Day two of a Cloud PC fleet is mostly a fleet you already know how to run. The management plane is Intune, the policies are your policies, and what Windows 365 adds is three levers physical hardware never had: restore, resize, and reprovision.
The quiet payoff of the whole Windows 365 model arrives on day two. A Cloud PC enrolled in your tenant is a Windows endpoint like any other: your security baseline applies, your compliance policies evaluate, your Conditional Access framework gates its access, your update rings or Autopatch groups patch it, and Defender sees it. If you have worked through the Intune Deployment Guide on this site, the operating manual for your Cloud PCs is the one you already wrote. This article is about the parts that are genuinely new, and the small set of operating decisions they demand.
Restore is the lever that changes your incident playbook
Point-in-time restore is the capability I would defend hardest, because it changes what a bad day costs. The service keeps ten short-term restore points per Cloud PC at an interval you choose, anywhere from every four hours to every twenty-four, plus longer-term weekly points and one manual restore point you can create on demand before risky changes. That manual point is a single slot, overwritten by the next one and expiring after roughly four weeks, so treat it as a pre-change snapshot rather than an archive. Restore points can also be exported to your own storage account, which is the answer when an investigation needs to preserve a machine state.
Two operating decisions follow. First, the cadence: the four-hour interval covers the last forty hours in ten points, the twenty-four-hour interval covers ten days at coarser grain. I default to short intervals for populations doing volatile work and would rather lose reach than lose granularity, because the second decision constrains the first: restores get riskier with age. Machine account passwords, agent secrets, and certificates roll on their own schedules, and a restore point old enough to predate a credential rotation can produce a Cloud PC that boots but cannot trust anything. Restore to the newest point that predates the problem, and have the user sign in immediately to verify. Whether users may trigger their own restores is a judgment call per population; I grant it to technical users who understand what the rollback destroys and withhold it elsewhere, because a restore is a full-disk time machine, not an undo button.
Restore before you reprovision. One preserves the desktop and costs minutes; the other destroys it and costs the user their working world.
Reprovision is the other end of the spectrum: the Cloud PC is deleted and rebuilt to the current provisioning policy, everything local is gone, and the machine comes back as if newly born. It is the right tool for a handoff to a new user, for a failed provisioning, and for the rare machine you no longer trust at all. It is the wrong tool for almost everything a restore can fix, and the discipline of trying restore first is worth writing into the runbook, because reprovision is always available and always tempting to a hurried technician.
Resize is a licensing operation wearing a compute costume
The resize action changes a Cloud PC’s vCPU, RAM, or storage without reprovisioning, with the machine offline for fifteen to twenty minutes. The constraints were covered in the licensing article and they bind here: compute and memory move both directions, storage only grows, GPU SKUs do not resize at all, and Flex dedicated machines resize only at the provisioning-policy level while Flex shared machines do not resize, period. What makes resize an operational topic rather than a button is that it is a license swap underneath. A directly assigned license is swapped for you; a group-assigned license parks the Cloud PC in a pending state until you remove the old license and assign the new one, and the sequencing has a forty-eight hour clock on it before the machine slides toward a grace period. This is where the discrete-license-group design from earlier in the series pays its rent. One more trap for the hybrid-join, bring-your-own-network estate: a resize temporarily consumes a second IP address in the subnet, so a subnet run tight to its Cloud PC count will fail resizes in ways that look mysterious until you check the address pool.
Watching the fleet, and what the Suite money buys
Monitoring a Cloud PC fleet is mostly the monitoring you already do, with two additions worth naming. The Windows 365 utilization report is the ground truth for whether you bought the right things, and for Flex it is the only place license consumption is visible at all, since Flex licenses show as assigned to no one. Endpoint Analytics treats Cloud PCs as first-class citizens, and the newer Admin Insights experience, in preview as I write this, is Microsoft’s move toward a purpose-built health view of the Cloud PC estate. Watch utilization quarterly at minimum; the fleet that was sized correctly in March is oversized by October more often than anyone admits.
Finally, the Intune Suite question, because it lands differently on Cloud PCs than the feature list suggests. Remote Help matters more here, not less: there is no walking to the desk of a machine that has no desk, and a supported remote-assistance path into the actual session is the difference between diagnosing and guessing. Endpoint Privilege Management matters for the same reason it does on physical endpoints, standard users with governed elevation, and a Cloud PC fleet born standard-user is the cleanest place to hold that line. But before buying anything, check your entitlements: Microsoft’s July 2026 packaging update began folding Suite components, Remote Help, EPM, Advanced Analytics, and Cloud PKI among them, into the Microsoft 365 suites themselves, and the add-on you budgeted for may already be arriving in the license you hold. The operational layer article in the Intune Suite series on this site covers those tools in depth; everything it says applies to a Cloud PC without translation, which is, once more, the entire point of the platform. What does not translate from the physical world is the security architecture you can build when the endpoint itself is disposable and isolated, and that is where this series goes next.
Windows 365
‹ Previous: [W365 3.2] Building the Azure Network Connection
Next: [W365 4.1] Configuring Cloud PC Restore ›




