system-context instance or making all dependencies system-context. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session).\n\n## Applicability\n\nApply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune’s multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.\n\n## DSE recommendation\n\nReview the complete app relationship graph before changing the parent assignment. List each dependency and superseded app with its configured install context. Identify the intended device group and assignment intent. If a user-context relationship is present, design and test the supported system-context package arrangement with the application owner. Do not assume that changing only the parent app’s context resolves its linked packages or preserves the intended application behavior.\n\n## Verification\n\nIn an approved multi-session test pool, confirm the effective assignments and the context of every linked app before checking installation results. Exercise the application with the intended users and retain the dependency outcomes, not only the parent’s status. Keep any separate package instance clearly identified in the handoff. If an app still fails, investigate its actual relationship and installation evidence before widening its target population.\n\n## Official references\n\n[Microsoft Learn: Using Azure Virtual Desktop multi-session with Microsoft Intune](https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check every app relationship's install context on multi-session desktops",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/",
                "headline": "Check every app relationship's install context on multi-session desktops",
                "description": "Why can a system-context Intune app still fail to install on an Azure Virtual Desktop multi-session VM?",
                "abstract": "Why can a system-context Intune app still fail to install on an Azure Virtual Desktop multi-session VM?",
                "articleBody": "Source facts\nIntune requires apps for Windows Enterprise multi-session to install in system or device context and target devices. Only Required and Uninstall assignment intents are supported, not Available. A system-context Win32 app will not install if a dependency or supersedence relationship points to a user-context app. Microsoft recommends a separate system-context instance or making all dependencies system-context. Microsoft Learn.\nApplicability\nApply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune’s multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.\nDSE recommendation\nReview the complete app relationship graph before changing the parent assignment. List each dependency and superseded app with its configured install context. Identify the intended device group and assignment intent. If a user-context relationship is present, design and test the supported system-context package arrangement with the application owner. Do not assume that changing only the parent app’s context resolves its linked packages or preserves the intended application behavior.\nVerification\nIn an approved multi-session test pool, confirm the effective assignments and the context of every linked app before checking installation results. Exercise the application with the intended users and retain the dependency outcomes, not only the parent’s status. Keep any separate package instance clearly identified in the handoff. If an app still fails, investigate its actual relationship and installation evidence before widening its target population.\nOfficial references\nMicrosoft Learn: Using Azure Virtual Desktop multi-session with Microsoft Intune.",
                "datePublished": "2026-09-10T00:24:57+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check every app relationship's install context on multi-session desktops"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 239,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Using Azure Virtual Desktop multi-session with Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session"
                }
            }
        ]
    }
}