Windows 365 is easy to describe and easy to misjudge. The description: a persistent Windows desktop that runs in Microsoft’s cloud and streams to whatever screen the user happens to have. The misjudgment: treating it as VDI with a friendlier price sheet.
What Windows 365 actually represents is a decision about who operates your desktop virtualization platform. With classic VDI, and with Azure Virtual Desktop, that answer is you. You design the host pools, you own the images, you scale the capacity, you carry the operational responsibility when it breaks at 2 a.m. With Windows 365, the answer is Microsoft. You define policy and identity; Microsoft runs the platform. Everything else about the product, its pricing model, its constraints, its strengths, follows from that single division of responsibility. If you understand that, you understand the product. This article opens a standalone series on the platform, and it ties into the Intune Deployment Guide constantly, because a Cloud PC is an Intune-managed endpoint. But the decision it represents deserves its own treatment.
A Cloud PC is an endpoint, not a session
The unit of the platform is the Cloud PC: a dedicated virtual machine, assigned to one user, that keeps its state. Applications stay installed. The profile persists. The user closes their laptop on Tuesday and opens the same desktop from a browser on Wednesday. That persistence is the point, and it is what separates Windows 365 from session-based virtualization, where the desktop is a temporary construct assembled around a login.
It matters architecturally because a persistent, dedicated machine can be managed exactly like a physical one. The Cloud PC enrolls in Intune and from that moment it is just another Windows endpoint in your tenant. Your configuration profiles apply. Your compliance policies apply. Your Defender onboarding, your update strategy, your Conditional Access posture, all of it applies without a parallel set of tooling. If you have followed the Intune Deployment Guide on this site, you have already done nearly all of the work a Cloud PC fleet requires. That reuse is the strongest argument for the platform in any Intune-invested organization, and it is the thread this whole series pulls on.
Users reach their Cloud PC from Windows, macOS, Linux, iPadOS, Android, or a plain HTML5 browser session. There is also now purpose-built hardware: Windows 365 Link, a small Microsoft-built device running a locked-down OS with no local data, no local apps, and no local administrators, whose only job is to connect to a Cloud PC. The fact that Microsoft ships dedicated hardware for this tells you where they think the model is going. The local device is becoming a peripheral.
Business and Enterprise divide on control, not size
Windows 365 comes in two primary editions, Business and Enterprise, and the naming does the conversation a disservice. It suggests the dividing line is headcount, and there is indeed a hard cap: Business is limited to 300 users per tenant. But plenty of organizations under 300 users should still buy Enterprise, because the real dividing line is authority.
Business is the edition where you hold almost no levers. There are no licensing prerequisites; you buy a license, assign it, and a Cloud PC provisions from a standard image on a Microsoft-hosted network with default configuration. Provisioning is not configurable. Policy management through Intune is not natively part of the edition. Networking is Microsoft’s, full stop, with monthly outbound data allowances tied to the size of the Cloud PC. It is genuinely simple, and for a small organization with no Intune investment and no need to reach internal resources, that simplicity is honest value.
Enterprise is the edition where the levers exist. It requires each user to be licensed for Windows Enterprise, Intune, and Entra ID P1, which is Microsoft’s way of saying this edition assumes you already run a managed environment. In exchange you get provisioning policies you author, gallery or custom images you choose, the option to attach Cloud PCs to your own Azure virtual network, hybrid join if you still need it, full Intune management including security baselines and remote actions, and Defender for Endpoint integration. Enterprise is not a bigger Business. It is a different answer to the question of who decides how a Cloud PC is built and governed.
Business is for organizations that have not built a management plane and do not intend to.
My position is straightforward. If your organization runs Intune today, Enterprise is the only edition worth discussing, at any size. Buying Business alongside an existing Intune estate means operating a class of Windows endpoints your management plane cannot fully see or shape, and that split costs more in operational incoherence than the licensing difference saves.
There is a third licensing model worth knowing now and understanding properly later in the series: Windows 365 Flex, which Microsoft renamed from Windows 365 Frontline in May 2026. Flex exists for users who do not need a dedicated, always-available machine, and it changes the economics substantially for shift-based and intermittent work. It also carries real constraints the marketing does not lead with. The licensing article covers it.
Where it sits against AVD
Windows 365 and Azure Virtual Desktop are built on shared plumbing and solve adjacent problems, so the comparison is unavoidable. The honest version of it is short. AVD gives you architecture: multi-session hosts, pooled desktops, application streaming, custom scaling logic, and every design decision that comes with them. Windows 365 gives you an operating model: one user, one machine, one flat monthly price, and Microsoft carrying the platform.
Neither is the better product. They are different allocations of responsibility. AVD is the right tool when the economics of multi-session matter, when you need pooled non-persistent desktops, or when the workload demands an architecture Microsoft’s fixed SKUs cannot express. Windows 365 is the right tool when what you want is a fleet of managed Windows endpoints that happen to live in the cloud, without acquiring a virtualization practice to run them. Most organizations asking the question are closer to the second description than they admit, because the ongoing cost of operating AVD well is chronically underestimated in the initial comparison.
The landscape also moved in May 2026. Alongside the Flex rename, Microsoft cut Windows 365 Business pricing by twenty percent and put Azure Virtual Desktop Hybrid into public preview, which extends AVD session hosts onto your own on-premises hardware through Azure Arc. Read those three moves together and the strategy is legible: Microsoft wants to own the desktop control plane wherever the desktop physically runs, on their cloud, on your servers, or on a thin device on a desk. The decision facing you is less about which virtualization product to pick and more about how much of the operating burden you want to keep.
Where it earns its cost, and where it does not
A Cloud PC is a subscription, and the subscription never ends. For a full-time knowledge worker with a perfectly good laptop, adding a Cloud PC on top is a cost with no clear owner of the benefit. The scenarios where the platform earns its monthly price share a shape: the person needs a trustworthy Windows environment and the device in front of them is not one, or should not be treated as one.
Contractors and outsourced teams, where shipping and reclaiming corporate hardware is slow, expensive, and often simply does not happen. Mergers and acquisitions, where you need day-one access into an environment you have not yet integrated. BYOD arrangements where corporate data staying inside the session is the entire security story. Temporary projects with a defined end date, which is exactly what a subscription is for. And privileged access, where the isolation of a separately managed machine is the feature, a scenario strong enough that it gets its own article later in this series, as does the government cloud variant that defense contractors are using to reach CUI enclaves without dragging their whole fleet into assessment scope.
The failure modes are just as consistent. Power users on GPU or compute-heavy workloads, where the required SKUs erode the cost argument quickly. Anything sensitive to latency or dependent on specialized local peripherals. Anywhere the internet connection is not dependable, because a Cloud PC without connectivity is a login screen. And the quiet one: organizations that provision Cloud PCs as permanent second desktops for people who already have managed laptops, doubling the endpoint count and the monthly bill while halving the clarity about where work actually happens. The platform rewards deliberate scoping and punishes drift, which is a theme that will recur when we get to licensing and sizing in the next article.
So the decision Windows 365 represents is not really a virtualization decision. It is a decision to treat the desktop as a service Microsoft operates and you govern, and to accept fixed SKUs and reduced architectural freedom as the price of shedding the operational weight. For a specific and growing set of scenarios, that trade is clearly right. The rest of this series is about making it deliberately: the licensing mechanics and their traps, the Enterprise deployment design, the day-two operations, and the two security architectures, privileged access and the government enclave, where a Cloud PC stops being a convenience and becomes a boundary.
Windows 365
Next: [W365 2] Licensing and Sizing: The Four Variables and the Flex Question ›




