# Migrating Citrix VDI to Azure Virtual Desktop

> To move Citrix into Azure, choose native Azure Virtual Desktop or Citrix DaaS, settle licensing, assess with Azure Migrate, then build one of two ways.

Canonical: https://mikereams.com/writing/migration-guide-for-citrix-to-azure-vd

Published: May 8, 2023  
Author: Mike Reams (https://mikereams.com/about)  
Topics: [Cloud Computing](https://mikereams.com/writing/topics/cloud), [Virtualization](https://mikereams.com/writing/topics/virtualization), [Virtual Desktop](https://mikereams.com/writing/topics/virtual-desktop), [Azure](https://mikereams.com/writing/topics/azure)  
Tags: Azure, Citrix, VDI, Virtualization  
Project: [Migration of Citrix to Azure Virtual Desktop](https://mikereams.com/work/migration-of-citrix-to-azure-virtual-desktop)  
Diagrams: [Azure Hub-Spoke Network](https://mikereams.com/diagrams/azure-hub-spoke-network), [Azure Virtual Desktop at Scale](https://mikereams.com/diagrams/azure-virtual-desktop-at-scale)

![Migration Guide for Citrix to Azure Virtual Desktop](https://mikereams.com/writing/f657961aa78771c9e219c4641aeff508512c7515-1004x591.png)

*Written in 2023 and updated in 2026. Names have moved since: the Citrix Virtual Apps and Desktops service is now Citrix DaaS, and Azure AD is Microsoft Entra ID. Windows 10 reached end of support in October 2025, so build new images on Windows 11.*

## Why move VDI to Azure

Since 2020 I've watched a lot of organizations rethink their virtual desktop infrastructure, usually to support hybrid work and to stop owning datacenter hardware for it. On-premises Remote Desktop Services or Citrix works, but you carry the hardware, the capacity planning and the patching. Moving to Azure trades that for:

- **No hardware to buy.** Capacity becomes operating cost that scales up and down with demand.
- **Faster change.** New host pools deploy and scale in minutes rather than on a procurement cycle.
- **Security built in.** Conditional access, MFA and Azure's network controls apply to every session.
- **Multi-session Windows.** Windows 11 Enterprise multi-session packs several users onto one VM and is optimized for Microsoft 365 apps and Teams.

## First decision: native AVD or Citrix DaaS on Azure

Either way, Microsoft runs the infrastructure — compute, storage and network. The difference is who runs the control plane: the broker, gateway, load balancing, diagnostics and management.

- **Native Azure Virtual Desktop:** Microsoft runs the control plane. You own the images, apps and policies. Fewer moving parts and one vendor.
- **Citrix DaaS on Azure:** Citrix runs the control plane, including the gateway and client, on top of Azure. You still own images, apps and policies. It makes sense when you want to keep Citrix skills, policies and features, or manage desktops across more than one cloud.

Microsoft's reference architecture for native AVD shows the moving parts: identity synced from on-premises, a hub network with domain controllers and a VPN back to the datacenter, session hosts in hub and spoke networks, and profile storage on Azure Files or Azure NetApp Files.

![Azure Virtual Desktop reference architecture: on-premises AD DS and Azure AD Connect with password hash sync, a VPN gateway into a hub virtual network with domain controllers and a firewall appliance, session-host VMs in hub and spoke subnets, and user profiles on Azure Files or Azure NetApp Files, all under the Microsoft-managed control plane.](https://mikereams.com/writing/325823694f38b8bf5d5a244a25f597ad75765ac8-1365x581.png)

*Diagram: Microsoft's Azure Virtual Desktop reference architecture, drawn when the service was still called Windows Virtual Desktop.*

## Licensing

Users need a license that includes Azure Virtual Desktop access rights, on top of any Citrix DaaS licensing if you go that way:

- **Windows 11 or 10 Enterprise, single or multi-session:** Microsoft 365 E3, E5, A3, A5, F3 or Business Premium; Windows Enterprise E3 or E5; Windows Education A3 or A5; or Windows VDA per user.
- **Windows Server session hosts:** an RDS Client Access License with Software Assurance, or an RDS User Subscription License.
- **External users** (customers, not employees): per-user access pricing, enrolled on the Azure subscription.

Check Microsoft's [Azure Virtual Desktop licensing](https://learn.microsoft.com/en-us/azure/virtual-desktop/licensing) page before you commit; the eligible list changes.

## Prerequisites

- An Azure subscription with billing set up, and the permissions to create networks, storage and VMs.
- A domain the session hosts can join: Active Directory Domain Services reachable from the Azure virtual network, or Microsoft Entra Domain Services.
- Identity synced to Entra ID with Entra Connect (formerly Azure AD Connect).
- If back-end applications stay on-premises, connectivity to them over ExpressRoute or a site-to-site VPN.

## Assess before you move

Use [Azure Migrate](https://learn.microsoft.com/en-us/azure/migrate/migrate-services-overview) to discover the current VDI servers and measure cloud readiness, cost and risk. Choose the assessment type first:

- **As-is:** sizes Azure VMs from each server's current configuration. Quick, but it copies today's over- or under-provisioning.
- **Performance-based:** sizes from collected CPU, memory, disk and network data. Better, but it needs time.

For a performance-based assessment, let discovery run at least a day before you create it, and ideally for the whole performance window you choose (a day, week or month).

In the Azure portal the flow is: create an Azure Migrate project, discover servers with the Azure Migrate appliance (or import a CSV), then **Assess → Azure VM**, choose the servers, and create the assessment. Export it to Excel to work with it offline.

### Reading the assessment

- **Readiness** puts every VM in one of four groups: ready, ready with conditions, not ready (both with suggested fixes), or unknown because data was missing.
- **Cost** estimates monthly compute and storage for running the VMs as Azure VMs. It doesn't include PaaS or SaaS costs.
- **Confidence** rates performance-based assessments from one to five stars, based on how many data points were collected. Aim for five stars (81–100% of data points). CSV imports get no rating.

### What the assessment has to tell you

The tooling gives you servers. A VDI decision needs people and apps as well, so collect:

- User personas and how many users are in each.
- The applications each persona uses, and whether their licenses allow virtualization.
- Resource use per user and averages per persona.
- Server performance data, concurrency and peak-hour patterns.

That's what tells you how much can move to pooled, multi-session hosts and who genuinely needs a personal desktop.

## Two ways to build

### Option 1: New golden images (most common)

Build fresh images on Windows 11 Enterprise multi-session from the Azure Marketplace and store them in an Azure Compute Gallery. You get the current OS and a clean start. For Citrix DaaS, install the Citrix Virtual Delivery Agent (VDA) in the image and import it into Citrix.

### Option 2: Lift and shift

Replicate the existing VDI servers into Azure with the Azure Migrate Migration and modernization tool (formerly Server Migration): deploy its replication appliance, replicate, run a test migration, then migrate for real. Once the VMs run in Azure, install the Citrix VDA (for Citrix DaaS) or the AVD agent on each. Faster, but you inherit every problem the old servers had.

Moving an on-premises Citrix site to Citrix DaaS? Citrix's Automated Configuration tool exports the existing site configuration and imports it into DaaS.

## Before you cut over

- **Pilot by persona,** not by department, so each image is proven with the people it's built for.
- **Profiles:** plan FSLogix profile containers on Azure Files or Azure NetApp Files, so users land on any pooled host with their settings.
- **Printing and peripherals:** test them early; they are a common source of cutover tickets.
