Windows 365 Cloud PC Implementation
Windows 365 Cloud PC Implementation is a 2-week, $3,950 fixed-price service that deploys Microsoft's Windows 365 Cloud PCs for your organization: plan and license sizing, Intune provisioning policies, image and application configuration, Conditional Access integration, a validated pilot cohort, and cutover for the remaining users. It is built for SMBs that want to skip a hardware refresh or give contractors and BYOD users a secure, company-managed desktop without shipping laptops. Azure Virtual Desktop design is a separate service — this page explains when each fits.
What this engagement is
Windows 365 gives each user a dedicated Cloud PC — a full Windows 11 desktop streamed from Microsoft's cloud at a fixed per-user monthly license cost, managed in Microsoft Intune like any other company device. That predictability is why it is the cloud desktop SMBs actually buy: no Azure consumption bills to forecast, no host pools to right-size, no session hosts to patch. Users connect from the Windows App or a browser on Windows, macOS, iPadOS, or Android, so an aging desktop, a contractor's personal laptop, or a thin client all become safe entry points to a machine you control. How it differs from Azure Virtual Desktop: AVD is consumption-billed infrastructure you (or we) design and operate — multi-session hosts, autoscaling, deep customization — and it rewards that effort with lower per-seat cost at scale and workloads Windows 365 cannot express. Windows 365 trades that control for a flat license fee and near-zero infrastructure operations. Our rule of thumb: pick Windows 365 when each user needs their own persistent desktop and you want fixed costs and simple Intune management; pick our Azure Virtual Desktop Implementation when you need pooled multi-session desktops, GPU or specialized workloads, or fine-grained control of the underlying virtual machines. We deliver both, so the recommendation you get in scoping is driven by your workload, not by what we sell. During the engagement we confirm which Windows 365 edition fits — Business for simpler tenants up to 300 users, Enterprise for full Intune policy, custom image, and Microsoft Defender integration, or Frontline (being renamed Windows 365 Flex by Microsoft) where shift workers can share licenses non-concurrently — then configure provisioning, security, and applications, prove the design on a pilot cohort, and cut the remaining users over.
Success criteria
What you receive
How the work unfolds
Confirm user groups, workloads, and endpoints; map existing Microsoft 365 licensing against Windows 365 prerequisites; recommend edition and Cloud PC sizes; agree the pilot cohort and acceptance checks.
Verify tenant readiness, license assignment, and identity configuration. For Enterprise deployments, confirm each user holds Windows 10/11 Enterprise, Intune, and Microsoft Entra ID P1 entitlements (included in Microsoft 365 Business Premium, F3, E3, E5, and A3/A5), and decide between the Microsoft-hosted network and an Azure network connection.
Build Intune provisioning policies for the agreed groups, configure the gallery or custom image, and deploy the agreed core application set and configuration baselines through Intune.
Scope Conditional Access policies to Cloud PC access, align Intune compliance policies, and deploy in report-only mode; review sign-in results with you before enforcement.
Provision Cloud PCs for the pilot users, validate sign-in paths, application function, and performance against the acceptance checks, and fix what the pilot surfaces.
Provision the remaining in-scope users, distribute connection instructions, and support the switch from aging desktops or onboard contractor/BYOD users to their Cloud PCs.
Admin handover on day-2 operations (provisioning, resizing, restore, deprovisioning), and a closeout report covering final status, acceptance criteria, and any outstanding items.
Prerequisites
Who does what
IT Partner
- Recommend the Windows 365 edition and Cloud PC sizes and verify licensing prerequisites.
- Configure provisioning policies, image, applications, and Intune management for the in-scope Cloud PCs.
- Integrate Conditional Access and compliance policies with Cloud PC access, report-only first.
- Provision and validate the pilot cohort, then cut over the remaining in-scope users.
- Provide end-user connection instructions, admin handover, and the project closeout report.
Your team
- Provide tenant access, the in-scope user list, and application requirements.
- Purchase (or approve our CSP order for) the required Windows 365 and prerequisite licenses.
- Make pilot users available and review pilot results within the agreed window.
- Communicate the change to end users and coordinate any outside vendors.
- Review and approve deliverables in a timely manner.
What's not included
Limitations & technical notes
Frequently asked questions
What is included in the Windows 365 Cloud PC Implementation service?
The service covers sizing and edition selection, licensing prerequisite verification, Intune provisioning policies, image and core application configuration, Conditional Access integration, a validated pilot cohort, cutover of the remaining in-scope users, end-user connection instructions, an admin handover session, and a project closeout report — delivered in 2 weeks for a fixed $3,950.
Should we choose Windows 365 or Azure Virtual Desktop?
Choose Windows 365 when each user needs a persistent personal desktop and you want fixed per-user monthly license costs with simple Intune management. Choose Azure Virtual Desktop when you need pooled multi-session desktops, GPU or specialized workloads, or full control of the underlying infrastructure — AVD is consumption-billed and rewards operational effort with flexibility and per-seat economics at scale. We implement both, so the scoping call recommends on workload fit, not on which service we would rather sell.
What is the difference between Windows 365 Business, Enterprise, and Frontline?
Business is the simple edition for up to 300 users with minimal license prerequisites and a lighter management surface. Enterprise has no user cap and unlocks full Intune management, custom images, Azure network connections, and Microsoft Defender integration, but requires each user to hold Windows 10/11 Enterprise, Intune, and Entra ID P1 entitlements. Frontline — which Microsoft is renaming Windows 365 Flex — lets non-concurrent users such as shift workers share licenses, currently up to three users per license under Microsoft's licensing. We confirm the right edition during sizing.
What licenses do users need for Windows 365 Enterprise?
Each user needs Windows 10/11 Enterprise, Microsoft Intune, and Microsoft Entra ID P1. All three are included in Microsoft 365 Business Premium, F3, E3, E5, and A3/A5, so many SMBs already hold the prerequisites and only need to add the Windows 365 license itself. We map your existing licensing during sizing so you do not double-buy.
Do we need an Azure subscription for Windows 365?
Usually not. Cloud PCs on the Microsoft-hosted network need no Azure subscription at all. You only need one if your design calls for an Azure network connection (for example, to reach on-premises resources over private networking) or for storing a custom image. We flag this in the sizing recommendation before anything is purchased.
How do users connect to their Cloud PC?
Through the Windows App on Windows or macOS, through mobile apps on iPadOS and Android, or from any modern browser — no VPN required. That is what makes Cloud PCs practical for contractors and BYOD users: the personal device only ever runs a viewer, while work happens on the managed Cloud PC.
Is Windows 365 a good fit for contractors and BYOD users?
Yes — it is one of the two scenarios this service is built around. A contractor gets a company-managed Windows 11 desktop inside your tenant, protected by your Conditional Access and Intune compliance policies, without you shipping or reclaiming hardware. When the engagement ends, you deprovision the Cloud PC and the license returns to the pool.
Can Windows 365 replace our aging desktop fleet?
That is the other core scenario. Old desktops become thin entry points to a current Windows 11 Cloud PC, which defers or shrinks the hardware refresh. One useful detail for Windows 10 hold-out hardware: Microsoft has stated that Windows 10 endpoints used to access Windows 365 Enterprise Cloud PCs can be entitled to Extended Security Updates at no additional Microsoft charge, subject to Microsoft's conditions such as Entra join state, periodic user sign-in, and an enablement policy — we confirm eligibility for your fleet during scoping. If your bigger problem is getting the fleet itself onto Windows 11, see our Windows 11 Migration and Windows 10 ESU Transition service.
How are Cloud PCs secured?
Cloud PCs enroll in Microsoft Intune like any other corporate device, so your configuration baselines, compliance policies, and application controls apply. We scope Conditional Access to Cloud PC access and deploy it report-only first, review the sign-in results with you, then enforce — so nobody gets locked out by a policy that was never tested.
How long does the implementation take, and what can extend it?
The engagement is planned as 2 weeks: sizing, prerequisites, and configuration in week one; pilot, cutover, and handover in week two. The usual extenders are license procurement delays, pilot users who are unavailable, or a scope change such as adding a custom image or an Azure network connection mid-flight.
How much does the service cost, and what does the fee not cover?
The implementation is a fixed $3,950 per project, quoted in writing before work begins, and you pay after you approve delivery. The fee does not cover Microsoft's charges: Windows 365 per-user licenses, prerequisite Microsoft 365 licensing, or any Azure consumption your design requires. We quote those separately so you see the full monthly run-rate before committing.
What is not included in the implementation?
Azure Virtual Desktop work (a separate service), Microsoft license costs, bulk data migration from old PCs beyond OneDrive guidance, application packaging beyond the agreed core set, hardware procurement or disposal, and ongoing fleet management after handover — which is available separately as Device as a Service.
What happens after the project is done?
Your administrators receive a handover covering provisioning, resizing, restore points, and deprovisioning, plus the closeout report. From there you can run the fleet yourself, or hand day-2 operations to us under Device as a Service. Either way there is no lock-in: your Cloud PCs, licenses, and policies live in your tenant.