The virtual desktop business case, honestly
Where the numbers genuinely work, where they do not, and how to model it before committing.
Read moreVirtual desktops solve a narrow set of problems extremely well and are a poor answer to everything else. When data must not leave a controlled environment, when contractors need access without company hardware, or when a specialist application will not run locally, this is the right tool. We will tell you plainly if your situation is not one of those.
Azure Virtual Desktop is a specific tool for a specific set of problems. These are the ones where it consistently wins.
Client, patient or financial data must remain inside a controlled boundary. Endpoint encryption helps but does not remove the fundamental exposure of data at rest on a device that travels.
Procuring, imaging, shipping and recovering a laptop for a three-month engagement costs more than the engagement's IT budget, and the recovery step frequently does not happen.
Engineering, design or legacy line-of-business software with unreasonable hardware requirements or an incompatibility that has no fix. Centralising it is far cheaper than replacing it.
Users far from the datacentre experience an application that is unusable over a wide-area link. Putting the desktop next to the data solves what network optimisation cannot.
Where the return actually comes from — and where it does not: Be careful with the business case here, because the honest version is narrower than the marketing version. Virtual desktops rarely save money against a well-managed laptop estate; the compute and storage cost is real and ongoing. The return comes from risk removed where data genuinely cannot leave a boundary, from onboarding time when contractors need access in hours rather than weeks, and from avoided replacement cost when a specialist application would otherwise need rewriting. If none of those apply to you, a well-managed physical estate with Intune is usually the better and cheaper answer, and we will say so.
The components that determine whether the experience is good or merely functional.
Multiple users on a single host with Windows multi-session, which is the capability that makes the economics work at scale rather than one virtual machine per user.
Delivering a single application into a user's local desktop rather than a full remote session — often a much better experience when only one program needs to be centralised.
User profiles held centrally so a session on any host feels like the user's own machine. The single largest determinant of whether users accept the experience.
Host pools scaling with demand and shutting down outside working hours — the difference between a viable running cost and an unpleasant monthly surprise.
Conditional access, session controls on clipboard, drive redirection and printing, and no data at rest on the endpoint.
Entra ID, Intune management of session hosts, Defender coverage and the same monitoring as the rest of your Azure environment.
The practical direction is convergence with the rest of endpoint management: session hosts managed by Intune, secured by Defender, and governed by the same conditional access policies as physical devices. That is a good thing — it means virtual desktops stop being a separate estate with separate tooling, which is where the operational cost used to accumulate.
We baseline the specific scenario — contractor onboarding, application delivery, data containment — rather than the platform generally.
Access provisioned without shipping hardware
For the users in scope
Reduction from autoscaling and right-sized host pools
Consistent, maintained and rebuildable
Including personal and unmanaged endpoints, safely
Session performance monitored, not assumed
How to read these: How to read these: the figures above are typical ranges we plan and measure against, not guarantees. In your first engagement we agree the baseline, the target and the measurement method in writing, then report against them.
Microsoft's documentation frames the service's value in the following terms.
Where this comes from: Where this comes from: these themes follow Microsoft's Azure Virtual Desktop documentation on learn.microsoft.com. The numeric ranges above are ours and are planning figures rather than Microsoft benchmarks — and, as noted above, we regard the cost case for virtual desktops as narrower than it is usually presented.
Specific scenarios rather than whole organizations. Almost nobody should virtualise everything.
Clinical application access from shared or personal devices, with no patient data written to the endpoint.
Contractor and temporary staff access to matter systems without provisioning firm hardware or extending the physical estate.
Regulated data kept inside a controlled boundary, with session controls on copy, print and drive redirection.
Graphics-intensive applications delivered on GPU-enabled hosts to users on ordinary laptops.
Plant-floor terminals and shared kiosks running a controlled application set with no local state.
Consistent, low-latency access to line-of-business systems for teams working far from the data.
Starting with an honest conversation about whether you need it at all.
Establishing whether virtual desktops are the right answer for your scenario, and for which users.
The build, with the details that determine whether users accept it.
Ongoing management, because this is a platform that degrades quietly if unattended.
Implementation, customization, support and integration — measured against user experience and cost per user, not against deployment completion.
Environment design, tenant and licensing setup, configuration, data migration, testing and go-live — scoped to a fixed price and a fixed date, against outcomes agreed in writing before we start. For virtual desktop that means piloting with the users who have the most demanding applications, because a pilot of light office users proves nothing about whether the design will hold.
Where the product stops short of your process, we extend it inside the platform rather than beside it, and we build it as configuration you can maintain wherever that is possible. Images, application sets, session policies and scaling schedules built for each user group rather than one configuration stretched across all of them.
Managed support after go-live: a named team, agreed response times, release management for Microsoft's update cadence, and a backlog we work through with you. Image maintenance, patching, capacity management and the session-level troubleshooting that virtual desktop estates generate more of than physical ones.
Connecting this platform to the systems you are keeping, with monitored, re-runnable interfaces and a documented contract for every field that moves. Entra ID, Intune management of session hosts, Defender coverage and connectivity to the data and applications the desktops need to reach.
We will tell you when you do not need this. A well-managed physical estate with Intune is cheaper and simpler than virtual desktop for most users, and recommending that costs us a considerably larger engagement. Virtual desktop should be deployed for the users and scenarios that genuinely require it.
The single biggest cause of failed virtual desktop projects is designing for the average user and then meeting the demanding ones.
We profile the user groups, their applications and their actual performance requirements.
We cost the design honestly against the alternative of a managed physical estate.
We size host pools, design the image and profile architecture, and plan for the peak not the mean.
We deploy to the most demanding users first and tune until they stop noticing it.
Session controls, conditional access, monitoring and autoscaling established as a managed service.
Profile management is where user acceptance is decided. If sign-in is slow or settings do not persist between sessions, users will conclude the whole platform is inferior regardless of how well everything else is engineered.
This is a platform where the honest scoping conversation is worth more than the deployment.
Virtual desktop for the users who genuinely require it, and Intune-managed physical devices for everyone else. Wholesale virtualisation is expensive and rarely justified.
Running cost is ongoing and real. We build the comparison against a managed physical estate before you commit, including the cases where that comparison does not favour us.
Profile performance and application responsiveness decide adoption. We pilot with the hardest cases because they are the ones who will define the platform's reputation.
Session hosts, Intune, conditional access, Defender and the Azure estate underneath from one accountable team.
Two illustrative engagements showing the shape of the work.
The firm regularly engaged contract reviewers for short projects. Each required a firm laptop, imaged, shipped and — in theory — returned. Recovery of devices was inconsistent and the administrative cost was significant.
The firm intended to move all staff to virtual desktops. Assessment established that only the design team, running GPU-intensive software, had a case that held up against a managed physical estate.
Practical pieces on when this is right and how to make it work.
Where the numbers genuinely work, where they do not, and how to model it before committing.
Read moreWhy sign-in time and settings persistence matter more than any other design decision.
Read moreClipboard, print and drive redirection policy — and the gaps people assume are covered.
Read moreTell us the scenario — contractors, a specialist application, data that cannot leave a boundary. We will build a pilot host pool for that use case, put your demanding users on it, and give you an honest cost comparison against the alternative.
Describe the situation in your own words.