Blog
Managing VDI and Azure VMs with Intune: what's possible and what's not
Learn what Intune can manage across VDI and Azure VMs, where support stops, and how deployment enrollment choices affect session hosts.
G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog
Blog
Learn what Intune can manage across VDI and Azure VMs, where support stops, and how deployment enrollment choices affect session hosts.
Table of Contents
You checked "Enroll the VM with Intune" on a new host pool, and half the session hosts never appeared in the admin center. Windows 365 Cloud PCs use Microsoft Intune, as can Azure Virtual Desktop session hosts running Windows client operating systems, but Intune doesn't support Windows Server. So how do you manage VDI (virtual desktop infrastructure) and Azure VMs using Intune?
This guide is for enterprise VDI platform owners and Intune administrators troubleshooting enrollment or planning cloud desktop management. Windows Cloud is Microsoft's umbrella term for Windows 365 and Azure Virtual Desktop; many enterprises use both.
Intune's reach across VDI and Azure VMs comes down to three choices made before a host ever boots. The operating system on the VM, the join type, and whether enrollment was configured at deployment together determine what Intune can manage.
Personal session hosts inherit the Intune estate already running in the tenant, multi-session hosts work inside a narrow prerequisite envelope, and Windows Server VMs sit outside Intune entirely. When those choices go wrong, redeployment is usually the fix.
Intune's supported platforms include Windows 11 and Windows 10 Enterprise and other client editions, including Windows 365 Cloud PCs. That supported-platform list covers client editions only.
Windows Server admins should use Azure Arc instead. Microsoft's Entra sign-in documentation states that "Windows Server VMs don't support MDM enrollment."
Azure Arc-enabled servers lets administrators manage Windows Server outside Azure. The service "isn't designed or supported to enable management of virtual machines running in Azure," and its prerequisites also recommend against running it on short-lived VDI VMs. For server VMs native to Azure, Azure Update Manager handles patching for machines running a server operating system, with no additional license required. Defender for Servers adds security coverage, with automatic Defender for Endpoint onboarding.
Azure Update Manager doesn't cover Windows 10 and Windows 11 client operating systems, so Intune picks up those workloads. Even then, Microsoft advises against using Intune to manage on-demand session-host VMs in the non-persistent VDI pattern, because administrators must enroll each VM at creation and regular deletion leaves orphaned device records behind.
The table below summarizes which service manages each workload.
| Workload | Management path |
| Windows 365 Cloud PCs | Microsoft Intune (automatic on Enterprise) |
| Azure Virtual Desktop hosts (Windows Enterprise, personal or multi-session) | Microsoft Intune |
| Windows Server VMs in Azure | Azure Update Manager plus Defender for Servers |
| Windows Server on-premises or in other clouds | Azure Arc |
| Non-persistent, on-demand VDI VMs | Intune not recommended by Microsoft |
| Azure Virtual Desktop hosts running Windows Server | Entra hybrid join plus Group Policy (Intune unsupported) |
Nerdio Manager for Enterprise manages Intune configuration profiles for Cloud PCs and session hosts. On that client-OS side, what Intune can do narrows sharply between personal and multi-session hosts.
Personal hosts behave like physical desktops, while multi-session hosts work under extra prerequisites. Microsoft's guidance for session host operating systems reads: "We recommend using Microsoft Intune to manage your Azure Virtual Desktop environment."
Per Microsoft: "Intune treats Azure Virtual Desktop personal VMs the same as Windows Enterprise physical desktops." Your supported existing configuration profiles and compliance policies apply without rework, and Conditional Access evaluates these VMs like any other Windows device.
Microsoft Entra joined hosts enroll by enabling "Enroll the VM with Intune" in the Azure Portal at deployment. Microsoft Entra hybrid joined hosts enroll through Active Directory Group Policy Object (GPO) auto-enrollment or Configuration Manager co-management. Users can also self-enroll. Hosts must sit in the same tenant as Intune.
Intune does not support Domain Join or Wi-Fi profile types on these hosts. It also excludes remote actions built for hardware someone can lose, such as Wipe and Fresh Start.
Windows 10 and Windows 11 multi-session hosts enroll when all of these hold:
Enrollment enables the four supported Intune workload areas below.
If your Entra joined session hosts store FSLogix profile containers on Azure Files, you must configure the Kerberos/CloudKerberosTicketRetrievalEnabled policy CSP and use the Intune Settings Catalog, the only supported delivery path.
Microsoft explicitly rejects manually adding the registry key. Without enrollment, profile containers fail to mount. Microsoft has also published the FSLogix administrative template in the Settings Catalog for enrolled hosts.
Personal hosts inherit the Intune estate you already run. Multi-session hosts work only inside a narrow prerequisite envelope, and on Entra joined hosts with FSLogix containers on Azure Files, enrollment stops being optional. Where that envelope ends, so does Intune's reach on pooled multi-session hosts.
Multi-session hosts carry more exclusions than physical desktops. Many of these exclusions produce the same confusing outcome. A policy reports Succeeded in the admin center and nothing changes on the host, or the assignment shows Not applicable without any explanation.
Nerdio Manager reduces the operational burden around supported image and application workflows through desktop orchestration and unified application management, but it doesn't change Microsoft's support boundaries.
Several of these exclusions are deployment-time constraints.
The AADLoginForWindows VM extension carries an MdmId parameter that triggers enrollment during the join. For multi-session hosts that were Entra joined without that option, Microsoft Q&A answers state that Microsoft provides no native post-deployment enrollment method for Entra joined multi-session hosts.
Hybrid joined hosts can retrofit enrollment through Active Directory Group Policy configured for auto-enrollment with device credentials or through Configuration Manager co-management. Enrollment using user credentials fails on multi-session hosts.
The image-preparation sequence runs dsregcmd /leave, strips MDM traces, then runs sysprep and publishes to the Azure Compute Gallery so each new host enrolls itself at deployment.
The same discipline applies at scale-in. Administrators should delete the Intune device object and the Entra ID device object before destroying a host. Intune's default device enrollment limit also caps bulk provisioning; raising it under enrollment restrictions belongs on the pre-rollout checklist.
Nerdio Manager automates the image patching and host redeploy cycle through desktop orchestration. Windows 365 makes that decision for you at provisioning, which moves the management work rather than removing it.
Windows 365 Enterprise Cloud PCs enroll in Intune automatically during provisioning, while Azure Virtual Desktop session hosts require enrollment to be configured at deployment or through Group Policy. Windows 365 Enterprise Cloud PCs appear under Devices > All devices with an enrollment profile name matching the provisioning policy.
Windows 365 Business is the exception. Those Cloud PCs aren't automatically enrolled in Intune, and their managedDeviceId property is always null. The Windows 365 side trades deployment-time choices for ongoing Intune work.
A provisioning policy in the Intune admin center orchestrates Cloud PC creation and includes a Windows Update management choice of Windows Autopatch, None, or Windows Autopilot (in preview). Point-in-time restore returns a Cloud PC to its exact earlier state.
The table below compares how enrollment, provisioning, and Autopilot work across the two products.
| Capability | Windows 365 | Azure Virtual Desktop |
| Intune enrollment | Automatic during provisioning (Enterprise) | Configured at deployment or via Group Policy |
| Provisioning construct | Provisioning policy in Intune | ARM host pools, outside Intune |
| Autopilot | Device preparation GA with provisioning | Out-of-box experience and Autopilot unsupported on multi-session |
Centralized RDP Shortpath configuration through Intune reached general availability in January 2026 and covers both Cloud PCs and session hosts. Intune's February 2026 service release (2601) extended Endpoint Privilege Management elevation policies to users on single-session Azure Virtual Desktop VMs.
As of July 1, 2026, advanced Intune Suite capabilities are included in Microsoft 365 E5, with select capabilities in Microsoft 365 E3, including Remote Help and Advanced Analytics along with Intune Plan 2. On the E5 side that extends to Endpoint Privilege Management, Cloud PKI, and Enterprise App Management. Licensing terms change, so confirm current entitlements against Microsoft's licensing pages before you plan around them.
When organizations run products side by side, both enrollment models live in the same tenant. Policy routes through Intune for both products, but day-to-day operations still span Microsoft Intune, Azure Portal, PowerShell, and Entra ID.
Nerdio Manager deploys inside your Azure tenant, and manages Windows 365, Intune, and Azure Virtual Desktop from a single console. Across both products, one management workflow covers desktop orchestration, Cloud PC application deployment, image sharing, and Intune policy controls.
On the Azure Virtual Desktop side, desktop orchestration automates image patching and staged testing across Microsoft Marketplace, custom, and Azure Compute Gallery images. An independent benchmark from Dr. Tritsch IT Consulting measured a custom image update at 37 seconds and 13 clicks in Nerdio Manager, against 5 minutes 9 seconds and 146 clicks with native tooling: 88% less time and 91% fewer clicks. Reimaging session hosts took 85% less time and 89% fewer clicks in the same benchmark. Fewer clicks also means fewer manual steps where a configuration error can slip into an image that hundreds of users inherit.
On the Windows 365 side, Nerdio's unified application management deploys applications to Cloud PCs in roughly 30 seconds, against native Intune delivery that can take up to three hours. For the Intune layer both products share, Nerdio Manager can back up and restore Intune policies, including deleted policies.
Image and application work stops being the part of the week that consumes a platform owner's attention, while Microsoft's support boundaries stay exactly where they were.
Missing session hosts usually require redeployment. Hybrid joined pools are the recoverable case because they can use Group Policy auto-enrollment with device credentials.
The join type and enrollment path should be settled before the first host pool deploys. The Settings Catalog becomes the primary Intune policy path for multi-session hosts, and device object cleanup belongs in every scale-in runbook.
Get a demo to see how Nerdio Manager works across your Windows 365 and Azure Virtual Desktop environment, or try it free in your Azure tenant.
No. Azure Update Manager patches native Azure server VMs, and Microsoft Defender for Servers secures them. Azure Arc covers Windows Server machines outside Azure and isn't supported for managing native Azure VMs.
Yes. Intune supports Windows 10 and Windows 11 Enterprise multi-session hosts when they meet the core ARM deployment, supported join and enrollment, agent version, tenant, MDM provider, and golden-image prerequisites covered above.
Most device configuration policies must come from the Settings Catalog; supported certificate and Device Tunnel VPN templates are exceptions. Apps deploy in device context with Required or Uninstall intent, and Intune doesn't support Windows Update ring policies.
Windows 365 Enterprise Cloud PCs enroll automatically during provisioning and appear in the Intune admin center under an enrollment profile named after their provisioning policy. Windows 365 Business Cloud PCs do not enroll automatically; their managedDeviceId property is always null.
You need both an eligible Azure Virtual Desktop entitlement and an Intune license. Microsoft's rule: "The appropriate Azure Virtual Desktop and Microsoft Intune license is required if a user or device benefits directly or indirectly from the Microsoft Intune service." In practice, eligible licenses include Microsoft 365 E3, E5, E7, A3, A5, F3, and Business Premium, and Student Use Benefit, plus Windows Enterprise E3/E5, Windows Education A3/A5, and Windows VDA per user. Microsoft 365 E3 includes Intune Plan 1.
Learn more about Nerdio Manager