Windows 365 Intune 11 min read

Windows 365 Enterprise: Custom Device Images & Provisioning

End-to-end provisioning of Windows 365 Enterprise Cloud PCs using custom gallery device images, provisioning policies, and Microsoft Intune configurations.

1. Prerequisites, Licensing & Entitlements

Before provisioning Cloud PCs at scale, confirm the tenant has the correct Windows 365 Enterprise licensing and clean entitlement plumbing so users are automatically allocated devices:

  • Licensing: Windows 365 Enterprise licenses must be purchased and assigned in Microsoft Admin before any Cloud PC can be created.
  • Microsoft Entra Groups: Users must belong to Entra groups that are mapped to provisioning policies; entitlements are evaluated dynamically at check-in.
  • Intune Roles: Intune Administrator or Policy and Profile Manager roles are required to manage custom device images and provisioning policies.
  • Azure Resource Region: Confirm the Azure geography and resource location so image replication targets a compliant region.

2. Custom Device Images from the Azure Gallery

Windows 365 Enterprise allows you to provision Cloud PCs from your own golden images instead of stock gallery images. Upload a Windows 10/11 image to an Azure Compute Gallery, opt-in for Windows 365 in the gallery settings, and then make it available through the Windows 365 provisioning user interface.

Golden Image Checklist

  • Region: Replicate the gallery image across every Azure geography where Cloud PCs will be provisioned.
  • Versioning: Maintain immutable, versioned image definitions so rollbacks map to a single gallery version.
  • CSP Compliance: Keep custom images in sync with the Windows 365 supported image lifecycle and security baselines.

3. Provisioning Policies & User Assignment

Provisioning policies are the engine that links licenses, device images, and user groups. Each policy selects a device image, a language and region, and one or more target Entra user groups, and it can be restricted to a single policy per user to avoid duplicate Cloud PC creation.

  • Single vs. Multiple Policies: Use one policy per user to keep provisioning deterministic; additional policies require explicit fallback ordering.
  • UPN Mapping: Provisioning ignores invitations with a user principal name mismatch - confirm the end user license and UPN agree before assigning.
  • Activation Window: Assign the policy at least 24 hours before the user signs in so the first check-in provisions cleanly.

4. Intune Integration & Endpoint Management

Because Cloud PCs are Intune-managed devices, publishing apps, certificates, and configuration profiles to the Cloud PC fleet is identical to physical Windows endpoints. Apply update policies, Defender baselines, and network configurations through the same Intune tenant used for on-premises fleets.

For custom images, confirm the device image is enrolled in the same Intune organization used by the provisioning policy; mismatched organizations result in orphaned, unmanaged Cloud PCs.

5. Verification & Troubleshooting

Validate provisioning from the Windows 365 admin console: a healthy Cloud PC appears in All devices with the correct image version and health status Good. End users sign in at windows365.microsoft.com.

  • Image Sync Failures: Re-upload the gallery image or verify the image definition supports Windows 365.
  • Entitlement Errors: Confirm the user is in the policy group and holds a Windows 365 Enterprise license.
  • Slow First Sign-In: Check regional image replication and the provisioning policy region match.

Official References

Read more

Technical Discussion & Q&A

Secure PostgreSQL Board

Join the Engineering Discussion

Loading discussion threads...

Akash Nagapure

Akash Nagapure

Microsoft Intune and VMware Architect

Microsoft Intune and VMware Architect specialized in designing scalable cloud infrastructure and zero-trust modern workspace solutions.

Was this guide helpful?

Loading community feedback...