What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Yes. Microsoft Intune can manage Windows Enterprise multi-session session hosts in Azure Virtual Desktop (AVD), including supported device- and user-scope configuration. This is a specific AVD scenario—not blanket Intune support for ordinary Windows Server, Remote Desktop Services, Citrix DaaS, or VMware Horizon Cloud workloads.
What “multi-session Windows” means here
Windows 10 and Windows 11 Enterprise multi-session are specialized operating-system editions for Azure Virtual Desktop. They allow multiple concurrent user sessions on one session host. Microsoft’s Intune guidance covers these Windows Enterprise multi-session VMs in AVD; it does not establish equivalent support for Windows Server 2019, 2022, or 2025, or for every multi-user VDI deployment. See Microsoft’s Intune guidance for Azure Virtual Desktop multi-session.
The distinction matters: a Windows Server RDS host is not interchangeable with an AVD host running Windows Enterprise multi-session. Microsoft also says this Intune support scenario is not currently available for Citrix DaaS or VMware Horizon Cloud.
What changed since the 2022 HTMD article
The HTMD article “Intune Support for Multi-Session Windows Server OS” was published on May 3, 2022. Its device-focused guidance reflected an earlier stage of support. Microsoft’s current documentation describes both device- and user-scope configuration as generally available for supported Windows Enterprise multi-session scenarios. User-scope Settings catalog policies, user certificates, and user-context PowerShell scripts are now part of the supported model.
#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
That update does not mean every Windows policy or Intune feature applies. The supported operating system, policy setting, assignment target, and execution context still matter.
Check the deployment prerequisites
Microsoft’s documented prerequisites for this scenario include:
- Windows Enterprise multi-session session hosts in a pooled AVD host pool.
- An Azure Resource Manager deployment, with the session hosts in the same tenant as Intune.
- Microsoft Entra joined or Microsoft Entra hybrid joined hosts.
- Azure Virtual Desktop Agent version 1.0.2944.1400 or later, as specified in Microsoft’s current Intune guidance.
- A supported Intune enrollment path for the host’s join type.
Check current AVD prerequisites, licensing, and supported operating-system information for the intended deployment. Do not infer licensing eligibility or total cost from the operating-system name alone; entitlements depend on the user’s subscription and licensing program.
Also decide how the hosts will be maintained. Pooled session hosts may be drained, reimaged, scaled, or replaced. A successful policy on one VM does not by itself make that configuration durable across host replacement; put durable settings in the image, an assignment-based policy, or the automated rebuild process as appropriate.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Enroll the session hosts
Choose the enrollment route that matches the host’s join state. The Azure portal option below applies to the supported Microsoft Entra-joined AVD flow; hybrid-joined hosts use Group Policy or Configuration Manager co-management.
Rank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
Microsoft Entra hybrid-joined hosts
- Configure Active Directory Group Policy for automatic Intune enrollment.
- Use device credentials for enrollment, or use Configuration Manager co-management where that is the chosen management design.
- Confirm the host appears as an enrolled device in Intune before assigning production policies.
Microsoft Entra-joined hosts
- During the supported AVD deployment flow in the Azure portal, enable Enroll the VM with Intune.
- After deployment, confirm the enrolled device identity and verify that the VM is reporting to Intune before targeting it with policies.
Microsoft’s current enrollment instructions are the reference for the exact flow. Treat a session host as a pooled service resource, not as a personal laptop owned by the first user who signs in.
Separate device and user policy deliberately
Use device scope for settings that configure the host as a machine, and user scope for supported settings that configure a user experience. They are separate assignment models: device-scope configuration belongs on device groups, while user-scope configuration belongs on user groups. A mismatch can produce Error or Not applicable results.
| Scope | Typical use | Assignment target |
|---|---|---|
| Device | Machine security settings, Windows Update settings, device certificates, Device Tunnel VPN, system-context scripts, and machine-wide applications | Device group containing the session hosts |
| User | Supported user-scope Settings catalog policies, user certificates, and user-context scripts | User group containing the users |
One workable naming convention is AVD-MS-Device-… and AVD-MS-User-…, with separate names for scripts and application assignments. The important point is that scope and target remain visible to the administrator reviewing assignments.
Filter the Settings catalog for multi-session support
- In the Microsoft Intune admin center, go to Devices > By platform > Windows.
- Under Manage devices > Configuration, select Create > New Policy.
- Choose Windows 10 and later, then select Settings catalog.
- Select Add settings. In Settings picker, select Add filter.
- Set Key to OS edition, Operator to
==, and Value to Enterprise multi-session; then select Apply. - Choose only settings whose supported scope matches the user or device group to which the policy will be assigned.
Portal labels can change. The durable check is to filter for OS edition = Enterprise multi-session and confirm that each selected setting supports the intended scope.
Configuration profiles: use supported templates or the catalog
Microsoft lists these configuration profile templates for Windows Enterprise multi-session:
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
- Trusted certificate.
- SCEP certificate.
- PKCS certificate.
- VPN, limited to Device Tunnel.
For other configuration, use the Settings catalog and check the multi-session OS-edition filter. A setting exposed through ADMX ingestion or an administrative template is not automatically valid on this edition: it must also be supported by the operating system and by the selected user or device scope. Test Office, Edge, and other ADMX-backed settings on a representative pooled host before broad assignment. Unsupported templates or settings may report as not applicable.
Compliance, Conditional Access, and endpoint security
Compliance
Microsoft documents support for selected compliance checks, including minimum and maximum OS version, valid OS builds, password settings, and Microsoft Defender state such as antimalware, security-intelligence currency, firewall, antivirus, antispyware, real-time protection, minimum Defender version, and risk score. Assign compliance policies to the device group containing the session hosts; user-targeted compliance configurations are not supported for this scenario.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsIntune compliance evaluates the enrolled device against configured requirements. It does not replace AVD host-pool health monitoring, session diagnostics, drain mode, capacity management, or application-health checks. Because one pooled host may serve several people, a device compliance failure can affect access for multiple users.
Conditional Access
Microsoft supports both user- and device-based Conditional Access configurations for Windows Enterprise multi-session. Keep the identities distinct in the design: the user signing in and the pooled session-host device are not the same object.
Endpoint security
Endpoint security policies can be used where the selected policy and Windows platform support multi-session. The platform or profile availability in the admin center is a useful support check; do not assume every Endpoint security policy applies. Validate the specific Defender antivirus, firewall, Attack Surface Reduction, EDR onboarding, or account-protection setting you intend to deploy. Microsoft identifies security baselines among the restricted or unsupported areas for multi-session, so do not assign a standard baseline and assume it will apply; configure supported equivalents individually.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Applications and PowerShell scripts have context restrictions
Applications
For supported app deployment to multi-session hosts, use system/device-context installation and assign the app to a device group with Required or Uninstall intent. Intune’s available-app deployment model is not supported here. Web apps normally install in user context and therefore do not fit this supported model.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →A system-context Win32 app can still fail if a dependency or supersedence relationship requires a user-context app. Validate detection rules, dependencies, install behavior, and timing on a test host. Microsoft does not support deploying AVD RemoteApp or MSIX app attach through this Intune application model.
For pooled hosts, keep the base image and app lifecycle coordinated. Stable applications used by every session may belong in the image; use Intune for controlled machine-context additions or removals that fit the rebuild and assignment plan.
PowerShell scripts
| Execution context | Assignment | Script setting |
|---|---|---|
| System | Devices | Run this script using the logged on credentials: No |
| User | Users | Run this script using the logged on credentials: Yes |
Make scripts safe to rerun, log to a known location, and return meaningful exit codes. Avoid assumptions that one device has one user, and avoid rebooting a host while sessions are active. If a change is user-specific, do not implement it as a machine-wide change simply because the host is easier to target.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Plan updates around the pooled-host lifecycle
Microsoft directs administrators to the Settings catalog for supported Windows Update client policies on multi-session. Filter for OS edition = Enterprise multi-session, search for Windows Update for Business, and use the settings currently surfaced for that edition. Do not assume that a standard Windows Update ring template or a historical list of settings applies unchanged; the catalog and support can evolve.
Recommended Free Tools
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Coordinate update deployment with host drain mode, maintenance windows, scaling, and image servicing. A policy controls supported client settings; it does not decide when a host can be safely removed from service or how an image should be validated before rollout.
Configuration Manager is an alternative or co-management option for organizations with established software-update and application workflows. Microsoft says Configuration Manager version 1906 and later can manage domain-joined and Microsoft Entra hybrid-joined AVD session hosts. See Microsoft’s AVD management overview. An older HTMD article describes a historical ConfigMgr/WSUS approach for multi-session patching; treat that product-specific behavior as historical guidance, not as a current Intune settings list: AVD Windows 10 multi-session patching with SCCM.
Troubleshoot policy and enrollment failures
- Confirm that the VM is running Windows Enterprise multi-session, not an assumed-equivalent Windows Server edition.
- Check that the AVD Agent meets the version stated in Microsoft’s current prerequisites.
- Verify Microsoft Entra join or hybrid-join state and confirm that Intune enrollment completed for the intended device identity.
- Check that the assignment group contains the correct object and that the policy scope matches its target: device to device, user to user.
- Confirm the setting is supported for Enterprise multi-session by using the OS-edition filter and checking the intended scope.
- Review Intune policy status. Not applicable may indicate an unsupported setting or template, a scope mismatch, an unsupported OS, or an enrollment problem; Pending and Error require checking delivery and policy details.
- For script or policy processing details, inspect Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin.
- For app failures, verify system-context installation, detection rules, dependencies, supersedence, and assignment intent.
- Check whether the host was recently reimaged, replaced, or removed from the assignment group; then reproduce on a clean test host before changing production assignments.
When Intune is a good fit—and when to add another management layer
| Requirement or environment | Fit | What to account for |
|---|---|---|
| Windows Enterprise multi-session in AVD | Strong | Use supported settings, correct scope, and a lifecycle plan for pooled hosts. |
| Device configuration, compliance, Conditional Access, and machine-wide apps | Supported with limits | Check per-setting support and app execution context. |
| User-scope configuration and scripts | Supported for documented settings and contexts | Assign to user groups and verify user scope in the catalog. |
| User-available app catalog, RemoteApp, or MSIX app attach through Intune | Poor fit or unsupported | Available-app assignments, RemoteApp, and MSIX app attach are not supported in this scenario. |
| Ordinary Windows Server RDS, Citrix DaaS, or VMware Horizon Cloud | Do not assume this support applies | Validate the platform’s own management support and tooling. |
| AVD host-pool lifecycle and image operations | Intune is not sufficient alone | Use AVD and image-management processes for scaling, drain mode, servicing, and session operations. |
Intune is a strong option when the workload is AVD Windows Enterprise multi-session and the organization wants Microsoft 365 policy, compliance, and Conditional Access in its management model. Configuration Manager may make more sense where mature ConfigMgr patching and application workflows already exist. For a Citrix or VMware estate, use that platform’s management model rather than extrapolating AVD-specific Intune support. Citrix Workspace Environment Management or Ivanti Environment Manager may be relevant when VDI-specific user-environment management is central; HTMD’s 2022 article names both as alternatives for server-based VDI control.
Bottom line
Intune can manage supported Windows Enterprise multi-session hosts in AVD, with both device- and user-scope options. The practical test is not simply whether a feature exists in Intune: check the OS edition, setting scope, assignment object, app or script context, and how the host will be rebuilt or replaced.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




