Modern Workplace consulting · Microsoft cloud architectureAdelaide, Australia
Enterprise architecture guide

Windows 365 enterprise design guide: when Cloud PCs fit

Choose the right personas, network model and operational controls for a secure Windows 365 service managed through Microsoft Intune.

Windows 365 provides a persistent personal Windows desktop as a cloud service. Microsoft manages the underlying compute platform while the organisation manages identity, licensing, provisioning policy, device configuration, applications, security and user support through Microsoft Intune and the wider Microsoft 365 control plane.

The service is strongest when the requirement is a predictable one-user-to-one-desktop experience and the organisation values operational simplicity more than low-level infrastructure control.

Where Cloud PCs fit

Contractors and partners

Provide a controlled corporate workspace without placing company data directly on an unmanaged personal device. Identity, Conditional Access and session controls still need careful design.

Merger and migration coexistence

Give selected users a target-tenant desktop while applications, identity and data move in stages. This can reduce local-device complexity but does not remove cross-tenant access planning.

High-risk or privileged roles

Separate administrative or sensitive work from the daily endpoint. Use a dedicated identity and strong controls; do not assume the Cloud PC is automatically a privileged access workstation.

Rapid workforce expansion

Provision a standard Windows environment without waiting for physical-device logistics, subject to licence, regional capacity, application and network readiness.

BYOD access

Keep managed applications and data inside a corporate Cloud PC while users connect from supported personal devices. Apply web, clipboard, drive and device-redirection controls according to risk.

Consistent specialist workspace

Provide a persistent desktop for applications that need a known configuration but do not require multi-session density or specialised Azure infrastructure.

Windows 365 or Azure Virtual Desktop?

Decision factorWindows 365Azure Virtual Desktop
Desktop relationshipPersistent personal Cloud PCPooled multi-session or personal host pools
Commercial modelPredictable per-user licence based on Cloud PC specificationAzure consumption plus relevant user licensing
Infrastructure controlMicrosoft manages the Cloud PC infrastructureCustomer designs and manages host pools, images, scaling and Azure resources
Operational complexityLower for standard personal-desktop scenariosHigher, with more flexibility and optimisation options
Multi-sessionNot the standard Enterprise modelCore pooled-host capability
Best fitPersonal desktops with simple, predictable operationsShared capacity, RemoteApp, specialised networking or granular Azure design
Decision principleChoose Windows 365 for service simplicity and predictable personal desktops. Choose Azure Virtual Desktop when session density, application publishing, infrastructure flexibility or consumption optimisation materially changes the outcome.

Choose the network model

Microsoft now recommends the Microsoft-hosted network for most deployments. It supports Microsoft Entra join and removes the need to operate an Azure virtual network for the Cloud PCs. Use an Azure Network Connection only when a genuine requirement—such as hybrid join, direct private connectivity, customer-controlled routing or fixed egress—cannot be met through a modern hosted-network pattern.

Windows 365 Microsoft-hosted network architecture showing a Cloud PC in a Microsoft-managed subscription with optional secure web gateway or VPN connectivity
Microsoft-hosted network keeps the Cloud PC and its network interface in Microsoft-managed infrastructure. Corporate access can be delivered through a device-based secure web gateway, private-access client or VPN. Image source: Microsoft Learn.
RequirementMicrosoft-hosted networkAzure Network Connection
Entra joinYesYes
Hybrid joinNoYes
Customer-managed VNetNoYes
Direct line of sight to on-premises resourcesUse VPN, secure web gateway or private-access clientCan use site-to-site VPN or ExpressRoute through the customer VNet
Operational overheadLowerHigher: routing, DNS, security, capacity and Azure operations remain customer responsibilities
Do not backhaul service trafficDesign split tunnelling so Windows 365 connection and Microsoft 365 traffic can use efficient paths. Backhauling through an on-premises data centre or overloaded security appliance can create latency and availability problems.

Prepare the service before assigning licences

  1. Define personas and specifications. Use application demand, concurrency, memory, storage and user experience—not job title alone—to select Cloud PC sizes.
  2. Confirm identity and administration. Use Entra groups, least-privileged Intune and Windows 365 roles, scope tags and privileged activation where appropriate.
  3. Select the network model and region. Prefer Microsoft-hosted network unless a documented dependency requires ANC. Validate data location, latency and service availability.
  4. Choose the image approach. Start with a gallery image when possible. Use a custom image only when configuration and app delivery cannot meet the requirement cleanly.
  5. Create provisioning policies. Separate policies by network, image, region and join model. Assign only to controlled pilot groups.
  6. Deploy policy and applications. Reuse the Windows 11 Intune baseline where suitable, but validate virtual-device settings, update behaviour, security clients and remote-session experience.
  7. Protect user data. Configure OneDrive Known Folder Move and appropriate retention or backup controls. Reprovisioning replaces the Cloud PC; it is not a data-recovery strategy.

Enterprise security baseline

  • Require phishing-resistant authentication for high-risk personas where practical.
  • Apply Conditional Access based on user, risk, client platform and session context.
  • Enroll Cloud PCs in Intune and onboard them to Microsoft Defender for Endpoint.
  • Apply BitLocker, antivirus, firewall, attack-surface-reduction and App Control requirements.
  • Remove permanent local administrator access; use Endpoint Privilege Management or controlled support processes.
  • Deploy secure web gateway, private-access or VPN clients with validated split-tunnel exclusions.
  • Control clipboard, drive, printer, USB and other redirection according to the use case.
  • Monitor sign-ins, Cloud PC health, device compliance and Defender risk together.

A Cloud PC is a managed Windows endpoint, not a trusted network location. Apply the same Zero Trust logic used for physical endpoints: verify identity, assess device posture, limit access, protect data and monitor continuously.

Build the operational model

EventRequired processEvidence
Provisioning failureCheck licence, group membership, policy assignment, region, image and network healthProvisioning status and audit records
Poor user experienceSeparate endpoint, local network, service path, Cloud PC resource and application causesResource performance, connection quality and Endpoint Analytics
Resize requestConfirm supported resize path, licence availability, user impact and rollbackApproved persona/specification record
ReprovisionConfirm user-data protection and application recovery before replacementReprovision record and post-build validation
Leaver or licence removalCoordinate access removal, data retention, grace periods and licence reclamationIdentity, device and service-management records
Service degradationCheck Microsoft service health, network dependencies and security-client health before broad remediationIncident timeline and communications

A controlled pilot

Week 1 — Foundation

Approve use cases, personas, architecture, licensing, security baseline, support ownership and success measures.

Week 2 — Technical build

Create groups and provisioning policies, deploy the image, apps, Intune policies, Defender and connectivity controls.

Week 3 — Friendly users

Validate provisioning, first sign-in, application performance, Microsoft 365 experience, peripherals, Teams media, security and support processes.

Week 4 — Operational proof

Test reprovision, restore of user data, resize, licence removal, incident triage, service communications and reporting.

  • Provisioning success meets the agreed target.
  • Sign-in and application performance are acceptable from representative locations.
  • Security controls apply without conflicting with the virtual desktop experience.
  • Support teams can distinguish local-device, connection, Cloud PC and application faults.
  • Cost and licence utilisation match the approved persona model.
  • Reprovisioning and user-data recovery are proven before production scale.

Microsoft references

  1. What is Windows 365?
  2. Windows 365 network deployment options
  3. Windows 365 architecture
  4. Create provisioning policies
  5. Windows 365 Enterprise requirements

Review note: Windows 365 licensing, regions, networking and service capabilities change. Validate the current Microsoft documentation before production design.