Product overview

From Azure connection to
resolved session.

Connect an Entra app you own, choose the host pools that matter, and let the right people resolve AVD issues, without opening the Azure portal.

No ARM templatePool-level accessEvery action recorded
Session operationsScoped to hp-exams
Access is in scopeHelp desk · 2 host pools
  • Customer-owned Entra app
  • Host-pool boundaries
  • Complete activity trail
  • No ARM template
  • AES-256-GCM secrets
  • Five practical roles

One clear operating path

Four steps. One controlled boundary.

AvdControl keeps Azure administration separate from everyday support. Your team decides what is connected, who can see it and which actions they can take.

01Connect

Validate your Entra app.

02Scope

Choose exact host pools.

03Delegate

Assign practical roles.

04Operate

Act with a full audit trail.

01

Connect Azure

Check the app before anything is stored.

Create an Entra app, grant the required Desktop Virtualization roles and paste the IDs. AvdControl lists subscriptions first, so you know the connection works before the secret is encrypted.

  • Validate credentials before storage
  • Rotate secrets without rebuilding
  • Never reveal the secret again
02

Pick host pools

Choose exactly what each person can see.

Include teaching or exams and leave research or finance out. Scope can follow an individual host pool, resource group, subscription or the whole connection.

  • Start with least privilege
  • Expand scope as responsibilities grow
  • Keep unrelated pools invisible
03

Delegate safely

Give people the actions, not the Azure role.

Invite service desk, faculty owners or department leads and assign a role on only their pools. They act immediately in AvdControl without waiting on IT or entering the Azure portal.

  • Practical roles for common responsibilities
  • Role and scope evaluated together
  • Change or revoke access centrally
04

Act and audit

Clear the session. Keep the evidence.

See active, idle and disconnected sessions together. Message and disconnect sit with help desk; logoff requires session admin. Every action records the actor, user and pool.

  • Confirm destructive actions first
  • Find the affected session quickly
  • Review a complete Activity record

See the full workflow

Connect, scope, delegate and resolve.

Watch the complete product path in 50 seconds, from a new Azure connection to a recorded session action.

50 seconds, no sound. Connect, scope, delegate and resolve.

Role-based access

Every role has a clear ceiling.

Assign the closest role, then tighten it to the connection, subscription, resource group or host pool.

Observe

Viewer

See sessions and host pools in scope.

Resolve

Session admin

Everything help desk can do, plus log users off.

Configure

Admin

Manage day-to-day configuration and invitations, excluding SSO and SCIM.

Control

Tenant owner

Manage billing, SSO, SCIM, Azure connections and every other setting.

Coming soon

Let the right people resolve the next session issue.

Self-serve signup will open shortly. Get in touch for early access while we finish launch.