Skip to main content

G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog

Blog

Managing VDI and Azure VMs with Intune: what's possible and what's not

Learn what Intune can manage across VDI and Azure VMs, where support stops, and how deployment enrollment choices affect session hosts.

You checked "Enroll the VM with Intune" on a new host pool, and half the session hosts never appeared in the admin center. Windows 365 Cloud PCs use Microsoft Intune, as can Azure Virtual Desktop session hosts running Windows client operating systems, but Intune doesn't support Windows Server. So how do you manage VDI (virtual desktop infrastructure) and Azure VMs using Intune?

This guide is for enterprise VDI platform owners and Intune administrators troubleshooting enrollment or planning cloud desktop management. Windows Cloud is Microsoft's umbrella term for Windows 365 and Azure Virtual Desktop; many enterprises use both.

Intune's reach across VDI and Azure VMs comes down to three choices made before a host ever boots. The operating system on the VM, the join type, and whether enrollment was configured at deployment together determine what Intune can manage.

Personal session hosts inherit the Intune estate already running in the tenant, multi-session hosts work inside a narrow prerequisite envelope, and Windows Server VMs sit outside Intune entirely. When those choices go wrong, redeployment is usually the fix.

Intune manages Windows client operating systems, not every Azure VM

Intune's supported platforms include Windows 11 and Windows 10 Enterprise and other client editions, including Windows 365 Cloud PCs. That supported-platform list covers client editions only.

Windows Server admins should use Azure Arc instead. Microsoft's Entra sign-in documentation states that "Windows Server VMs don't support MDM enrollment." 

Azure Arc-enabled servers lets administrators manage Windows Server outside Azure. The service "isn't designed or supported to enable management of virtual machines running in Azure," and its prerequisites also recommend against running it on short-lived VDI VMs. For server VMs native to Azure, Azure Update Manager handles patching for machines running a server operating system, with no additional license required. Defender for Servers adds security coverage, with automatic Defender for Endpoint onboarding.

Azure Update Manager doesn't cover Windows 10 and Windows 11 client operating systems, so Intune picks up those workloads. Even then, Microsoft advises against using Intune to manage on-demand session-host VMs in the non-persistent VDI pattern, because administrators must enroll each VM at creation and regular deletion leaves orphaned device records behind.

The table below summarizes which service manages each workload.

Workload

Management path

Windows 365 Cloud PCs

Microsoft Intune (automatic on Enterprise)

Azure Virtual Desktop hosts (Windows Enterprise, personal or multi-session)

Microsoft Intune

Windows Server VMs in Azure

Azure Update Manager plus Defender for Servers

Windows Server on-premises or in other clouds

Azure Arc

Non-persistent, on-demand VDI VMs

Intune not recommended by Microsoft

Azure Virtual Desktop hosts running Windows Server

Entra hybrid join plus Group Policy (Intune unsupported)

 

Nerdio Manager for Enterprise manages Intune configuration profiles for Cloud PCs and session hosts. On that client-OS side, what Intune can do narrows sharply between personal and multi-session hosts.

What Intune supports on Azure Virtual Desktop session hosts

Personal hosts behave like physical desktops, while multi-session hosts work under extra prerequisites. Microsoft's guidance for session host operating systems reads: "We recommend using Microsoft Intune to manage your Azure Virtual Desktop environment."

Personal session hosts are managed like physical desktops

Per Microsoft: "Intune treats Azure Virtual Desktop personal VMs the same as Windows Enterprise physical desktops." Your supported existing configuration profiles and compliance policies apply without rework, and Conditional Access evaluates these VMs like any other Windows device.

Microsoft Entra joined hosts enroll by enabling "Enroll the VM with Intune" in the Azure Portal at deployment. Microsoft Entra hybrid joined hosts enroll through Active Directory Group Policy Object (GPO) auto-enrollment or Configuration Manager co-management. Users can also self-enroll. Hosts must sit in the same tenant as Intune.

Intune does not support Domain Join or Wi-Fi profile types on these hosts. It also excludes remote actions built for hardware someone can lose, such as Wipe and Fresh Start.

Multi-session hosts enroll under stricter prerequisites

Windows 10 and Windows 11 multi-session hosts enroll when all of these hold:

  • Pooled multi-session host pool deployed through Azure Resource Manager (ARM) templates (classic host pools don't qualify)
  • Microsoft Entra joined, or Microsoft Entra hybrid joined with enrollment via device credentials (user credentials fail)
  • Azure Virtual Desktop agent version 1.0.2944.1400 or later
  • Same tenant as Intune, with a single mobile device management (MDM) provider
  • A golden image that was never enrolled before capture

Enrollment enables the four supported Intune workload areas below.

  • Device configuration: Settings Catalog filtered to the Enterprise multi-session OS edition and assigned to device groups. User-group assignment reports as Error or Not applicable.
  • User-scope configuration (generally available): Settings Catalog assigned to user groups and user certificates. Support also extends to user-context PowerShell scripts. Windows 10 multi-session requires KB5023773 update (OS build 19042.2788, 19044.2788, or 19045.2788 or later), per the previously cited session host operating systems guidance from Microsoft.
  • Compliance: Intune supports device-scope targeting. These checks cover OS version and build validity. They also cover password and Microsoft Defender health settings. Everything else reports as Not applicable.
  • Conditional Access: Both user-based and device-based configurations work.

FSLogix makes Intune enrollment effectively mandatory on Entra joined hosts

If your Entra joined session hosts store FSLogix profile containers on Azure Files, you must configure the Kerberos/CloudKerberosTicketRetrievalEnabled policy CSP and use the Intune Settings Catalog, the only supported delivery path.

Microsoft explicitly rejects manually adding the registry key. Without enrollment, profile containers fail to mount. Microsoft has also published the FSLogix administrative template in the Settings Catalog for enrolled hosts.

Personal hosts inherit the Intune estate you already run. Multi-session hosts work only inside a narrow prerequisite envelope, and on Entra joined hosts with FSLogix containers on Azure Files, enrollment stops being optional. Where that envelope ends, so does Intune's reach on pooled multi-session hosts.

Where Intune stops on multi-session hosts

Multi-session hosts carry more exclusions than physical desktops. Many of these exclusions produce the same confusing outcome. A policy reports Succeeded in the admin center and nothing changes on the host, or the assignment shows Not applicable without any explanation.

  • Enrollment
    Intune rejects cloned images of an already-enrolled machine, because replicating enrollment or identity tokens between devices causes enrollment or synchronization failures. Intune does not support Windows Autopilot, out-of-box experience (OOBE) enrollment, or the enrollment status page. Intune cannot manage hosts joined to Microsoft Entra Domain Services.
  • Policy templates
    Intune supports only certificate and Device Tunnel VPN configuration profile templates, and some ADMX-ingested settings don't apply to the multi-session edition. The Defender security baseline is "optimized for physical devices and is currently not recommended for use on virtual machines (VMs) or VDI endpoints."
  • Updates
    Administrators manage quality updates on these hosts through individual Settings Catalog settings because Intune doesn't support Windows Update ring policies. Microsoft recommends managing updates inside the core source image rather than pushing them to each session host individually.
  • Apps and scripts
    Apps must use Required or Uninstall intent (Available isn't supported), install in system/device context, and target devices. Web apps always apply in user context, so they never reach multi-session VMs.
  • Hybrid coexistence
    When the same setting arrives from both Group Policy and Intune, two management authorities can be challenging if they aren't properly orchestrated. A Microsoft moderator put it plainly about the MDMWinsOverGP workaround: "We strongly recommend that you avoid using this policy setting." The durable fix is to stop targeting the same settings from both authorities.

Nerdio Manager reduces the operational burden around supported image and application workflows through desktop orchestration and unified application management, but it doesn't change Microsoft's support boundaries.

Several of these exclusions are deployment-time constraints.

Enrollment decisions lock in at deployment

The AADLoginForWindows VM extension carries an MdmId parameter that triggers enrollment during the join. For multi-session hosts that were Entra joined without that option, Microsoft Q&A answers state that Microsoft provides no native post-deployment enrollment method for Entra joined multi-session hosts.

Hybrid joined hosts can retrofit enrollment through Active Directory Group Policy configured for auto-enrollment with device credentials or through Configuration Manager co-management. Enrollment using user credentials fails on multi-session hosts.

The image-preparation sequence runs dsregcmd /leave, strips MDM traces, then runs sysprep and publishes to the Azure Compute Gallery so each new host enrolls itself at deployment.

The same discipline applies at scale-in. Administrators should delete the Intune device object and the Entra ID device object before destroying a host. Intune's default device enrollment limit also caps bulk provisioning; raising it under enrollment restrictions belongs on the pre-rollout checklist.

Nerdio Manager automates the image patching and host redeploy cycle through desktop orchestration. Windows 365 makes that decision for you at provisioning, which moves the management work rather than removing it.

Windows 365 and Azure Virtual Desktop take different enrollment paths

Windows 365 Enterprise Cloud PCs enroll in Intune automatically during provisioning, while Azure Virtual Desktop session hosts require enrollment to be configured at deployment or through Group Policy. Windows 365 Enterprise Cloud PCs appear under Devices > All devices with an enrollment profile name matching the provisioning policy.

Windows 365 Business is the exception. Those Cloud PCs aren't automatically enrolled in Intune, and their managedDeviceId property is always null. The Windows 365 side trades deployment-time choices for ongoing Intune work.

A provisioning policy in the Intune admin center orchestrates Cloud PC creation and includes a Windows Update management choice of Windows Autopatch, None, or Windows Autopilot (in preview). Point-in-time restore returns a Cloud PC to its exact earlier state.

The table below compares how enrollment, provisioning, and Autopilot work across the two products.

Capability

Windows 365

Azure Virtual Desktop

Intune enrollment

Automatic during provisioning (Enterprise)

Configured at deployment or via Group Policy

Provisioning construct

Provisioning policy in Intune

ARM host pools, outside Intune

Autopilot

Device preparation GA with provisioning

Out-of-box experience and Autopilot unsupported on multi-session

 

Centralized RDP Shortpath configuration through Intune reached general availability in January 2026 and covers both Cloud PCs and session hosts. Intune's February 2026 service release (2601) extended Endpoint Privilege Management elevation policies to users on single-session Azure Virtual Desktop VMs.

As of July 1, 2026, advanced Intune Suite capabilities are included in Microsoft 365 E5, with select capabilities in Microsoft 365 E3, including Remote Help and Advanced Analytics along with Intune Plan 2. On the E5 side that extends to Endpoint Privilege Management, Cloud PKI, and Enterprise App Management. Licensing terms change, so confirm current entitlements against Microsoft's licensing pages before you plan around them.

When organizations run products side by side, both enrollment models live in the same tenant. Policy routes through Intune for both products, but day-to-day operations still span Microsoft Intune, Azure Portal, PowerShell, and Entra ID.

One console across Windows 365, Intune, and Azure Virtual Desktop

Nerdio Manager deploys inside your Azure tenant, and manages Windows 365, Intune, and Azure Virtual Desktop from a single console. Across both products, one management workflow covers desktop orchestration, Cloud PC application deployment, image sharing, and Intune policy controls.

On the Azure Virtual Desktop side, desktop orchestration automates image patching and staged testing across Microsoft Marketplace, custom, and Azure Compute Gallery images. An independent benchmark from Dr. Tritsch IT Consulting measured a custom image update at 37 seconds and 13 clicks in Nerdio Manager, against 5 minutes 9 seconds and 146 clicks with native tooling: 88% less time and 91% fewer clicks. Reimaging session hosts took 85% less time and 89% fewer clicks in the same benchmark. Fewer clicks also means fewer manual steps where a configuration error can slip into an image that hundreds of users inherit.

On the Windows 365 side, Nerdio's unified application management deploys applications to Cloud PCs in roughly 30 seconds, against native Intune delivery that can take up to three hours. For the Intune layer both products share, Nerdio Manager can back up and restore Intune policies, including deleted policies.

Image and application work stops being the part of the week that consumes a platform owner's attention, while Microsoft's support boundaries stay exactly where they were.

What this means for your session host architecture

Missing session hosts usually require redeployment. Hybrid joined pools are the recoverable case because they can use Group Policy auto-enrollment with device credentials.

The join type and enrollment path should be settled before the first host pool deploys. The Settings Catalog becomes the primary Intune policy path for multi-session hosts, and device object cleanup belongs in every scale-in runbook.

Get a demo to see how Nerdio Manager works across your Windows 365 and Azure Virtual Desktop environment, or try it free in your Azure tenant.

Frequently asked questions about managing VDI and Azure VMs using Intune

Ready to get started?