JJC SystemsBook a Consultation
Cloud, Security & Infrastructure

When the data should not live on the device

Virtual desktops solve a narrow set of problems extremely well and are a poor answer to everything else. When data must not leave a controlled environment, when contractors need access without company hardware, or when a specialist application will not run locally, this is the right tool. We will tell you plainly if your situation is not one of those.

Overview

The four situations where this is genuinely the right answer

Azure Virtual Desktop is a specific tool for a specific set of problems. These are the ones where it consistently wins.

01

Regulated data cannot sit on a laptop

Client, patient or financial data must remain inside a controlled boundary. Endpoint encryption helps but does not remove the fundamental exposure of data at rest on a device that travels.

02

Contractors and third parties need access, not hardware

Procuring, imaging, shipping and recovering a laptop for a three-month engagement costs more than the engagement's IT budget, and the recovery step frequently does not happen.

03

A specialist application will not run on modern endpoints

Engineering, design or legacy line-of-business software with unreasonable hardware requirements or an incompatibility that has no fix. Centralising it is far cheaper than replacing it.

04

Offshore or distributed teams need consistent, low-latency access

Users far from the datacentre experience an application that is unusable over a wide-area link. Putting the desktop next to the data solves what network optimisation cannot.

Be careful with the business case here

Where the return actually comes from — and where it does not: Be careful with the business case here, because the honest version is narrower than the marketing version. Virtual desktops rarely save money against a well-managed laptop estate; the compute and storage cost is real and ongoing. The return comes from risk removed where data genuinely cannot leave a boundary, from onboarding time when contractors need access in hours rather than weeks, and from avoided replacement cost when a specialist application would otherwise need rewriting. If none of those apply to you, a well-managed physical estate with Intune is usually the better and cheaper answer, and we will say so.

Capabilities & direction

What Azure Virtual Desktop provides, and where Microsoft is taking it

The components that determine whether the experience is good or merely functional.

Multi-session Windows

Multiple users on a single host with Windows multi-session, which is the capability that makes the economics work at scale rather than one virtual machine per user.

Published applications, not only desktops

Delivering a single application into a user's local desktop rather than a full remote session — often a much better experience when only one program needs to be centralised.

FSLogix profile management

User profiles held centrally so a session on any host feels like the user's own machine. The single largest determinant of whether users accept the experience.

Autoscaling and cost control

Host pools scaling with demand and shutting down outside working hours — the difference between a viable running cost and an unpleasant monthly surprise.

Security and access control

Conditional access, session controls on clipboard, drive redirection and printing, and no data at rest on the endpoint.

Integration with the wider estate

Entra ID, Intune management of session hosts, Defender coverage and the same monitoring as the rest of your Azure environment.

The practical direction is convergence with the rest of endpoint management: session hosts managed by Intune, secured by Defender, and governed by the same conditional access policies as physical devices. That is a good thing — it means virtual desktops stop being a separate estate with separate tooling, which is where the operational cost used to accumulate.

Business outcomes

What we measure an AVD engagement against

We baseline the specific scenario — contractor onboarding, application delivery, data containment — rather than the platform generally.

Contractor onboardingWeeks → hours

Access provisioned without shipping hardware

Data at rest on endpoints0

For the users in scope

Compute cost30–50%

Reduction from autoscaling and right-sized host pools

Per user group1 image

Consistent, maintained and rebuildable

Access fromAny device

Including personal and unmanaged endpoints, safely

User experienceMeasured

Session performance monitored, not assumed

How to read these: How to read these: the figures above are typical ranges we plan and measure against, not guarantees. In your first engagement we agree the baseline, the target and the measurement method in writing, then report against them.

The business outcomes Microsoft associates with Azure Virtual Desktop

Microsoft's documentation frames the service's value in the following terms.

  • Secure remote access — Corporate desktops and applications delivered without data residing on the endpoint
  • Rapid provisioning — New users and contractors given access in hours rather than procurement cycles
  • Bring-your-own-device support — Safe access from personal or unmanaged hardware
  • Simplified management — Images and applications maintained centrally rather than per device
  • Cost flexibility — Consumption scaled to actual usage with automated shutdown outside working hours
  • Legacy application delivery — Applications with specific requirements centralised instead of replaced

Where this comes from: Where this comes from: these themes follow Microsoft's Azure Virtual Desktop documentation on learn.microsoft.com. The numeric ranges above are ours and are planning figures rather than Microsoft benchmarks — and, as noted above, we regard the cost case for virtual desktops as narrower than it is usually presented.

Industry use cases

Where it earns its place

Specific scenarios rather than whole organizations. Almost nobody should virtualise everything.

Healthcare

Clinical application access from shared or personal devices, with no patient data written to the endpoint.

Legal

Contractor and temporary staff access to matter systems without provisioning firm hardware or extending the physical estate.

Financial services

Regulated data kept inside a controlled boundary, with session controls on copy, print and drive redirection.

Engineering & design

Graphics-intensive applications delivered on GPU-enabled hosts to users on ordinary laptops.

Manufacturing

Plant-floor terminals and shared kiosks running a controlled application set with no local state.

Outsourced & offshore teams

Consistent, low-latency access to line-of-business systems for teams working far from the data.

How we help

Three ways we work on Azure Virtual Desktop

Starting with an honest conversation about whether you need it at all.

Assess the fit honestly

Establishing whether virtual desktops are the right answer for your scenario, and for which users.

  • Use case and user group analysis
  • Cost modelling against a managed physical estate
  • Application compatibility assessment
  • Scope recommendation, including not proceeding

Design and deploy

The build, with the details that determine whether users accept it.

  • Host pool sizing and image design
  • FSLogix profile architecture
  • Application delivery and published app configuration
  • Network, latency and gateway design

Operate and optimise

Ongoing management, because this is a platform that degrades quietly if unattended.

  • Autoscaling and cost management
  • Image lifecycle and patching
  • Session performance monitoring
  • Security controls and conditional access
Our consulting services

Consulting services for Azure Virtual Desktop, tied to outcomes

Implementation, customization, support and integration — measured against user experience and cost per user, not against deployment completion.

implementation

Implementation of Azure Virtual Desktop

Environment design, tenant and licensing setup, configuration, data migration, testing and go-live — scoped to a fixed price and a fixed date, against outcomes agreed in writing before we start. For virtual desktop that means piloting with the users who have the most demanding applications, because a pilot of light office users proves nothing about whether the design will hold.

customization

Customization of Azure Virtual Desktop

Where the product stops short of your process, we extend it inside the platform rather than beside it, and we build it as configuration you can maintain wherever that is possible. Images, application sets, session policies and scaling schedules built for each user group rather than one configuration stretched across all of them.

support

Support of Azure Virtual Desktop

Managed support after go-live: a named team, agreed response times, release management for Microsoft's update cadence, and a backlog we work through with you. Image maintenance, patching, capacity management and the session-level troubleshooting that virtual desktop estates generate more of than physical ones.

integration

Integration of Azure Virtual Desktop

Connecting this platform to the systems you are keeping, with monitored, re-runnable interfaces and a documented contract for every field that moves. Entra ID, Intune management of session hosts, Defender coverage and connectivity to the data and applications the desktops need to reach.

We will tell you when you do not need this. A well-managed physical estate with Intune is cheaper and simpler than virtual desktop for most users, and recommending that costs us a considerably larger engagement. Virtual desktop should be deployed for the users and scenarios that genuinely require it.

Our approach

Understand, design, deploy, secure

The single biggest cause of failed virtual desktop projects is designing for the average user and then meeting the demanding ones.

1

Understand

We profile the user groups, their applications and their actual performance requirements.

2

Model

We cost the design honestly against the alternative of a managed physical estate.

3

Design

We size host pools, design the image and profile architecture, and plan for the peak not the mean.

4

Pilot

We deploy to the most demanding users first and tune until they stop noticing it.

5

Secure & operate

Session controls, conditional access, monitoring and autoscaling established as a managed service.

Profile management is where user acceptance is decided. If sign-in is slow or settings do not persist between sessions, users will conclude the whole platform is inferior regardless of how well everything else is engineered.

Why JJC Systems

Why organizations bring us in for Azure Virtual Desktop

This is a platform where the honest scoping conversation is worth more than the deployment.

We scope it to the scenarios that need it

Virtual desktop for the users who genuinely require it, and Intune-managed physical devices for everyone else. Wholesale virtualisation is expensive and rarely justified.

We model the cost honestly

Running cost is ongoing and real. We build the comparison against a managed physical estate before you commit, including the cases where that comparison does not favour us.

We design for the demanding users

Profile performance and application responsiveness decide adoption. We pilot with the hardest cases because they are the ones who will define the platform's reputation.

One partner across desktop, identity and cloud

Session hosts, Intune, conditional access, Defender and the Azure estate underneath from one accountable team.

Customer success

What good looks like on Azure Virtual Desktop

Two illustrative engagements showing the shape of the work.

Legal practice

Contractor access without a hardware programme

The firm regularly engaged contract reviewers for short projects. Each required a firm laptop, imaged, shipped and — in theory — returned. Recovery of devices was inconsistent and the administrative cost was significant.

2 wks → 3 hrsContractor onboarding
0Devices shipped
0Data on endpoints

What changed

  • Contractors accessing a controlled desktop from their own hardware
  • No matter data written to any endpoint, with clipboard and print controls applied
  • Access revoked instantly at the end of an engagement rather than chased
  • Hardware procurement for temporary staff eliminated entirely
Talk about a similar outcome
Engineering consultancy

The scope that got smaller after the assessment

The firm intended to move all staff to virtual desktops. Assessment established that only the design team, running GPU-intensive software, had a case that held up against a managed physical estate.

100% → 18%Users in scope
ModelledAgainst physical
2User groups, not one

What changed

  • Cost modelling comparing virtual desktop against Intune-managed laptops per user group
  • Design team moved to GPU-enabled hosts with a genuine performance benefit
  • Remaining staff kept on physical devices at materially lower cost
  • A smaller engagement than the one originally proposed
Talk about a similar outcome

Find out whether you actually need it

Tell us the scenario — contractors, a specialist application, data that cannot leave a boundary. We will build a pilot host pool for that use case, put your demanding users on it, and give you an honest cost comparison against the alternative.

Request your demo See it by industry We reply to every message within one business day.
Works alongside

Related platforms

Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.