Azure Virtual Desktop
AVD that performs, scales, and does not surprise the bill: host pools sized to real concurrency, FSLogix profiles that survive host churn, and an autoscale plan tuned to your sign-in storm instead of a vendor default.
Packer / Azure Image Builder + Compute Gallery
FSLogix on Azure Files / NetApp
MSIX App Attach + FSLogix App Masking
Measured concurrency-driven autoscaling
The 40-60% range comes from sizing pooled hosts to peak concurrent users instead of one VM per head; your number lands in the capacity model before you commit. The kit counts are real files, browsable below.
When the desktop should live in Azure, and not on the laptop.
Contractor- and BYOD-heavy teams
External people need real tools, and their laptops are not yours to manage. AVD gives them a contained session: work happens inside the boundary, nothing lands on the device.
Regulated data on the move
DORA or NIS2 scope with hybrid work on top. Sessions stream from an EU region with redirections off and watermarking on; the data never commutes.
Seasonal and campaign concurrency
Fifty agents in November, twelve in February. Pooled hosts plus autoscale mean the estate follows the calendar instead of billing for the peak all year.
The stuck AVD pilot
Licensed a year ago, one PoC VM, no production path. The usual blockers are images and profiles nobody standardised, and both have a module in the kit.
The boundary, the schedule, and the kit that ships both.
Three views of the same engagement: the session topology the Terraform deploys, the autoscale schedule that owns the bill, and the actual delivery kit, folder by folder. When a prospect asks "what do we actually get?", this is the answer.
Four artefacts, all in your repository.
Working host pools, documented image lifecycle
Pooled Windows 11 multi-session estate from versioned golden images. Hosts are cattle; RUNBOOK-03 is the only path to change, rollback version always kept.
Autoscale with a measured cost curve
The scaling plan follows your sign-in storm, and the monthly review reports euros per concurrent-user-hour and warm-idle ratio against a target under 15%.
Runbooks and evidence in your repo
Ten operating procedures, the security baseline checklist and a 12-control mapping matrix for DORA, NIS2 and ISO 27001, committed next to the Terraform.
A 12-month capacity and cost model
Concurrency-based projection from discovery data, refreshed by the monthly report, so the bill is a forecast you check rather than a surprise you explain.
In scope
- Host-pool topology + capacity model
- Image pipeline (Compute Gallery + Packer / AIB)
- FSLogix profile + Office container deployment
- Autoscaling with measured cost curve
- App delivery pipeline (MSIX / FSLogix App Masking)
Deliberately out of scope
- End-user training (separate Adoption engagement)
- Custom in-session app development
- Citrix licensing procurement (we integrate; you license)
- ISV migration to AVD-compatible packaging (case-by-case)
Pilot first. Then fixed scope, never T&M.
The tier scope sheet gets signed during discovery, so "what is included" is a document, never a memory.
Essential
Design plus a two-week pilot with real users.
- Discovery questionnaire + capacity model
- ADR set: topology, region, FSLogix, image strategy
- Security baseline gap read
- Pilot host pool with 5-10 real users for two weeks
- Go / no-go memo with measured sign-in and cost numbers
Outcome
You know how AVD behaves with your users and your apps before committing.
Implementation
The production estate, wired, evidenced and handed over.
- Terraform library deployed into your GitHub organisation
- Host pools, FSLogix premium storage, scaling plan per the ADRs
- Image pipeline with Compute Gallery + first golden image
- App delivery (MSIX App Attach / on-image per inventory)
- Runbooks 01-10, baseline verified, Exit Kit included
Outcome
A production AVD estate your team can operate from the runbooks alone.
Operate
We run the platform discipline. Your users just sign in.
- Monthly cost-vs-concurrency report with one proposed change
- Monthly image rolls with pilot-group validation
- Scaling plan tuning as working patterns move
- Quarterly baseline re-check + control matrix refresh
- Single Slack channel to the engineer who built it
Outcome
Sign-in stays fast and the bill stays boring, quarter after quarter.
Honest answers to the questions buyers actually ask.
AVD or Windows 365?
+
Different problems. Windows 365 = per-user assigned Cloud PC, simple billing, low-flex. AVD = pooled, dense, cost-efficient at scale but more operational overhead. We help you pick (or run both) based on user personas and total cost.
Can we run AVD on Azure for Citrix workloads too?
+
Yes - Citrix DaaS on Azure is supported. We design the integration points (image, FSLogix, networking) regardless of the brokering layer.
What about GPU workloads?
+
NV-series host pools with verified driver chain for 3D / video / engineering use cases. We benchmark before committing to a SKU.
Why is our current AVD bill so unpredictable?
+
Almost always one of two things: hosts sized to headcount instead of measured concurrency, or autoscale never enabled because nobody trusted it with live sessions. The kit fixes both: the capacity model sizes to peak concurrency, and the scaling plan drains hosts only at zero active sessions, so there is nothing to be afraid of.
Do our E3 / E5 / Business Premium licences already cover AVD?
+
For Windows 11 Enterprise multi-session access rights: yes, those licences carry them (confirmed against current Microsoft terms during discovery). What you pay on top is Azure compute and storage, which is exactly the part the capacity model and autoscale keep honest.
Can contractors use it from personal devices?
+
That is one of the main reasons to run AVD. Contractors get browser access to published apps only: no client install, no drive or clipboard redirection, access that expires on the project end date by default. RUNBOOK-07 in the kit is this exact flow.
Who actually does the work?
+
One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person holding the Terraform plan.
AVD rarely travels alone.
Secure Remote Workforce
The full architecture narrative: AVD plus Microsoft 365 hardening and the two enforcement tiers.
OpenAzure Cloud Infrastructure
The landing zone underneath: the AVD spoke consumes networking and governance from this kit.
OpenMicrosoft 365 Tenant Hardening
Conditional Access and identity baseline that the AVD session boundary builds on.
OpenSize the host pools against real session data, not a licence count.
Bring the usage export. We size the pools, set the scaling window and agree what happens to a profile when a session host is rebuilt.