Areas assessed
- Microsoft Entra ID and phishing-resistant authentication with passkeys/FIDO2 or Windows Hello for Business, enforced through Conditional Access where appropriate.
- Roles, administrator accounts and least privilege.
- Network segmentation, outbound traffic and private connectivity where appropriate.
- Session host hardening, updates and security configuration.
- Device and redirection policies for the clipboard, drives, printers and USB.
- Logging, alerts, incident handling and recovery procedures.
- Protection of profiles, data and management information.
Secure and practical
A control that users routinely bypass provides a false sense of security. Policies are therefore tested with different roles and devices. Exceptions are documented, assigned an owner and expiry date, and reassessed periodically.
Outcomes
Outcomes
An overview of risks and controls, a prioritised improvement plan, documented management boundaries and evidenced tests of access and critical recovery procedures. Security remains an ongoing process rather than a single delivery milestone.
Technology
Technology used in these services
- Azure Virtual Desktop
- Microsoft Entra ID
Frequently asked questions
Is multifactor authentication sufficient for AVD?
No. It is an important baseline control, but must be combined with appropriate access policies, secure administrative accounts, updated session hosts, network controls, monitoring and recovery.