Managing sound and video settings during Teams meetings and calls for optimal communication
Dear @Jim Bennett
I understand how frustrating it is when daily Microsoft Teams updates repeatedly reset client-side microphone permissions across your VMware/Omnissa VDI environment.
This is a known issue related to the new Teams VDI architecture (SlimCore) during rapid update cycles. New VDI Solution for Teams Architecture Provides an overview of the SlimCore media engine architecture, system requirements, and deployment principles across VDI environments.
With the new SlimCore optimization architecture, Microsoft Teams registers a local media plugin on the physical client endpoint (appearing under Windows App Privacy settings as Microsoft Teams VDI or Microsoft Teams VDI Optimizer).
Because Microsoft frequently pushes auto-updates to the Teams VDI client and SlimCore components, Windows treats each update as a modified or re-registered application binary. When Windows OS detects an app update without an enforced privacy policy, it defaults security permissions back to Off for safety.
Option 1: Enforce Client-Side Microphone Permissions via Group Policy
Instead of relying on end-users to manually toggle privacy settings, push a Domain Group Policy (GPO) or Intune configuration profile to your physical endpoint devices to permanently allow microphone access:
- GPO Path:
Computer Configuration > Administrative Templates > Windows Components > App Privacy - Policy Setting: Let Windows apps access the microphone
- Configuration: Set to Enabled, and under Options, set Default for all apps to Force Allow (or explicitly set desktop app access to Allow).
This overrides Windows' behavior of resetting permissions back to "Off" whenever SlimCore binaries update.
Please refer to this document for step by step: Windows Privacy Compliance: A Guide for IT and Compliance Professionals
Option 2: Manage Teams VDI Update Cadence
If your VDI environment is receiving updates daily or multiple times a day, check your Teams Update Policies in the Microsoft Teams Admin Center:
- Go to Admin Center > Teams Admin Center > Teams policies > Update policies.
- Adjust the update channel (e.g., move non-pilot users from Current Channel (Preview) to General) to reduce the update frequency and prevent constant re-registration of the SlimCore plugin.
For further technical details on how SlimCore interacts with local endpoint permissions, you can refer to Microsoft's official guide: Use Microsoft Teams on Azure Virtual Desktop
Please let me know if applying the App Privacy GPO resolves the issue for your endpoints.
If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in the forum document to enable e-mail notifications if you want to receive the related email notification for this thread.