Windows 365 Consultancy
Cloud PCs sized, licensed and rolled out properly, so a predictable price doesn't come with an unpredictable experience.
Cloud PCs, sized and rolled out properly
In short: Cloud PCs sized, licensed and rolled out against real usage data rather than a guess. Get the sizing and edition right at the start, because that decision drives everything afterwards and is awkward to unwind later.
Windows 365 is sold on simplicity: pick a size, assign a licence, done. Most of the ways it goes wrong happen before that point, in a sizing decision made without usage data, a network that was never checked against Microsoft's connection requirements, or an edition chosen for its price rather than what it actually unlocks.
The problem
Windows 365's fixed per-user price feels like it removes the decisions, but it just moves them earlier. Buy the wrong Cloud PC size and users get a desktop that stutters under their actual workload; buy too generous a size and you're paying a premium every month for headroom nobody uses. Pick Enterprise when Business would have covered you, or Business when you needed Enterprise's Conditional Access and custom images, and you find out at the point it's disruptive to change. None of it shows up until users are already logged in and unhappy, or the renewal invoice lands larger than the headcount justifies.
What we would do
Get the sizing and edition right at the start, because that decision drives everything afterwards and is awkward to unwind. After that, Windows 365 needs far fewer ongoing decisions than AVD, which is usually the actual reason to choose it.
- If you are under 300 users with no Intune, no custom images and no Conditional Access requirement on the desktop, Windows 365 Business is the simpler and cheaper route.
- If you need custom images, Conditional Access on the Cloud PC or integration with an existing Intune estate, you want Enterprise and the prerequisites that come with it.
When we are not the answer: If cost per seat is the deciding factor and you have the capability to tune infrastructure, AVD will be cheaper at scale. We will tell you that rather than sell you the simpler product.
We run Windows 365 consultancy as three phases. Assessment: which edition fits, what Cloud PC size each user group genuinely needs based on their actual application set, whether your network meets Microsoft's connection requirements, and a straight recommendation on whether Windows 365, Azure Virtual Desktop, or a mix of both is the right fit for your business. Migration: provisioning, image and policy build, Conditional Access and Intune integration, and a staged rollout. Optimisation: reviewing licence tier against real usage, reclaiming Cloud PCs from leavers promptly, and adjusting sizing as application needs change.
More on how we deliver Windows 365 consultancy
Because the platform itself has few moving parts, the value of a specialist engagement sits almost entirely in getting the upfront decisions right: edition, sizing and network readiness. Get those three correct and Windows 365 is genuinely close to a subscription to manage. Get them wrong and you're paying every month for a desktop that either underperforms or overshoots what your users need.
Still weighing Cloud PCs against the alternatives? Our AVD vs Windows 365 vs traditional desktops guide compares the two cloud platforms alongside traditional physical desktops, so you can see where the cost and the management overhead actually diverge before you commit to one.
What people use a Cloud PC for is applications, and how those arrive decides how much rebuilding follows. Our application packaging service keeps the image small rather than accumulating installs.
Everything you need, managed for you
What does a Windows 365 consultancy engagement actually involve?
The same three-phase model we run for any virtual desktop engagement, scaled to how much Windows 365 itself needs deciding. Assessment covers edition choice, Cloud PC sizing per user group based on actual application and workload data rather than a standard tier, and a network readiness check against Microsoft's published connection requirements, because a Cloud PC that's correctly sized but reached over a poor connection still feels slow to the user sitting in front of it.
Migration is the provisioning and rollout itself:
- Image build, if you are on Enterprise
- Intune and Conditional Access policy
- A staged rollout by user group, rather than a single cutover for everyone at once
Optimisation is lighter than it is for AVD, because there is less infrastructure to tune, but it is still real:
- Licence tier reviewed against actual usage
- Cloud PCs reclaimed promptly from leavers
- Sizing revisited as application needs change, rather than left at whatever was chosen on day one
Business or Enterprise: which edition fits?
Windows 365 Business is capped at 300 users and needs no infrastructure prerequisites:
- No Intune
- No Microsoft Entra ID tenant configuration beyond the basics
- No domain
It suits a small or mid-sized business that wants Cloud PCs working with minimal setup and does not need custom images or Conditional Access policy applied to the desktop itself.
Windows 365 Enterprise has no user cap and unlocks custom images built and versioned through the Azure Compute Gallery, full Conditional Access, and management through Intune alongside your other managed devices, but it requires Microsoft Entra ID, Intune, and eligible Windows and Microsoft 365 licences per user already in place.
The deciding question isn't headcount alone, it's whether you need a custom image or Conditional Access enforced on the Cloud PC. If you do, Enterprise is the only option regardless of size.
How do you size a Cloud PC without over- or under-buying?
From the applications each user group actually runs, not a generic recommendation. Windows 365 is sold in fixed vCPU, memory and storage tiers, and the temptation is to standardise on one size for everyone, which either overpays for light users or starves anyone running a heavier line-of-business application or multiple large applications simultaneously.
We group users by workload rather than by department or job title, because a finance analyst running one heavy application and a sales user running a browser and email are different sizing decisions even if they sit in the same team. Getting this right at the assessment stage matters more for Windows 365 than for AVD, because there's no autoscale to paper over a sizing mistake after the fact, the Cloud PC is that size until someone changes it.
When is Windows 365 more cost-effective than AVD, and when isn't it?
Windows 365 wins on cost, and more importantly on predictability, when headcount is stable and every seat is genuinely used most of the working day. There's no infrastructure to design or tune, no scaling plan to get wrong, and the monthly cost per user is fixed regardless of what happens to Azure's own compute pricing. For a business that wants desktops without taking on infrastructure decisions, that simplicity has real value beyond the raw pound figure.
It stops being the cheaper option once usage becomes genuinely variable, seasonal, or shift-based beyond what Frontline licensing covers, or once you need GPU-backed compute, which Windows 365 doesn't offer at any price.
In those cases Azure Virtual Desktop's ability to scale capacity down when it isn't needed, or to provision GPU host pools at all, starts to outweigh the simplicity Windows 365 offers. We size this against your real usage pattern at assessment, because the honest crossover point moves depending on how concurrent your actual demand is, not on headcount alone.
How does Windows 365 management actually differ from AVD management?
Windows 365 management is close to administering a subscription: assign a licence at the size a user needs, and the Cloud PC exists, dedicated to that one person, with the profile living on the machine itself rather than in a separate profile store. There's no host pool to size, no scaling plan to configure, and no shared infrastructure whose performance depends on how many other users happen to be logged in at the same moment.
AVD management is running infrastructure. These are all decisions that need making and then revisiting as usage changes:
- Host pools
- Autoscale scaling plans
- FSLogix profile storage
- Image versioning
The feature comparison that matters in practice is not a checklist of what each platform can do, it is who is going to own the ongoing decisions, because Windows 365 genuinely needs far fewer of them once the initial sizing and edition choice are right.
What actually breaks a Windows 365 rollout?
Network readiness is the one most often skipped, and it's the one users notice immediately. Windows 365 has published bandwidth, latency and port requirements for a usable Cloud PC connection, and a site with a congested internet connection or an aggressive firewall blocking the required endpoints will deliver a stuttering desktop regardless of how correctly the Cloud PC itself is sized. This gets checked before provisioning, not discovered afterwards from a help desk queue.
The second recurring failure is Conditional Access and identity gaps on Enterprise: a Cloud PC provisioned without device compliance or Conditional Access policy applied is reachable from anywhere with valid credentials, which defeats a large part of the security case for moving to Cloud PCs in the first place.
The third is licence mismatch, assigning Enterprise-tier features to users who'd have been fully served by Business, or the reverse, discovering mid-rollout that Business can't do what a use case actually needed.
Windows 365 Frontline, Boot and Switch: what are they and do you need them?
Frontline licensing shares a smaller pool of Cloud PCs across shift or part-time workers rather than dedicating one to each named user, which suits retail, healthcare or hospitality teams where staff rarely overlap. It's worth checking specifically if you have shift-based roles, because licensing everyone individually in that scenario pays for capacity that's idle most of the week.
Windows 365 Boot signs a user directly into their Cloud PC from the Windows welcome screen on a shared or thin-client device, useful where several people use the same physical machine across a day. Windows 365 Switch lets a user move between their local desktop and their Cloud PC on the same device without a separate remote desktop session.
Neither is essential for every deployment, but both are easy to miss if nobody asks whether your user base includes shared devices or people who genuinely need to move between local and cloud desktops during the day.
Is a Cloud PC actually more secure than a laptop?
Generally yes, for the same reason any virtual desktop is: company data lives in the Cloud PC, not on whatever physical device is being used to reach it, so a lost, stolen, or quietly retained device carries nothing to breach. That removes a whole category of incident rather than simply mitigating it.
The rest of the security case depends on what's configured around it, which on Windows 365 Enterprise means Conditional Access requiring a compliant or known device before a session opens, Intune policy applied to the Cloud PC itself, and access revoked centrally and immediately the day someone leaves, reclaiming the Cloud PC rather than leaving it assigned and idle. Business edition has fewer of these controls available, which is part of the trade-off against its simpler setup.
Why does a Cloud PC have a smaller blast radius than multi-session AVD?
Because a Cloud PC is one user's machine, and an AVD multi-session host is several users' machine at once. That single architectural difference is the most under-discussed factor in choosing between the two, and it decides how far a problem travels before anyone notices.
What each incident actually costs on a Cloud PC versus a pooled host, and when AVD is still the right answer
On a Windows 365 Cloud PC the blast radius of almost any incident is one person. A malware detection, a profile corruption, a bad application install, a driver or update that breaks something, a runaway process consuming all available memory: each of those affects the user it happened to, and the remedy is to isolate, reset or reprovision that one Cloud PC. Nobody else's desktop is involved, because nobody else was on it.
On an AVD pooled host running multi-session, the same events land on every user signed in to that host. A compromised session sits on the same operating system instance as its neighbours. One user's resource-hungry process degrades performance for everyone sharing the host. A problem introduced through an image update reaches every session that lands on the affected hosts.
Taking a host out of service to fix it means draining and moving the users on it. None of that makes AVD insecure, and it is manageable with the right host pool design, image discipline and monitoring, but it is a materially larger radius per incident and it needs to be a deliberate choice rather than a surprise.
This is why regulated and security-sensitive workloads often land on Windows 365 even where AVD would be cheaper on paper. Dedicated per-user isolation is easier to explain to an auditor, easier to reason about during an incident, and simpler to contain, because containment is reprovisioning one machine.
Where the workload genuinely needs pooled multi-session economics or GPU-backed hosts, AVD remains the right answer, and personal (rather than pooled) AVD host pools narrow the gap at the cost of the density that made pooling attractive in the first place.
Can you migrate between Azure Virtual Desktop and Windows 365?
In both directions, and it is more common than the way these platforms are usually presented would suggest. They are not a one-time either/or decision: they share an underlying platform, the same identity and management stack, and much of the same preparation work, so moving between them is a change of hosting model rather than a rebuild from scratch.
AVD to Windows 365 is the direction we see most. It typically follows a realisation that the infrastructure overhead is not being repaid:
- Host pools and scaling plans that nobody has time to tune
- FSLogix profile storage that has become a recurring source of incidents
- An environment inherited from a previous provider that has drifted, and now costs more to keep healthy than the flexibility is worth
For a stable, predictable workforce, moving those users onto dedicated Cloud PCs removes an entire class of ongoing work. Our AVD to Windows 365 migration case study covers exactly this pattern and what it did to priority-one incident volume.
Windows 365 to AVD happens for narrower and more specific reasons:
- A workload that grows into needing GPU-backed compute
- Genuinely variable or seasonal usage, where paying per user per month stops making sense
- A requirement for custom host configuration beyond what the fixed Cloud PC tiers offer
Often it is not a wholesale move at all but a partial one, taking a subset of users to AVD while the rest stay on Cloud PCs.
The practical point is that the same assessment covers both. Working out the right hosting model means understanding application sets, concurrency, usage patterns and network readiness, and that work is identical whichever platform you end up on. It also means a mixed estate is a legitimate outcome rather than an admission of indecision: put the steady-state users on Cloud PCs for the isolation and the predictable cost, and use AVD where pooled or GPU capacity genuinely earns its keep.
What should you expect from a Cloud PC provider?
Less than you would demand of an AVD partner, because Microsoft runs the infrastructure, and that changes what is actually worth paying for. Most Cloud PC providers will happily sell you licences and provision them, but licence resale is the commodity part.
The work that decides whether a Windows 365 rollout lands is sizing against real application behaviour, the Intune configuration that governs the estate afterwards, network readiness on the sites people will actually connect from, and the identity and Conditional Access design that keeps a Cloud PC from being a soft entry point.
So the useful question for any cloud pc service provider is what happens in month two. Ask who reviews sizing once people are working on them, because the commonest Windows 365 waste is not overspend on the wrong tier at purchase, it is nobody reclaiming licences from leavers and long-term absences.
Ask whether they will move users down a size as well as up. And ask what their answer is when a workload turns out to need GPU or fine-grained VM control, because the honest one is Azure Virtual Desktop, not a bigger Cloud PC.
The credential behind the recommendation
Ryan Mangan, Systech's founder, is a Microsoft MVP, an award renewed specifically for his work across both Azure Virtual Desktop and Windows 365, and the author of Mastering Azure Virtual Desktop, published by Packt across two editions. He maintains a public MSIX App Attach reference wiki used by other engineers working through the same platform decisions covered on this page.
The reason that matters for a Windows 365 engagement specifically is that Windows 365 and AVD share the same underlying platform and the same set of trade-offs, and the recommendation on edition, sizing, blast radius or whether to move between the two comes from someone who works across the whole platform daily, not from whoever happens to answer the phone at a reseller. It is also why we will tell you when AVD is the better answer, which a Windows 365 licence sale would not.
| Management feature | Windows 365 | Azure Virtual Desktop |
|---|---|---|
| How a desktop is provisioned | Assign a licence at a chosen Cloud PC size | Assign a session on a host pool sized, built and scaled by your team |
| Where the user profile lives | On the dedicated Cloud PC itself | FSLogix container on Azure Files, sized for concurrent logins |
| Scaling to demand | Manual: assign or remove a licence per user | Autoscale scaling plans add and remove hosts automatically |
| Image customisation | Custom images on Enterprise only, via Azure Compute Gallery | Full image pipeline as standard, versioned and staged |
| Shift or part-time staff | Frontline licensing shares a smaller Cloud PC pool across shifts | Pooled multi-session hosts serve this by design |
| Ongoing admin overhead | Low: licence assignment and periodic right-sizing | Higher: host pools, scaling plans, images and storage need active management |
| Best fit | Stable headcount wanting predictable cost with minimal admin | Variable demand, larger scale, or GPU and specialist workloads |
Questions we hear a lot
Windows 365 vs AVD: what's the actual difference?
Windows 365 gives each user a dedicated Cloud PC at a fixed per-user, per-month price, with nothing to size or scale. Azure Virtual Desktop runs on your own Azure subscription with pooled multi-session hosts, autoscaling and GPU options, so it's often cheaper at real scale but has to be designed and actively managed. Many organisations run both, matched to different user groups rather than picking one for the whole business.
When is Windows 365 more cost-effective than AVD?
When headcount is stable and predictable and every seat gets used most of the working day, because you're then paying for capacity you're genuinely consuming, with none of the design or ongoing tuning overhead AVD needs to realise its own savings. Once usage becomes variable, seasonal, or needs GPU compute, AVD's ability to scale capacity to actual demand usually overtakes Windows 365's fixed price.
What's the feature comparison between Windows 365 and AVD management platforms?
Windows 365 management is licence assignment and periodic right-sizing, with the profile living on the dedicated Cloud PC and custom images only available on Enterprise. AVD management is host pools, autoscale scaling plans, FSLogix profile storage and a full image pipeline, all of which need active configuration and revisiting as usage changes. The trade is Windows 365's low admin overhead against AVD's greater control and cost efficiency at scale.
Is there a cost optimisation checklist for Windows 365?
It's shorter than AVD's, because there's less infrastructure to tune. The items that matter: right-size Cloud PC tier against actual application usage rather than a standard default, reclaim licences from leavers immediately rather than at the next audit, check whether Frontline licensing fits any shift-based teams, and confirm you're on the correct edition, since Enterprise features nobody uses are a recurring source of unnecessary spend.
Do we need Intune and Entra ID to run Windows 365?
It depends on the edition. Windows 365 Business is capped at 300 users and needs no infrastructure prerequisites, so a small team can run it without Intune or a configured Entra ID tenant. Enterprise has no user cap and unlocks custom images, Conditional Access and full Intune management, but requires Microsoft Entra ID, Intune, and eligible Windows and Microsoft 365 licences per user.
Can we manage Windows 365 and Azure Virtual Desktop together?
Yes, and for many businesses that's the right architecture rather than a compromise: stable, predictable user groups on Windows 365 Cloud PCs, and variable-demand or specialist workloads on AVD host pools, with one consistent identity, Conditional Access and Intune policy baseline applied across both. We cover the combined management question in more depth on our AVD consultancy page.
How long does a Windows 365 rollout take?
For Business edition with no infrastructure prerequisites, provisioning itself can be quick once sizing and licensing are decided. Enterprise rollouts take longer because of image build, Conditional Access policy and Intune integration work, and because network readiness needs checking against Microsoft's connection requirements before users are moved over. The honest timeline comes after the assessment, once we know which edition and how much custom configuration your business actually needs.
Get your Windows 365 sizing right first time
Tell us your headcount, the applications people depend on, and whether the team is stable or seasonal. We will size it against that rather than a rule of thumb, and say where Azure Virtual Desktop would be the better fit.
Windows 365 consultancy is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in York, Sheffield, Barnsley, Halifax, Doncaster and Wakefield and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Get your Windows 365 sizing right first time
Book a free Windows 365 assessment and we'll size your Cloud PCs, pick the right edition and check network readiness before a single licence is bought, so you're not paying every month for the wrong decision.
Technology partners
Best-of-breed technology we use to deliver Windows 365 consultancy.
See all technology partners →