The estate
What they were running
Personal and pooled host pools for a UK head office and two regional sites.
The problem
Why the queue filled up
Out-of-hours staff used a shared privileged account in the Azure Portal. Business teams logged tickets for idle sessions that they could have cleared themselves. Nobody could show who sent a log-off during a change freeze.
What they set up
The same four moves, scoped to this estate.
- 01
Stand up AvdControl. The AVD data plane stays in the customer subscription.
- 02
Map service desk to help desk across the shared pools. Give a department owner help desk on their own host pool so they do not log a ticket.
- 03
Map EUC to session admin for log off. Turn on MFA for owner and admin.
- 04
Use session state filters (active, idle, disconnected) on the night shift.
What that gives them
A clearer way to act.
- No shared Azure admin account for session actions.
- A business owner can message or disconnect on their pool without a ticket.
- Change-freeze reviews use the tenant audit list, not Portal activity logs.
More scenarios
All case studies