[W365 3.2] Building the Azure Network Connection

The ANC build, prerequisites first: subnet headroom, the three service principal permissions, the hybrid join account, and the health check gate that will hold you to all of it.

The ANC build, prerequisites first: subnet headroom, the three service principal permissions, the hybrid join account, and the health check gate that will hold you to all of it.

The build companion to the deployment design article: the provisioning policy wizard in current post-April-2026 navigation, with the naming decision and the change-model traps called out.

The CMMC enclave pattern won because it keeps the assessment boundary small. The Cloud PC is how people step into that boundary without their laptop walking into scope.

A dedicated Cloud PC is the cheapest privileged access workstation ever built, and an incomplete one. This article takes both halves of that sentence seriously.

A Cloud PC fleet runs on the Intune practice you already have. What is genuinely new are three levers physical hardware never offered: restore, resize, and reprovision.

The provisioning policy is the blueprint of a Windows 365 Enterprise deployment. Join type, network, and image are authority decisions, and this is how I argue them.

In Windows 365, the license is the hardware. Sizing is an ongoing discipline, and a few of the doors, storage above all, only swing one way.

Windows 365 is not VDI with a friendlier price sheet. It is a decision about who operates your desktop platform, and everything about the product follows from that division of responsibility.