All servicesCitrix to Azure Virtual Desktop Migration

Citrix to Azure Virtual Desktop Migration

Citrix estates of 1,000 seats or more moved to Azure Virtual Desktop as a governed programme, by our certified UK team.

Request a call

Citrix to Azure Virtual Desktop, run as a programme

In short: A programme for moving Citrix estates of 1,000 seats or more to Azure Virtual Desktop: assess, design, pilot, migrate in waves while Citrix keeps serving everyone not yet moved, then hand over or keep running it. Delivered by our certified UK team under ISO 27001 and ISO 9001. The decision that matters is the order: inventory and test the applications before anyone commits to a cutover date.

In a large Citrix estate the desktops are rarely the hard part. The hard part is the long tail of published applications, profiles and peripherals that grew with the organisation over the years, and a migration date that gets set before anyone has counted them.

Who this is for

You run Citrix for 1,000 or more users and are choosing a partner to move the estate to Azure Virtual Desktop
A Citrix release you depend on is approaching the end-of-life date in Citrix's own lifecycle, and you need a plan either way
You need the migration run as a programme, with governance, named roles and waves, not as a technical build

The problem

Citrix estates of this size grew over years: delivery groups added department by department, images forked for one site or one team, applications published for a project and never retired, profiles carrying a decade of settings. Each of those made sense at the time. Together they mean nobody holds a complete list of what users actually depend on, and a migration that starts without that list finds it out one service desk call at a time, after cutover.

What we would do

Run it as a programme, not a platform swap. Microsoft runs Azure Virtual Desktop's broker and gateway as a service and you manage only the images and session hosts in your subscription, so new host pools are built, images and profiles are moved or rebuilt, and applications are repackaged or reinstalled. Inventory and test the applications first, prove the design with a pilot, then move users in waves while Citrix keeps serving everyone else.

  • If some teams need a personal desktop with a fixed monthly price rather than a shared one, Windows 365 may suit that part of the estate better, and the assessment will say so.
  • If applications have to stay close to on-premises databases or file servers, AVD Hybrid or a staged move is often the safer route.

When we are not the answer: If the assessment finds a capability your users depend on that Azure Virtual Desktop does not provide, the honest answer is to stay on Citrix and renew on the best terms you can, and we will put that in writing. And if what you need is a short extension to buy time, that is a conversation with Citrix, not a migration.

We run Citrix to Azure Virtual Desktop migrations for estates of 1,000 seats and more in five stages: assess, design, pilot, migrate in waves, and run. Each stage is scoped and signed off before the next begins, and the programme has named owners on both sides from the first week. Citrix keeps serving every user who has not yet moved, so nothing is switched over in a single night.

More on how we deliver Citrix to AVD migration

The work is carried out by our certified UK team under ISO 27001 and ISO 9001, with engineers certified to AZ-140, Microsoft's Azure Virtual Desktop specialty exam. The recommendation is not tied to one platform: where Windows 365, AVD Hybrid or staying on Citrix is the better answer for part of the estate, the assessment says so in writing.

Everything you need, managed for you

Discovery of published applications, desktops, users, sites and peripherals across the Citrix estate
Application compatibility testing, with a delivery route for each application: image, Intune or App Attach
MSIX and App-V packages for App Attach, signed, catalogued and assigned per user
Landing zone, host pool, image pipeline and autoscale design for Azure Virtual Desktop
Identity design with Microsoft Entra ID, hybrid identity, single sign-on and Conditional Access
FSLogix profile container design on Azure Files or Azure NetApp Files
Pilot, wave planning and cutover, with Citrix running alongside until each wave signs off
Handover with as-built design, runbooks and knowledge transfer, or ongoing running by our team

Why do organisations move from Citrix to Azure Virtual Desktop?

Usually for a combination of reasons, and the strongest come from how Azure Virtual Desktop is built rather than from anything Citrix does wrong. Citrix remains a capable platform, and a move only makes sense where these reasons outweigh the work of the migration itself.

The capabilities Microsoft documents for Azure Virtual Desktop:

  • The service runs the gateway and broker roles. You manage the images and virtual machines in your subscription, not the supporting infrastructure.
  • Windows 11 and Windows 10 Enterprise multi-session, which Microsoft describes as exclusive to Azure Virtual Desktop, so many users share one virtual machine.
  • Autoscale that adds and removes capacity by time of day, day of the week or demand.
  • User access rights included in licences many organisations already hold, such as Microsoft 365 E3, E5, F3 and Business Premium, with Azure compute and storage paid for as you use them.
  • Connections made through reverse connect to the service, so no inbound ports are opened.

Timing usually comes from the Citrix side. Citrix publishes an end-of-life date for each release in its product lifecycle matrix: Citrix Virtual Apps and Desktops 2203 LTSR, for example, reaches end of life on 23 March 2027, with extended support for eligible customers. A date like that is a decision point, whether the decision is to upgrade Citrix or to move, and a programme of this size needs to start well before it.

How does a Citrix to AVD migration run as a programme?

In five stages, each with its own scope, exit criteria and sign-off. Microsoft runs Azure Virtual Desktop's broker and gateway as a service, and you manage only the images and session host virtual machines in your own subscription, so the move is a rebuild rather than a conversion: new host pools are built, golden images are brought into Azure or rebuilt, profiles are migrated or rebuilt, and applications are delivered through App Attach or installed in the image.

Five stages of a Citrix to Azure Virtual Desktop migration: assess, design, pilot, migrate in waves with Citrix still available, then run or hand over.
Each stage has its own scope, exit criteria and written sign-off before the next begins.

The five stages:

Assess
inventory every published application and desktop, who uses it, from where and on what device, and measure peak concurrency.
Design
landing zone, host pools, images, identity, profiles, application delivery, networking and the wave plan.
Pilot
a representative group of users on the new platform, chosen to include the awkward applications, peripherals and sites rather than the easy ones.
Migrate in waves
groups of users move on agreed dates, with Citrix still available to them until their wave is signed off.
Run
handover to your team with runbooks and training, or ongoing running and optimisation by ours.

Assessment is where large migrations are won or lost. Microsoft notes that services such as Azure Migrate can help assess existing infrastructure and dependencies, but the session hosts themselves are always new, so the work that matters is knowing exactly what has to run on them.

What does the assessment cover in a large Citrix estate?

Everything a user would notice if it stopped working. We start from what Citrix actually publishes and who launches it, because in an estate that has grown over years the published list and the used list are rarely the same.

Illustration of a Citrix estate's published applications: an application published for one team with no owner recorded, profiles carrying years of settings, and printing and smart cards not yet tested.
Estates of this size grew over years. The work that decides the dates is counting what users actually depend on before cutover, not after it.

The assessment produces:

  • An application inventory with owners, usage and a delivery route for each application
  • Peak concurrency by user group, which sizes the host pools instead of headcount
  • The sites, networks and devices users connect from
  • Printing, scanning, smart cards and other peripherals in use
  • Identity readiness: whether every user is in Microsoft Entra ID with matching accounts
  • A wave plan, a cost model and the risks that could move the dates

Session host sizing starts from Microsoft's published guidance, which sets a maximum number of users per vCPU for each workload type, and is then confirmed in the pilot with real users, because Microsoft itself describes those figures as initial estimates.

How is a migration of this size governed, and who does what?

Through a small programme board that meets on a fixed cadence, owns the wave plan and signs off each stage. A migration of a thousand seats or more touches every department, so decisions about dates, exceptions and acceptance cannot sit with the technical team alone.

The roles on our side:

Programme lead
the plan, risks, reporting and the board
Lead architect
the design and every decision that changes it
Packaging lead
testing and packaging, application by application
Identity and security
Entra ID, Conditional Access and the access model
Migration engineers
builds, the pilot and each wave
Service transition
handover to whoever runs the estate

The roles we ask you to name:

Sponsor
owns the outcome and the budget
Application owners
confirm each application works before its users move
Service desk
takes first-line calls during each wave, briefed in advance
Security and compliance
approve the design and the access model

Each stage ends with written sign-off against exit criteria agreed at the start. We run a migration under the same ISO 27001 and ISO 9001 management systems as the rest of our work, so change control, access and records follow a documented process rather than a project's habits.

How are applications handled: compatibility, MSIX and App Attach?

Application by application, because one undocumented dependency can hold up a whole wave. Each application is tested on the target operating system and given one of three routes: built into the golden image, installed through Intune, or attached at sign-in with App Attach.

What App Attach changes, from Microsoft's documentation:

  • Applications are not installed on the session hosts or images, which keeps images smaller and easier to maintain.
  • Packages can be MSIX, Appx or App-V, so existing App-V packages can be reused.
  • Applications are assigned per user, so people on the same host can get different applications.
  • The same package can be used across several host pools.
  • A new version can be added without a maintenance window, and users get it at their next sign-in.

There are prerequisites worth planning early. Every MSIX and Appx package needs a code signing certificate that the session hosts trust, packages sit on an SMB file share in the same Azure region as the session hosts, and Microsoft advises against sharing that file share with FSLogix profile containers. Where an application cannot be packaged, it goes in the image or through Intune instead, and the assessment says which applications those will be.

How are identity and user profiles handled?

Identity comes first, because it decides who can sign in at all. Azure Virtual Desktop requires users to be discoverable in Microsoft Entra ID: identities that exist only in Active Directory Domain Services are not supported. Most estates of this size already sync Active Directory to Entra ID with Microsoft Entra Connect, and the check is that each user's UPN or SID matches between the two, which Microsoft requires for hybrid identities.

Sign-in to the service goes through Entra ID, which is where Conditional Access and multifactor authentication apply. Microsoft recommends single sign-on with Microsoft Entra authentication, so users are not asked for credentials again at the session host. Smart card and Windows Hello for Business sign-in to the session needs Kerberos, which means line of sight to a domain controller or a KDC proxy, and we plan for that wherever those methods are in use.

Profiles move to FSLogix profile containers, which Microsoft recommends for Azure Virtual Desktop. Each user's profile is a single virtual disk attached at sign-in, stored on Azure Files or Azure NetApp Files in the same region as the session hosts. Existing profiles are either migrated into containers or rebuilt, decided per user group: a clean profile often clears problems people have lived with for years, while some groups need their settings carried across.

FSLogix matters for OneDrive too: without profile containers, Microsoft does not support OneDrive in non-persistent virtual desktops.

How do Citrix and Azure Virtual Desktop run side by side?

For the length of the programme, by design. Users move in waves, and each wave keeps access to Citrix until its applications, printing and sign-in have been confirmed on Azure Virtual Desktop. If something fails that the pilot did not find, the affected users go back to Citrix the same day while it is fixed.

Diagram: users in signed-off waves connect through Windows App to new Azure Virtual Desktop host pools, while everyone not yet moved stays on Citrix. Both platforms share one identity and the same back-end data.
Citrix keeps serving everyone not yet moved, and its capacity is reduced as waves complete, never before.

What coexistence takes:

  • One identity: users sign in to Azure Virtual Desktop with their existing directory account, synced to Entra ID.
  • Both clients on the endpoint during a wave: the Citrix client and Windows App.
  • Applications reaching the same back-end data from both platforms, with network paths tested before each wave.
  • A clear rule for profiles, so nobody's settings are split between two platforms.
  • Citrix capacity reduced as waves complete, never before.

The wave plan is built backwards from the date that matters most to you, often a Citrix renewal or a release end-of-life date, with contingency before it. If the dates cannot be met safely, the assessment says so while there is still time to extend Citrix on sensible terms.

What do you hand over at the end?

Everything needed to run the estate without us:

  • The as-built design and the decisions behind it
  • Infrastructure as code for the host pools and supporting resources
  • The image pipeline and its documentation
  • The application catalogue: each application, its route, owner and package
  • Scaling plans, monitoring with Azure Virtual Desktop Insights, and alerting
  • Runbooks for routine operations, and a cost report against the business case
  • Knowledge transfer sessions with your team

If you would rather not run it yourselves, our team can carry on running and optimising the estate after the last wave. Either way the handover pack is the same, so the choice stays open.

Why Systech for a Citrix to AVD migration?

Because the work is done by a team that delivers virtual desktops every day, under certified management systems. Systech is ISO 27001 and ISO 9001 certified and a Microsoft partner, our support is 100% UK-based, and our engineers are certified to AZ-140, Microsoft's Azure Virtual Desktop specialty exam.

Our virtual desktop work covers cloud Azure Virtual Desktop, AVD Hybrid, Windows 365 and Remote Desktop Services, so the recommendation is not tied to one platform. The team includes our founder, Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and author of Packt's Mastering Azure Virtual Desktop.

How do we start?

With a call. Tell us roughly how many users you have, what Citrix publishes today and what is driving the timing, and we will tell you how we would approach it and what the assessment would cover. If you are earlier in the decision than that, our free virtual desktop review is a shorter first step.

The five stages of a Citrix to Azure Virtual Desktop migration
StageWhat happensWhat you get
AssessInventory of applications, users, sites and peripherals; peak concurrency; identity readinessAn application inventory with a route for each application, a wave plan and a cost model
DesignLanding zone, host pools, images, identity, profiles and application deliveryA design signed off by your security and application owners
PilotA representative group of users, including the hardest applications and sitesEvidence that the design works, and the fixes it needed
Migrate in wavesGroups of users move on agreed dates, with Citrix still available to themEach wave signed off before the next starts
RunHandover to your team, or ongoing running and optimisation by oursAs-built design, runbooks, application catalogue and knowledge transfer

Checked against Microsoft Learn, Azure pricing and Citrix's product lifecycle matrix on 4 October 2026: What is Azure Virtual Desktop?, Azure Virtual Desktop landing zone design guide (Azure Architecture Center), App Attach in Azure Virtual Desktop, FSLogix profile containers for Azure Virtual Desktop, Azure Virtual Desktop identities and authentication, Session host virtual machine sizing guidelines, Azure Virtual Desktop pricing and Citrix product lifecycle matrix. Confirm current terms with Microsoft before buying.

Questions we hear a lot

Is there a direct migration path from Citrix to Azure Virtual Desktop?

Not as a conversion. Microsoft runs Azure Virtual Desktop's broker and gateway as a service, and you manage only the images and session host virtual machines in your own subscription, so a Citrix site is not carried across as it stands. New host pools are built, golden images are moved into Azure or rebuilt, profiles are migrated into FSLogix containers or rebuilt, and applications are delivered through App Attach or installed in the image.

How long does a Citrix to Azure Virtual Desktop migration take?

It depends more on the number of applications than the number of users, because applications are what has to be tested and packaged before each wave. We give you a dated wave plan at the end of the assessment, built backwards from the date that matters to you, rather than a figure before anyone has counted what Citrix publishes.

Can we keep Citrix running during the migration?

Yes, and we plan for it. Users move in waves and keep access to Citrix until their wave is signed off, so anyone hit by a problem the pilot did not find can go back the same day. Citrix capacity is reduced as waves complete, not before.

Do our users need new licences for Azure Virtual Desktop?

Often not for access. Microsoft lists Microsoft 365 E3, E5, A3, A5, F3 and Business Premium, Windows Enterprise E3 and E5, Windows Education A3 and A5, and Windows VDA per user as licences that include access to Windows 11 and Windows 10 on Azure Virtual Desktop. The Azure compute, storage and networking are paid for separately, and Citrix licensing carries on until the last wave is complete.

Can we reuse our App-V packages?

Often, yes. App Attach in Azure Virtual Desktop accepts App-V packages as well as MSIX and Appx, so existing App-V packages can be tested and attached rather than rebuilt. MSIX remains the format to move towards where an application supports it, and the assessment sets a route for each application.

What happens to user profiles?

They move to FSLogix profile containers, which Microsoft recommends for Azure Virtual Desktop, stored on Azure Files or Azure NetApp Files in the same region as the session hosts. Profiles are migrated into containers or rebuilt, decided per user group during design.

Show all 8 questionsShow fewer questions
Will you tell us if we should stay on Citrix?

Yes. If the assessment finds a capability your users depend on that Azure Virtual Desktop does not provide, or the dates cannot be met safely, we will say so in writing. Our virtual desktop work also covers Windows 365, AVD Hybrid and Remote Desktop Services, so the recommendation is not tied to one platform.

Do you work with Citrix estates smaller than 1,000 seats?

Yes. This page describes the programme we run for large estates; smaller estates follow the same stages with a lighter governance model, and our Azure Virtual Desktop consultancy covers that work.

Tell us about your Citrix estate

Roughly how many users, what Citrix publishes today, and what is driving the timing. We will come back with how we would run the migration and what the assessment would cover, and we will say so if staying on Citrix is the better answer.

Spam-protected by hCaptcha. Privacy · Terms

Citrix to AVD migration is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Scarborough, Bradford, Hull, Leeds, York and Sheffield and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Plan your Citrix to AVD migration

A call about the size of your estate, what Citrix publishes today and what is driving the timing, and how we would run the programme.

Request a call Or book the free virtual desktop review

ISO 27001 & ISO 9001 certified · 100% UK-based support

Prefer to talk now? Call us on +44 (0)1482 770583.