Schedule a call

Azure Virtual Desktop

Ten reasons to use Azure Virtual Desktop, and three not to

Cloud Kings

Most lists of reasons to use Azure Virtual Desktop are written by people selling it, so every reason is a benefit and none has a caveat. That is not useful when you are deciding whether to spend money.

Here are ten genuine reasons, each with the condition attached that decides whether it applies to you — and then three situations where the honest answer is that this is the wrong tool.

1. Your data stops living on laptops

The strongest reason by a distance. A laptop is a copy of your working environment that leaves the building; a virtual desktop is a window onto one that does not. Lose the device and you have lost hardware, not data.

The condition: this only matters if where your data currently sits actually worries you. If it does not, most of the rest of this list is secondary.

2. Onboarding and offboarding become fast

Access is granted and revoked centrally rather than by shipping a machine and, later, chasing it. For anyone who takes on contractors or seasonal staff, this is the benefit felt weekly.

The condition: only if your identity setup is in order. Without that, you have moved the problem rather than solved it.

3. Everyone gets the same environment

Built once, patched once. No more machines that are subtly different because of something that happened to them years ago and was never documented.

The condition: someone has to own the image. Left alone, it drifts, and you have recreated the problem in a new place.

4. Old hardware stays useful

Performance comes from Azure rather than the device, so the refresh cycle lengthens and a five-year-old laptop stops being a support burden.

The condition: this is a saving on a future purchase, not money back today.

5. Bring-your-own-device becomes defensible

Personal devices can access a corporate desktop without corporate data landing on them. Whether or not BYOD is your policy, it is probably already your reality.

The condition: the endpoint still needs to be healthy enough to be trusted with a session.

6. It scales in both directions

Capacity follows demand. Take on twenty people for a project and give them desktops the same week; release them and stop paying.

The condition: the downward direction only works if you configure it. Scaling that was never set up is just a bill.

7. Patching stops being a fleet problem

Update the hosts rather than chasing thirty machines that are each three versions behind and one of which is always switched off.

The condition: it does not patch itself. It concentrates the work rather than removing it.

8. Access can be conditioned properly

Because sign-in goes through your identity provider, you can require managed devices, compliant locations or stronger authentication before a desktop opens at all. That is considerably better than a VPN that lets anything on the network once it has a password.

The condition: this benefit is entirely a function of how conditional access is configured. Deployed with defaults, it is not there.

9. Business continuity improves almost incidentally

An office that becomes unusable stops being a crisis. People work from anywhere with a connection, using the same environment as yesterday.

The condition: it is not a backup or a recovery plan. If the environment is your whole estate, it needs backing up and the recovery needs rehearsing, just like anything else.

10. It fits compliance work unusually well

For defense contractors, deployed in Azure Government with a designed CUI boundary, controlled data never touches an endpoint. That removes a category of risk and a category of evidence you would otherwise have to produce about how endpoints are managed, encrypted and wiped.

The condition: it is not compliant by default. The boundary design is what makes it so, and it comes first. See the shared responsibility matrix for which of those controls are yours rather than a provider’s.


And three reasons not to

1. Your people work where there is no connection. The desktop is in Azure. No connection, no desktop. Field engineers, sites with poor coverage and anyone who works on aircraft are the wrong users for this, and no amount of design changes that.

2. The work is graphics-heavy or latency-sensitive. CAD, video editing, anything where a few milliseconds are visible in the output. It can be done with GPU-backed hosts, at a cost that needs justifying rather than assumed.

3. Nothing is actually wrong. If a team of ten has working laptops, no compliance obligation and no security concern about where files sit, this is a solution looking for a problem. We would rather say so than sell it — that sentence has cost us work before and it will again.

Where to start if it does fit

Application compatibility is the first question and the one that most often changes the plan. Anything old, anything with a hardware dongle, and anything licensed per machine wants checking before a design exists, not after.

Then a pilot group of real users, then a staged rollout. Moving everyone at once is possible and is usually how the problems get discovered at the worst moment.

The detail of what a deployment involves is on our Azure Virtual Desktop page, and if you want the plain explanation first, start with what Azure Virtual Desktop actually is.

If you would rather just ask someone, schedule a call. Twenty minutes, and we will tell you if the answer is no.

Frequently asked

What is the single strongest reason to deploy Azure Virtual Desktop?
That company data stops living on laptops. Every other benefit — consistency, onboarding speed, hardware costs — is real but secondary. If nothing about where your data currently sits worries you, the case is much weaker.
Will Azure Virtual Desktop save us money?
Sometimes, and not automatically. It converts a capital cost into a running cost, and the saving depends on hosts shutting down when nobody is using them. A deployment that runs constantly because scaling was never configured usually costs more than the laptops it replaced.
Can we move everyone at once?
You can, and it is usually a mistake. Application compatibility is the thing that changes plans, and it is better discovered by a pilot group of real users than by an entire company on a Monday morning.
Does it replace our backup and disaster recovery?
No. Centralising desktops removes some risk and concentrates the rest. If the environment is your whole working estate, it needs backing up and the recovery needs rehearsing, exactly as an on-premises estate would.

Continue reading

  • What CMMC Level 2 actually costs

    The five things you are actually paying for, why scope moves the number more than anything else, and why we will not publish a figure.

  • Your SPRS score, and why it is negative

    How the NIST SP 800-171 self-assessment score is calculated, why a negative number is normal rather than alarming, and who is actually reading it.

Keep in the loop