AVD Assignment
AVD ready on next login
Azure Virtual Desktop (or VMware Horizon, Citrix, AWS WorkSpaces) assignment is manual + inconsistent. New employee needs a virtual desktop; IT ops manually assigns from the correct pool, configures apps, joins to session host, sets up profile. Contractor + external users need scoped access with time limits. Reassignment on role change means retiring old VD + provisioning new. Manual = slow + error-prone; scale increases both.
An hour-by-hour walkthrough.
Step by step.
- 01
Detect assignment need + resolve requirements
HRIS event or manager request. Role-based AVD pool + app requirements resolved from catalog.
HRIS · AVD catalog · Role registry - 02
Provision to correct host pool
Assign to appropriate pool (employee-standard, contractor-secure, developer-elevated). Session capacity + policies applied.
Azure AVD · VMware Horizon · Citrix · AWS WorkSpaces - 03
Configure profile + apps + policies
FSLogix profile in appropriate storage. Apps via MSIX app-attach or vendor packaging. Session policies per pool.
FSLogix · MSIX · App-attach · Session policies - 04
Apply access controls
Conditional Access, MFA requirement, device compliance requirement, network restrictions per pool.
Azure AD Conditional Access · MFA · Compliance policies - 05
Schedule deprovision on end date
Contractor engagement end triggers auto-deprovision. Profile retention per policy; license released.
Scheduler · AVD deprovisioning · License pool
What you connect to make this run.
Azure AVD · VMware Horizon · Citrix · AWS WorkSpaces
read+writePrimary virtual desktop platform. Assignment, session control, deprovisioning.
FSLogix · Profile management
read+writeUser profile containers. Storage account per pool sensitivity.
Azure AD · Conditional Access
read+writeAccess control policies + MFA + device compliance for VD access.
HRIS · License pool
readEmployment status + engagement dates drive provisioning + deprovisioning lifecycle.
Before and after, honestly.
Answers about this playbook.
What about BYOD accessing corporate VDs?
BYOD access supported with compliance requirements: MFA required, no local file save allowed, session recording per policy.
How does it handle GPU-intensive workloads (design, ML)?
GPU-enabled pools for specialized workloads. Provisioning routes based on role + workload requirements.
What about multi-region users needing low-latency access?
Regional pool selection per user location. AVD deployed in multiple Azure regions; user assigned to nearest.
How does it handle temporary access spikes (contractor surge, event)?
Auto-scaling host pools accommodate surge. Idle scale-down after event reduces cost.
Can users have persistent vs. non-persistent desktops?
Both supported per pool config. Persistent (dedicated) for developers; non-persistent (pooled) for contractors + kiosk-style users.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.