Schedule a call

Azure Virtual Desktop

What is Azure Virtual Desktop?

Cloud Kings

Azure Virtual Desktop is a Windows desktop that runs in Microsoft Azure and is streamed to whatever device you are sitting in front of. The device becomes a screen and a keyboard. The desktop, the applications and the data stay in your tenant.

That sentence covers what it is. What it is for is the more useful question, and so is when it is the wrong answer — which is the part most explanations skip.

The problem it actually solves

For most businesses the problem is not that people want to work from home. It is that when they do, the company’s data goes with them.

A laptop is a copy of your working environment that walks out of the building. It gets left in cars and airports. Its local disk fills with documents nobody has inventoried. When someone leaves, the company’s data is in their bag until somebody remembers to collect the machine.

A virtual desktop inverts that. Nothing is copied to the endpoint, so the laptop stops being a repository and becomes a window. Lose it and you have lost a piece of hardware rather than suffered a data incident.

The second thing it solves is consistency. Everyone gets the same environment, built once and patched once, rather than thirty machines that have each drifted in their own direction since the day they were issued.

How it differs from things it gets confused with

A VPN connects a device to your network. The device is still the device — still holds files, still needs managing, still the weak point. A VPN extends your network out to an endpoint you do not fully control. A virtual desktop does the opposite: the work stays inside and you are shown a picture of it.

Windows 365 is Microsoft’s simpler take on the same idea. Each user gets a dedicated Cloud PC at a fixed price per user per month. Easier to buy, easier to budget, harder to get wrong — but less flexible, and usually more expensive once you have a lot of users.

Azure Virtual Desktop is the infrastructure version. You size the hosts, choose whether users get their own machine or share a multi-session one, and pay for the compute you consume. More control, more capability, and more that has to be got right.

An honest way to choose between the two: if you cannot articulate why you need multi-session hosts or fine control over sizing, Windows 365 is probably the better purchase.

When it is the right answer

  • People work from several places or several devices, and you would rather the environment followed them than the files did.
  • You take on contractors or seasonal staff and need to grant access quickly and remove it cleanly.
  • The data genuinely should not sit on endpoints, for compliance reasons or because of what it is.
  • You are supporting a mixed estate of ageing hardware and want performance to stop being a function of who has the newest laptop.
  • Bring-your-own-device is already happening, whether or not it is policy.

When it is not

This is where most vendor explanations stop being useful, so:

  • Anyone who regularly works without connectivity. The desktop is in Azure. No connection, no desktop. Field staff are often the worst fit.
  • Graphics-heavy or latency-sensitive work. CAD, video editing, anything where a few milliseconds are visible in the output. It can be done with GPU-backed hosts, at a cost that needs justifying rather than assuming.
  • Specialist attached hardware. Dongles, scanners, badge printers and instruments bound to a physical machine are a source of friction and occasionally a blocker.
  • Small teams where nothing is actually wrong. If ten people have working laptops and no compliance driver, this is a solution in search of a problem.

What it costs, honestly

It trades a capital cost for a running cost, and it is not automatically cheaper.

You stop buying powerful laptops on a refresh cycle and start paying for Azure compute every month. Whether that nets out as a saving depends almost entirely on whether hosts shut down when nobody is using them. A deployment where usage follows working hours and hosts scale down overnight can be markedly cheaper. One where everything runs constantly because scaling was never configured usually is not.

Sizing is the other half of it. Capacity should be planned against concurrent usage rather than headcount — forty staff who all work nine to five need more than a hundred spread across shifts — and sizing against the wrong number is the most common way this gets expensive.

The compliance case

For defense contractors this is where it becomes genuinely interesting.

Deployed in Azure Government alongside a properly designed CUI boundary, a virtual desktop means controlled information never lands on an endpoint. That removes a whole category of risk, and just as usefully a whole category of evidence you would otherwise have to produce about how endpoints are controlled, encrypted, inventoried and wiped.

It is not compliant out of the box. Nothing is. The boundary design is what makes it so, which is why that work comes before the deployment rather than after it. Our shared responsibility matrix sets out which of those controls typically sit with a provider and which stay with you.

Where to go next

For the shape of an actual deployment — what gets assessed, what gets built, and what people underestimate — see our Azure Virtual Desktop page. If the driver is CUI rather than convenience, start with CMMC compliance instead, because the boundary decision comes first and everything else follows it.

And if you are not sure whether this is the right tool for your situation, that is a twenty-minute conversation rather than a project. Schedule a call — we will tell you plainly if it is not.

Frequently asked

Is Azure Virtual Desktop the same as Windows 365?
No, though they solve a similar problem. Windows 365 gives each user a dedicated Cloud PC at a fixed monthly price per user — simple to buy and simple to predict. Azure Virtual Desktop is consumption-based infrastructure you size and manage yourself, including multi-session hosts where several users share one machine. AVD is more flexible and usually cheaper at scale; Windows 365 is easier to run and easier to budget.
Does Azure Virtual Desktop work without an internet connection?
No. The desktop runs in Azure and is streamed to the device in front of you, so a working connection is required. If your people regularly work somewhere with no connectivity, a virtual desktop is the wrong tool for those users.
Do we still need laptops?
Yes, but they matter far less. Performance comes from Azure rather than the device, so a cheaper or older machine stays useful for longer. What changes is that the device stops being where your data lives.
Can Azure Virtual Desktop be used for CUI and CMMC work?
Yes — deployed in Azure Government alongside a properly designed CUI boundary. It suits that work because controlled data never lands on the endpoint, which removes a category of risk and a category of evidence you would otherwise have to produce. It is not compliant by default; the boundary design is what makes it so.
Is it cheaper than buying laptops?
Not automatically. It trades a capital cost for a running cost, and that running cost depends on how many hosts you have and how long they stay switched on. The saving is real when usage patterns let hosts shut down outside working hours, and disappears when everything runs constantly because nobody configured scaling.

Continue reading

  • What CMMC Level 2 actually costs

    The five things you are actually paying for, why scope moves the number more than anything else, and why we will not publish a figure.

  • Your SPRS score, and why it is negative

    How the NIST SP 800-171 self-assessment score is calculated, why a negative number is normal rather than alarming, and who is actually reading it.

Keep in the loop