Azure Virtual Desktop no longer has to mean running the session hosts in Azure.
In this episode of Demystifying Microsoft, Nathan Taylor speaks with Azure Cloud Engineer Denis Vozian about AVD Hybrid: running virtual desktops on existing on-premises infrastructure while retaining Microsoft-brokered access, Entra ID controls and the familiar AVD user experience. They also get into Azure Local, Arc-enabled deployment, infrastructure-as-code and the current limitations IT leaders should know before treating AVD Hybrid as production-ready everywhere.
For years, the AVD decision was closely tied to an Azure infrastructure decision. If you wanted Microsoft’s brokered remote desktop experience, the assumption was usually that the session hosts would live in Azure too.
AVD Hybrid changes that equation.
In this episode of Demystifying Microsoft, Nathan Taylor sits down with Denis Vozian, Azure Cloud Engineer at Sourcepass, to explore how Azure Virtual Desktop can now extend to virtual machines running on infrastructure an organization already owns.
What You’ll Learn:
- Why organizations want AVD without moving the underlying workload into Azure
- How AVD Hybrid brokers access to on-premises virtual machines
- Why HTTPS-based access can reduce reliance on VPN-based remote desktop connectivity
- How Entra ID Conditional Access can still apply to AVD Hybrid connections
- Why AVD Hybrid is less restrictive about underlying infrastructure than Azure
- Why Azure Arc is central to the deployment architecture
- How Denis uses Azure DevOps and BICEP to automate VM onboarding
- Why the lack of Windows 11 multi-session support remains a significant limitation
About the Guest:
Denis Vozian is an Azure Cloud Engineer at Sourcepass with deep expertise across Microsoft Azure and Microsoft 365 technologies. A highly certified Microsoft professional, Dennis holds advanced credentials including Azure Solutions Architect Expert, Azure Network Engineer Associate, Enterprise Administrator Expert, Azure Security Engineer Associate, and Teams Administrator Associate.
With extensive hands-on experience designing, securing, and optimizing modern cloud environments, he helps organizations navigate complex Microsoft infrastructure, networking, security, and workplace transformation challenges.
About the Host:
Nathan Taylor is Senior Vice President and Global Microsoft Practice Leader at Sourcepass, where he leads the Sourcepass Center of Excellence for Microsoft, also known as the Sourcepass MCOE. With nearly two decades of experience, he helps organizations manage complex Microsoft cloud and security decisions by turning technology into secure, scalable outcomes.
Episode Highlights:
03:13 Why Denis Still Likes AVD
Denis explains why AVD remains a strong option for managed desktops, especially when infrastructure can be deployed through code, documented properly and scaled according to actual usage.
07:48 Microsoft-Brokered Access to Your Own Infrastructure
AVD Hybrid lets users connect to virtual machines running on-premises through the Windows app over HTTPS, without requiring the VM itself to sit in Azure or users to establish a traditional VPN connection.
10:19 AVD Hybrid vs. Azure Local
Azure Local requires specific infrastructure and deployment patterns. Denis explains why AVD Hybrid gives IT teams considerably more freedom over the underlying hypervisor and hardware.
13:37 Moving Remote Access Security Up the Stack
With Microsoft handling the connection brokerage, IT no longer needs to manage the remote-access gateway in the same way. Conditional Access in Entra ID can then be applied to control who is allowed to connect.
15:57 Automating Arc Enablement
The main deployment challenge Denis identifies is getting virtual machines Arc-enabled reliably. He explains how he uses an Azure DevOps agent, managed service account, PowerShell, and pipeline logic to automate the process.
19:28 The Windows 11 Multi-Session Limitation
AVD Hybrid supports familiar AVD concepts such as RemoteApp and full desktops, but Windows 11 multi-session is not currently supported. Denis calls that out as a major missing capability for many prospective deployments.
Episode Resources:
Explore whether AVD Hybrid is the right fit for your infrastructure. Talk to Sourcepass MCOE about designing a secure, flexible deployment around your existing environment: https://sourcepassmcoe.com/demystifying-microsoft-contact
Quotes:
- “You can connect over HTTPS without any VPN, without anything like that.”
- “You’re not forced to use Azure Local, and you’re not forced to use that hardware that has been certified.”
- “The security benefit is really great. You don’t have to manage that brokerage anymore.”