The estate
What they were running
Pooled AVD for social care, revenue, and civic staff, hosted in UK South.
The problem
Why the queue filled up
Service desk could not act on a locked session after 5pm. Service owners logged tickets to the cloud team and waited hours. Security would not approve Portal access for first line or the business.
What they set up
The same four moves, scoped to this estate.
- 01
Register an Entra app the cloud team owns. Grant only Desktop Virtualization roles on the AVD subscription.
- 02
Limit help desk to the civic and social-care pools. Invite a social-care service owner with help desk on that pool only.
- 03
Keep the finance pool for session admins. Encrypt the client secret and rotate it from settings when it nears expiry.
- 04
Keep SSO and SCIM off until the directory team is ready. Email and password is enough for the first users.
What that gives them
A clearer way to act.
- First line and a service owner work in a browser console. They never see the Azure Portal.
- A locked session after 5pm does not need a ticket to the cloud team.
- Privileged Azure stays with the cloud team.
More scenarios
All case studies