Skip to content
Mike Reams
← Diagrams

DGM · Technical Architecture

Azure Virtual Desktop at Scale

Azure Virtual Desktop splits a Microsoft-managed control plane from the host pools, profiles, images and network you run in your own subscription.

Architecture diagram: users connect to the Microsoft-managed control plane (gateway and broker, workspaces and app groups, host pools, scaling plans). In your subscription's AVD spoke sit pooled and personal host pools, identity (Entra ID, AD DS), FSLogix profiles on Azure Files over a private endpoint, Compute Gallery images and hub peering to the firewall and ExpressRoute. Session hosts connect outbound only; a note mentions RDP Shortpath and a new region needing its own storage and domain controller.Architecture diagram: users connect to the Microsoft-managed control plane (gateway and broker, workspaces and app groups, host pools, scaling plans). In your subscription's AVD spoke sit pooled and personal host pools, identity (Entra ID, AD DS), FSLogix profiles on Azure Files over a private endpoint, Compute Gallery images and hub peering to the firewall and ExpressRoute. Session hosts connect outbound only; a note mentions RDP Shortpath and a new region needing its own storage and domain controller.

What it is

Azure Virtual Desktop delivers Windows desktops and apps from Azure. The split that shapes every design decision is responsibility: Microsoft runs the service that brokers connections, and you run the session hosts, user profiles, images, identity and network in your own subscription.

What Microsoft runs

The gateway and connection broker, workspaces and application groups, host pool definitions and the scaling orchestration. You configure them; you do not patch or host them.

What you run

  • Session hosts in pooled host pools (many users per multi-session host) or personal ones (one desktop per user).
  • FSLogix profile containers on Azure Files or Azure NetApp Files, reached over private endpoints.
  • Golden images in Azure Compute Gallery, so every new host starts identical.
  • Identity: Microsoft Entra ID, with Active Directory Domain Services where the hosts need it.
  • Network: an AVD spoke peered to the hub, which holds the firewall and the connection to on-premises.

Network rules worth keeping

Session hosts connect outbound to the service, so no inbound ports are opened to them. RDP Shortpath can carry sessions over direct UDP where the network allows it. Everything else follows the hub-spoke pattern.

Scaling out

  • Scaling plans add and remove hosts on a schedule and with demand; drain mode moves users off a host before it is removed.
  • A second region gets its own non-overlapping address space, its own profile storage and ideally its own domain controller.
  • Assign each user to one region, so profiles never split between two copies.

Based on Azure Virtual Desktop for the enterprise (Azure Architecture Center). Drawn for this site; no client or employer material.