October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Azure Virtual Desktop

Intune Support for Windows Enterprise Multi-Session in Azure Virtual Desktop

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Microsoft Intune can manage Windows Enterprise multi-session session hosts in Azure Virtual Desktop (AVD), including supported device- and user-scope configuration. This is a specific AVD scenario—not blanket Intune support for ordinary Windows Server, Remote Desktop Services, Citrix DaaS, or VMware Horizon Cloud workloads.

What “multi-session Windows” means here

Windows 10 and Windows 11 Enterprise multi-session are specialized operating-system editions for Azure Virtual Desktop. They allow multiple concurrent user sessions on one session host. Microsoft’s Intune guidance covers these Windows Enterprise multi-session VMs in AVD; it does not establish equivalent support for Windows Server 2019, 2022, or 2025, or for every multi-user VDI deployment. See Microsoft’s Intune guidance for Azure Virtual Desktop multi-session.

The distinction matters: a Windows Server RDS host is not interchangeable with an AVD host running Windows Enterprise multi-session. Microsoft also says this Intune support scenario is not currently available for Citrix DaaS or VMware Horizon Cloud.

What changed since the 2022 HTMD article

The HTMD article “Intune Support for Multi-Session Windows Server OS” was published on May 3, 2022. Its device-focused guidance reflected an earlier stage of support. Microsoft’s current documentation describes both device- and user-scope configuration as generally available for supported Windows Enterprise multi-session scenarios. User-scope Settings catalog policies, user certificates, and user-context PowerShell scripts are now part of the supported model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

That update does not mean every Windows policy or Intune feature applies. The supported operating system, policy setting, assignment target, and execution context still matter.

Check the deployment prerequisites

Microsoft’s documented prerequisites for this scenario include:

  • Windows Enterprise multi-session session hosts in a pooled AVD host pool.
  • An Azure Resource Manager deployment, with the session hosts in the same tenant as Intune.
  • Microsoft Entra joined or Microsoft Entra hybrid joined hosts.
  • Azure Virtual Desktop Agent version 1.0.2944.1400 or later, as specified in Microsoft’s current Intune guidance.
  • A supported Intune enrollment path for the host’s join type.

Check current AVD prerequisites, licensing, and supported operating-system information for the intended deployment. Do not infer licensing eligibility or total cost from the operating-system name alone; entitlements depend on the user’s subscription and licensing program.

Also decide how the hosts will be maintained. Pooled session hosts may be drained, reimaged, scaled, or replaced. A successful policy on one VM does not by itself make that configuration durable across host replacement; put durable settings in the image, an assignment-based policy, or the automated rebuild process as appropriate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enroll the session hosts

Choose the enrollment route that matches the host’s join state. The Azure portal option below applies to the supported Microsoft Entra-joined AVD flow; hybrid-joined hosts use Group Policy or Configuration Manager co-management.

Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
  • 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
  • 4GB DDR4 System Memory; 128GB Solid State Drive
  • 11.6" HD (1366 x 768) Multi-Touch Display
  • Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
  • Windows 11 Pro

Microsoft Entra hybrid-joined hosts

  1. Configure Active Directory Group Policy for automatic Intune enrollment.
  2. Use device credentials for enrollment, or use Configuration Manager co-management where that is the chosen management design.
  3. Confirm the host appears as an enrolled device in Intune before assigning production policies.

Microsoft Entra-joined hosts

  1. During the supported AVD deployment flow in the Azure portal, enable Enroll the VM with Intune.
  2. After deployment, confirm the enrolled device identity and verify that the VM is reporting to Intune before targeting it with policies.

Microsoft’s current enrollment instructions are the reference for the exact flow. Treat a session host as a pooled service resource, not as a personal laptop owned by the first user who signs in.

Separate device and user policy deliberately

Use device scope for settings that configure the host as a machine, and user scope for supported settings that configure a user experience. They are separate assignment models: device-scope configuration belongs on device groups, while user-scope configuration belongs on user groups. A mismatch can produce Error or Not applicable results.

Scope Typical use Assignment target
Device Machine security settings, Windows Update settings, device certificates, Device Tunnel VPN, system-context scripts, and machine-wide applications Device group containing the session hosts
User Supported user-scope Settings catalog policies, user certificates, and user-context scripts User group containing the users

One workable naming convention is AVD-MS-Device-… and AVD-MS-User-…, with separate names for scripts and application assignments. The important point is that scope and target remain visible to the administrator reviewing assignments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Filter the Settings catalog for multi-session support

  1. In the Microsoft Intune admin center, go to Devices > By platform > Windows.
  2. Under Manage devices > Configuration, select Create > New Policy.
  3. Choose Windows 10 and later, then select Settings catalog.
  4. Select Add settings. In Settings picker, select Add filter.
  5. Set Key to OS edition, Operator to ==, and Value to Enterprise multi-session; then select Apply.
  6. Choose only settings whose supported scope matches the user or device group to which the policy will be assigned.

Portal labels can change. The durable check is to filter for OS edition = Enterprise multi-session and confirm that each selected setting supports the intended scope.

Configuration profiles: use supported templates or the catalog

Microsoft lists these configuration profile templates for Windows Enterprise multi-session:

Rank #3
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.
  • Trusted certificate.
  • SCEP certificate.
  • PKCS certificate.
  • VPN, limited to Device Tunnel.

For other configuration, use the Settings catalog and check the multi-session OS-edition filter. A setting exposed through ADMX ingestion or an administrative template is not automatically valid on this edition: it must also be supported by the operating system and by the selected user or device scope. Test Office, Edge, and other ADMX-backed settings on a representative pooled host before broad assignment. Unsupported templates or settings may report as not applicable.

Compliance, Conditional Access, and endpoint security

Compliance

Microsoft documents support for selected compliance checks, including minimum and maximum OS version, valid OS builds, password settings, and Microsoft Defender state such as antimalware, security-intelligence currency, firewall, antivirus, antispyware, real-time protection, minimum Defender version, and risk score. Assign compliance policies to the device group containing the session hosts; user-targeted compliance configurations are not supported for this scenario.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Intune compliance evaluates the enrolled device against configured requirements. It does not replace AVD host-pool health monitoring, session diagnostics, drain mode, capacity management, or application-health checks. Because one pooled host may serve several people, a device compliance failure can affect access for multiple users.

Conditional Access

Microsoft supports both user- and device-based Conditional Access configurations for Windows Enterprise multi-session. Keep the identities distinct in the design: the user signing in and the pooled session-host device are not the same object.

Endpoint security

Endpoint security policies can be used where the selected policy and Windows platform support multi-session. The platform or profile availability in the admin center is a useful support check; do not assume every Endpoint security policy applies. Validate the specific Defender antivirus, firewall, Attack Surface Reduction, EDR onboarding, or account-protection setting you intend to deploy. Microsoft identifies security baselines among the restricted or unsupported areas for multi-session, so do not assign a standard baseline and assume it will apply; configure supported equivalents individually.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

Applications and PowerShell scripts have context restrictions

Applications

For supported app deployment to multi-session hosts, use system/device-context installation and assign the app to a device group with Required or Uninstall intent. Intune’s available-app deployment model is not supported here. Web apps normally install in user context and therefore do not fit this supported model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A system-context Win32 app can still fail if a dependency or supersedence relationship requires a user-context app. Validate detection rules, dependencies, install behavior, and timing on a test host. Microsoft does not support deploying AVD RemoteApp or MSIX app attach through this Intune application model.

For pooled hosts, keep the base image and app lifecycle coordinated. Stable applications used by every session may belong in the image; use Intune for controlled machine-context additions or removals that fit the rebuild and assignment plan.

PowerShell scripts

Execution context Assignment Script setting
System Devices Run this script using the logged on credentials: No
User Users Run this script using the logged on credentials: Yes

Make scripts safe to rerun, log to a known location, and return meaningful exit codes. Avoid assumptions that one device has one user, and avoid rebooting a host while sessions are active. If a change is user-specific, do not implement it as a machine-wide change simply because the host is easier to target.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan updates around the pooled-host lifecycle

Microsoft directs administrators to the Settings catalog for supported Windows Update client policies on multi-session. Filter for OS edition = Enterprise multi-session, search for Windows Update for Business, and use the settings currently surfaced for that edition. Do not assume that a standard Windows Update ring template or a historical list of settings applies unchanged; the catalog and support can evolve.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
15.6 Inch Win 11 Laptop Computer, N4020, 4GB DDR4 RAM, 128GB Storage
  • WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
  • 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
  • 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
  • CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
  • LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.

Coordinate update deployment with host drain mode, maintenance windows, scaling, and image servicing. A policy controls supported client settings; it does not decide when a host can be safely removed from service or how an image should be validated before rollout.

Configuration Manager is an alternative or co-management option for organizations with established software-update and application workflows. Microsoft says Configuration Manager version 1906 and later can manage domain-joined and Microsoft Entra hybrid-joined AVD session hosts. See Microsoft’s AVD management overview. An older HTMD article describes a historical ConfigMgr/WSUS approach for multi-session patching; treat that product-specific behavior as historical guidance, not as a current Intune settings list: AVD Windows 10 multi-session patching with SCCM.

Troubleshoot policy and enrollment failures

  1. Confirm that the VM is running Windows Enterprise multi-session, not an assumed-equivalent Windows Server edition.
  2. Check that the AVD Agent meets the version stated in Microsoft’s current prerequisites.
  3. Verify Microsoft Entra join or hybrid-join state and confirm that Intune enrollment completed for the intended device identity.
  4. Check that the assignment group contains the correct object and that the policy scope matches its target: device to device, user to user.
  5. Confirm the setting is supported for Enterprise multi-session by using the OS-edition filter and checking the intended scope.
  6. Review Intune policy status. Not applicable may indicate an unsupported setting or template, a scope mismatch, an unsupported OS, or an enrollment problem; Pending and Error require checking delivery and policy details.
  7. For script or policy processing details, inspect Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin.
  8. For app failures, verify system-context installation, detection rules, dependencies, supersedence, and assignment intent.
  9. Check whether the host was recently reimaged, replaced, or removed from the assignment group; then reproduce on a clean test host before changing production assignments.

When Intune is a good fit—and when to add another management layer

Requirement or environment Fit What to account for
Windows Enterprise multi-session in AVD Strong Use supported settings, correct scope, and a lifecycle plan for pooled hosts.
Device configuration, compliance, Conditional Access, and machine-wide apps Supported with limits Check per-setting support and app execution context.
User-scope configuration and scripts Supported for documented settings and contexts Assign to user groups and verify user scope in the catalog.
User-available app catalog, RemoteApp, or MSIX app attach through Intune Poor fit or unsupported Available-app assignments, RemoteApp, and MSIX app attach are not supported in this scenario.
Ordinary Windows Server RDS, Citrix DaaS, or VMware Horizon Cloud Do not assume this support applies Validate the platform’s own management support and tooling.
AVD host-pool lifecycle and image operations Intune is not sufficient alone Use AVD and image-management processes for scaling, drain mode, servicing, and session operations.

Intune is a strong option when the workload is AVD Windows Enterprise multi-session and the organization wants Microsoft 365 policy, compliance, and Conditional Access in its management model. Configuration Manager may make more sense where mature ConfigMgr patching and application workflows already exist. For a Citrix or VMware estate, use that platform’s management model rather than extrapolating AVD-specific Intune support. Citrix Workspace Environment Management or Ivanti Environment Manager may be relevant when VDI-specific user-environment management is central; HTMD’s 2022 article names both as alternatives for server-based VDI control.

Bottom line

Intune can manage supported Windows Enterprise multi-session hosts in AVD, with both device- and user-scope options. The practical test is not simply whether a feature exists in Intune: check the OS edition, setting scope, assignment object, app or script context, and how the host will be rebuilt or replaced.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99
Bestseller No. 2
Dell Latitude 3190 11.6' HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core; 4GB DDR4 System Memory; 128GB Solid State Drive
Bestseller No. 3
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$304.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.