Fix it now
Azure Virtual Desktop is not a licence you buy and install. Microsoft runs the broker, gateway and diagnostics; you run the session hosts in your own Azure subscription; and the right for a user to connect comes from a licence most organisations already hold. That makes it flexible, and makes the bill a question of who is watching it.
- Buy into it if you already run in Azure and have somebody to size virtual machines, maintain an image and read a cost report.
- Buy into it when multi-session works. Windows 11 and Windows 10 Enterprise multi-session are exclusive to Azure Virtual Desktop, and density is where the savings come from.
- Buy into it when you want to publish individual applications rather than whole desktops, or when demand is seasonal and autoscale can switch hosts off.
- Skip it if nobody owns the platform. Every saving depends on tuning that has to be done and then redone.
- Skip it if you want one predictable figure per user. Windows 365 exists for that and costs less in staff time.
- Check what your users already hold before buying anything. Microsoft 365 E3, E5, A3, A5, F3 and Business Premium all grant the access right, as do Windows Enterprise E3 and E5, Windows Education A3 and A5, and Windows VDA per user.
Session hosts running Windows Server are covered differently: by RDS client access licences with Software Assurance or RDS User Subscription Licences. Microsoft states that per-user access pricing is not supported for Windows Server operating systems.
If that settles it you can stop here. If you want the licensing table, the cost levers and the administrative load stated plainly, keep reading.
Why it happens
The split of responsibility is the first thing to understand, because everything else follows from it. Microsoft manages the supporting infrastructure roles: the broker that places sessions, the gateway that admits remote clients without you publishing anything to the internet, the web client and the diagnostics. You manage the image and the session host virtual machines in your own Azure subscription, plus profile storage so users get their settings on whichever host they land on, a network, and an identity arrangement that lets those hosts authenticate people. What you pay for is the Azure resources you run and the per-user access licence, not a product licence for the service itself.
Two host pool types cover most needs. Pooled host pools put several users on each session host and load-balance new connections, which is where density savings come from. Personal host pools assign one host permanently to one user, which is what you use for developers and for applications that will not tolerate sharing. Within a pool you publish either a full desktop or an application group of individual programs, so somebody can run one line-of-business application in a window on their own machine without ever seeing a remote desktop.
Windows 11 and Windows 10 Enterprise multi-session are the reason this product exists at the price it does. Microsoft describes multi-session as exclusive to Azure Virtual Desktop: a client Windows build that accepts concurrent interactive sessions, letting you serve a room of call handlers from a handful of machines. It is not available in Windows 365, where a Cloud PC is a dedicated single-session desktop. Density is where money is saved and where the experience is lost if you are optimistic, so test with real people on a real working day rather than with a synthetic load.
Compute hours dominate almost every bill. After that come profile storage, log ingestion where the monitoring workbooks are on, and egress. The levers are well known and each needs somebody to pull it: right-size the virtual machine family rather than copying the last project, add a scaling plan so hosts drain and shut down outside working hours, commit to reservations for the baseline you always need, use ephemeral operating system disks where the image allows, and turn on start-on-connect so the first user of the morning wakes a host rather than you paying overnight for one nobody used.
The lever most teams never touch is session density. Moving from six users per host to eight saves more than any purchasing decision, and it stays invisible until somebody measures processor queue length and memory pressure under real load. The counterweight is FSLogix profile containers, which grow quietly because the Outlook and Teams caches live inside them. Size that storage for the containers you will have in a year rather than the ones you have in week one.
The identity requirements are worth stating because they catch people at design time rather than at run time. Users need accounts in Microsoft Entra ID, and where you use Active Directory Domain Services or Microsoft Entra Domain Services those accounts must be hybrid identities. Session hosts must be joined to Microsoft Entra ID, to AD DS, or to Microsoft Entra Domain Services. A design that assumes cloud-only accounts against a domain-joined host pool will not work, and finding that out late is expensive.
Full reference
The licences that grant access
| What you hold | What it covers |
|---|---|
| Microsoft 365 E3, E5, A3, A5, F3, Business Premium or Student Use Benefit | Windows client session hosts, single-session and multi-session |
| Windows Enterprise E3 or E5, Windows Education A3 or A5, Windows VDA per user | Windows client session hosts, single-session and multi-session |
| RDS CALs with Software Assurance, or RDS User Subscription Licences | Session hosts running Windows Server rather than Windows client |
| Per-user access pricing on an enrolled Azure subscription | External commercial users. Microsoft states this is not supported for Windows Server |
| An Azure subscription | The virtual machines, disks, storage and network you run, billed on consumption |
Two consequences follow. If your staff hold Microsoft 365 Business Premium, E3 or E5, the access right is already yours and anyone telling you to buy something extra is selling you what you own. And people employed by somebody else are not covered by your staff licences: the published route for them is per-user access pricing on an enrolled Azure subscription, which is a separate decision to make before you design around contractor access.
Supported session host operating systems
- Windows 11 Enterprise and Windows 11 Enterprise multi-session.
- Windows 10 Enterprise and Windows 10 Enterprise multi-session.
- Windows Server 2025, 2022, 2019 and 2016.
- All of them 64-bit only. There is no 32-bit session host option.
The administrative work, stated plainly
- Maintain a golden image through Azure Compute Gallery with versioning, and rebuild it on a schedule rather than patching hosts in place.
- Replace session hosts on a cycle, with a way to drain sessions before you do.
- Watch FSLogix container growth and the Office and Teams caches inside it.
- Package applications through app attach or bake them into the image, and decide which of the two you are going to maintain.
- Tune the scaling plan seasonally, because the schedule that suited November is wrong in July.
- Protect the workspace with Conditional Access and multifactor authentication, since the gateway is reachable from anywhere by design.
Repointing FSLogix at a new share without migrating containers, or deleting the profile storage, loses user profiles. Back up the share and test a restore before any change to it. The failure mode is every user signing in to an empty desktop at once, on the same morning.
Where the money actually goes
| Cost line | The lever | Who has to pull it |
|---|---|---|
| Session host compute hours | Right-sizing, scaling plans, start-on-connect, reservations | Whoever owns the platform |
| Profile storage | Container sizing and cache management inside FSLogix | The same person |
| Log ingestion | Deciding which diagnostics you actually read | The same person |
| Egress | Architecture, not tuning | Whoever designed it |
| Access licences | Already covered for most staff; per-user access pricing for external users | Licensing |
When Windows 365 is simply the better answer
- Nobody owns the Azure platform, and nobody is going to.
- Demand is steady, so there is nothing for autoscale to save.
- You want one predictable figure per user that finance can plan against.
- The estate is small enough that the tuning effort outweighs the density saving.
- You need the desktop to exist for a named person with their own settings, rather than a pooled seat.
When a licence is the actual fix
Most readers of this article should buy nothing. If your users hold Microsoft 365 Business Premium, E3, E5, F3, A3 or A5, or Windows Enterprise E3 or E5, or Windows VDA per user, the access right is already yours and the only bill is Azure consumption. A purchase is genuinely needed in the gap cases: users on Business Standard or Apps-only plans who need a qualifying Windows or Microsoft 365 licence before they may connect, and estates whose session hosts run Windows Server, which need RDS CALs with Software Assurance or RDS User Subscription Licences. Arco can supply the Microsoft 365 licences required for Azure Virtual Desktop and the RDS licensing where Windows Server is the host, and will say plainly when you already have what you need. If the honest answer for your size is Windows 365 rather than a host pool nobody has time to run, we would rather tell you that.
Questions people ask about this
Is Azure Virtual Desktop cheaper than Windows 365?
It can be, for uneven demand with somebody to tune it. It is not automatically cheaper, and an untuned deployment running hosts around the clock usually costs more than the equivalent Cloud PCs. Compare a modelled cost including staff time against a Windows 365 quote rather than comparing sticker figures.
Can I get multi-session Windows in Windows 365 instead?
No. Microsoft describes Windows 11 and Windows 10 Enterprise multi-session as exclusive to Azure Virtual Desktop. A Windows 365 Cloud PC is a dedicated single-session desktop, and Windows 365 Flex shares licences non-concurrently rather than sharing a host.
How do we license contractors who are not our employees?
Not through your staff licences. Microsoft publishes per-user access pricing, enabled by enrolling an Azure subscription, for external commercial purposes. Note that it is not supported for Windows Server session hosts, so a Windows Server host pool needs RDS licensing instead.
Do we still need a VPN?
Not for the desktop connection itself; the gateway handles that. You do need connectivity from the session hosts to any on-premises resources they use, which usually means a site-to-site VPN or ExpressRoute from the Azure network to yours.
What causes most surprise bills?
Hosts that never turn off. A scaling plan, a drain policy and start-on-connect remove most of the waste and none of them is difficult. Second place goes to oversized virtual machines chosen before anybody measured the workload.
