2.5 Azure Virtual Desktop
Key Takeaways
- Azure Virtual Desktop (AVD) is a cloud-based desktop and application virtualization service running on Azure infrastructure.
- AVD provides multi-session Windows 11/10 capability, which is unique to Azure and not available on-premises.
- Users can access their full Windows desktop from any device with an internet connection.
- AVD reduces costs through multi-session hosting and integrates with Microsoft 365 Apps for enterprise.
- Security features include Azure AD integration, MFA, RBAC, and Conditional Access policies.
Azure Virtual Desktop
Quick Answer: Azure Virtual Desktop (AVD) is a cloud-based virtual desktop and application virtualization service. It provides multi-session Windows 11/10 desktops hosted on Azure VMs, accessible from any device, with full Microsoft 365 integration.
What Is Azure Virtual Desktop?
Azure Virtual Desktop (AVD) — previously known as Windows Virtual Desktop (WVD) — is a desktop and application virtualization service that runs in the Azure cloud. It enables users to access a full Windows desktop experience from any device with a web browser or the AVD client application.
Key Capabilities
| Feature | Description |
|---|---|
| Multi-session Windows | Run Windows 11 or Windows 10 Enterprise multi-session — a capability unique to Azure (not available on-premises) |
| Full desktop | Provide users with a complete Windows desktop experience |
| Remote App | Publish individual applications rather than full desktops |
| Microsoft 365 integration | Optimized performance for Microsoft 365 Apps (Word, Excel, Teams) |
| Persistent or pooled | Choose persistent desktops (each user gets their own VM) or pooled desktops (users share VMs) |
Why Azure Virtual Desktop?
- Work from anywhere — Users access their desktop from any device, anywhere with internet
- BYOD support — Users can use personal devices securely
- Centralized management — IT manages all desktops from Azure
- Security — Data stays in the cloud, not on local devices
- Cost optimization — Multi-session hosting means fewer VMs for the same number of users
- Windows 11 multi-session — Only available on Azure (not available with on-premises Hyper-V)
Security Features
- Microsoft Entra ID integration for authentication
- Multi-factor authentication (MFA) and Conditional Access
- Role-based access control (RBAC) for management
- Reverse connect — No inbound ports need to be opened to the internet
- Data stays in Azure — Only screen pixels are transmitted to the client device
On the Exam: Remember that Windows 11/10 Enterprise multi-session is UNIQUE to Azure Virtual Desktop. This capability is not available on-premises or on other cloud providers. It allows multiple users to share a single Windows VM.
What capability is unique to Azure Virtual Desktop and not available on-premises?
Which of the following is a security benefit of Azure Virtual Desktop?