Primary expertise

Azure Virtual Desktop: the modern Windows desktop with Microsoft Azure

Azure Virtual Desktop is Microsoft's service for full Windows desktops and individual applications. The control plane runs in Azure; session hosts can run in Azure or, in supported Azure Virtual Desktop Hybrid scenarios, on your own infrastructure through Azure Arc. suXus helps organisations use the service responsibly, from feasibility and architecture to migration, management and optimisation.

A complete desktop environment, beyond individual virtual machines

A reliable AVD environment connects Microsoft Entra ID, access policies, networks, session hosts, images, applications, FSLogix profiles, storage, monitoring and management. A fault in one layer can result in slow sign-ins, unstable profiles, unnecessary Azure costs or users being unable to work.

suXus designs these components as a coherent whole. We consider the target environment alongside existing applications, peripherals, dependencies, management processes and continuity.

What suXus delivers

  • An assessment of user groups, applications, data flows and technical dependencies.
  • Selection of pooled or personal host pools, and full desktops or RemoteApp.
  • Design of identity, Conditional Access, network segmentation and administrative access.
  • Image, application and update management.
  • FSLogix profile design and appropriate storage.
  • Capacity planning, autoscaling where supported, monitoring and cost control.
  • Pilot deployment, migration, acceptance, documentation and handover.
  • Technical management and regular optimisation after go-live.

When is AVD a good fit?

AVD often suits organisations with changing capacity requirements, remote or hybrid users, centralised applications, shared desktops or specific management and access requirements. Windows 365 may be a better fit for a dedicated personal Cloud PC with simpler capacity management. The choice follows usage, management needs, costs and risks, rather than a preference for a particular product.

Technical architecture

From access to demonstrated recovery

The layers below show, in a logical reading order, how users reach their desktops through identity and the AVD platform, with management and protection across the entire chain.

  1. 01

    Users and devices

    • Employees and external users
    • Managed and suitable devices
    • AVD client or web access
  2. 02

    Identity and access

    • Microsoft Entra ID
    • MFA and Conditional Access
    • Roles and administrative access
  3. 03

    Azure Virtual Desktop

    AVD control plane

    Broker, gateway, web access and diagnostics.

    Host pools

    Pooled or personal, with suitable capacity and autoscaling.

    Session hosts

    Windows sessions, application groups and desktop assignment.

  4. 04

    Desktop foundation

    • Images and applicationsVersions, updates and controlled rollout
    • FSLogix and profile storageProfile containers, performance and availability
    • Network and connectivitySegmentation, DNS, private access and dependencies
  5. 05

    Management, protection and recovery

    • Monitoring and managementHealth, capacity, costs, changes and reporting
    • Protection and backupConfiguration, data, profiles and recoverable copies
    • Recovery and continuityRecovery objectives, procedures, tests and responsibilities

Responsibilities

Clearly defined responsibilities

Microsoft manages the AVD control plane. The customer and its management partner remain responsible for Azure resources, session hosts, images, applications, identity, access policies, data, monitoring and user acceptance, among other things. suXus documents this division for each environment so that critical tasks do not fall between the parties.

Outcomes

Measurable results

Before we start, we define measures such as sign-in time, session stability, application availability, user density, Azure consumption, patch status and incident handling. After the pilot and after go-live, we report against the same measures. This shows what has improved and where further optimisation is needed.

Technology

Technology used in these services

  • Microsoft Azure
  • Azure Virtual Desktop
  • Microsoft Entra ID
  • FSLogix

Frequently asked questions

Can Azure Virtual Desktop replace an on-premises RDS environment?

Often, yes. Applications, profiles, printers, peripherals, network connections, identities and licences must be assessed first.

Can suXus manage an existing AVD environment?

Yes. We first carry out a technical baseline assessment, then agree the management scope, priorities, reporting and change procedures.

Is AVD always cheaper than an on-premises desktop?

No. Costs depend on capacity, usage hours, storage, network traffic, licences, management and architecture. Appropriate configuration and active cost management are essential.

Services

Explore this topic

Discuss your environment

Book a technical assessment with suXus.