A practical Windows 365 engineering guide. Start with a small pilot, record what happens, and use the same checks before a wider rollout. The repository separates Business lab observations from Enterprise procedures that still need live validation.
New to Windows 365? Read the fundamentals, then follow the first Cloud PC lab. The use-case numbers are permanent topic IDs, not the order of deployment: the network decision (UC-03) and image choice (UC-13) come before provisioning (UC-02). The learning path lists every topic in the order to study it.
| Step | What you will decide or verify | Guide |
|---|---|---|
| 1. Prepare | License, tenant roles, pilot users, and success criteria | Tenant readiness |
| 2. Choose a network | Microsoft-hosted network or Azure network connection; Entra join or hybrid join | Network decision |
| 3. Provision | User group, license, image, policy, and Cloud PC state | Enterprise provisioning |
| 4. Manage | Enrollment, configuration, apps, security, updates, and access | Management path |
| 5. Operate | Support, lifecycle actions, user changes, and rollout | Operations path |
If you have no tenant access, you can still work through the architecture decisions and dry-run the lab worksheet. A real provisioning result requires your own eligible tenant, license, and pilot user. Start with the Microsoft-hosted network and gallery image to keep the first lab focused; build the Azure network connection variant only when a private network requirement calls for it.
Evidence status: Earlier Business lab work covered Intune enrollment, Edge and desktop settings, Company Portal, and creation of an update ring and compliance policy. No screenshots or logs from that lab are published here, so those observations cannot yet be independently verified. A dated Enterprise pilot check confirms one existing Provisioned Cloud PC, a successful pilot-user web session, Microsoft Entra join, its policy and Intune record. It does not show a newly run provisioning workflow or device-side policy and update results. Azure network connection, resize, move, restore, and reprovision remain documented procedures without completed tests. See the live validation status and evidence index before treating any procedure as a tested result.
| Option | Use when | Customer network work |
|---|---|---|
| Microsoft-hosted network + Microsoft Entra join | Cloud PCs mainly use internet, Microsoft 365, and SaaS apps; a separately tested VPN or private access client may reach private apps | No customer Azure network connection or subscription required for Cloud PC networking |
| Azure network connection + Microsoft Entra join | Cloud PCs need customer-controlled routing, private access, or egress | Plan VNet, subnet capacity, DNS, outbound access, and connection health |
| Azure network connection + hybrid join | AD DS device join is a firm application or policy requirement | Add domain-controller reachability, DNS, join permissions, and identity synchronization |
Choose one network option for each provisioning policy. The Cloud PC runs in the Windows 365 service; with an Azure network connection its virtual network interface attaches to the customer VNet. The Azure network connection does not place the Cloud PC VM in the customer's subscription. Microsoft's deployment options and Azure network connection overview explain the boundaries.
- UC-01: tenant readiness and pilot — define scope, roles, licenses, and acceptance checks.
- UC-03: network architecture — make the network and join decision before creating a provisioning policy.
- UC-13: image and application baseline — decide whether a gallery image meets the persona before building a custom image.
- UC-02: Enterprise provisioning — select image and network, assign a user group, monitor the first Cloud PC, and record evidence.
- UC-04: Intune enrollment and inventory — confirm device records and check-in before assigning more controls.
| Order | Guide | Result to capture |
|---|---|---|
| 1 | UC-05: configuration | Assignment and setting on the Cloud PC |
| 2 | UC-07: applications | Install state, detection, and uninstall result |
| 3 | UC-08: Windows servicing | Ring settings, update state, and restart behavior |
| 4 | UC-06: security and compliance | Policy result, device state, and failed checks |
| 5 | UC-14: local admin and LAPS | Local group membership and password rotation test |
| 6 | UC-09: Conditional Access | Report-only outcome, sign-in logs, and exclusions |
- UC-12: monitoring and troubleshooting — establish a support baseline and capture diagnostic facts.
- UC-10: lifecycle actions — test restart, resize, move, restore, and reprovision with a pilot.
- UC-11: joiner, mover, and leaver — handle group, license, and Cloud PC changes together.
- UC-15: production rollout — define personas, rollout rings, support ownership, cost checks, and continuity tests.
Each diagram has an editable draw.io source and SVG/PNG export. The network variants are separate so the Microsoft-hosted option is not mistaken for a customer VNet deployment.
| Diagram | Editable source | Preview |
|---|---|---|
| Enterprise overview | draw.io | SVG |
| Microsoft-hosted network | draw.io | SVG |
| Entra join with Azure network connection | draw.io | SVG |
| Hybrid join with Azure network connection | draw.io | SVG |
| Sign-in and Conditional Access | draw.io | SVG |
| Intune policy delivery | draw.io | SVG |
| Provisioning lifecycle | draw.io | SVG |
| Apps and updates | draw.io | SVG |
| User lifecycle | draw.io | SVG |
| Cloud PC actions | draw.io | SVG |
Start with the technical review path and Enterprise pilot gates. It identifies the design to inspect and the results still needed before a full Enterprise claim.
The coverage matrix tells you where a procedure is documented. It is not a test report. Use the evidence index to see what can be independently checked. Add screenshots only after removing tenant names, user details, addresses, and device identifiers. The architecture decisions and diagram review standard capture the reasoning behind the designs.
Run bash scripts/validation/validate-repository.sh to check diagram sources and exports, required sections, local links, evidence claims, and common publication mistakes. This is a repository check; it does not validate a tenant or prove a lab result.
- Windows 365 Enterprise documentation
- Windows 365 requirements
- Networking deployment options
- Create a provisioning policy
- Conditional Access for Windows 365
This is an independent engineering project. Verify portal steps against current Microsoft documentation before a production change. Original text and code use the repository MIT license; Microsoft architecture icons remain subject to Microsoft’s icon terms.