Validate your Entra app.
From Azure connection to
resolved session.
Connect an Entra app you own, choose the host pools that matter, and let the right people resolve AVD issues, without opening the Azure portal.
- Customer-owned Entra app
- Host-pool boundaries
- Complete activity trail
- No ARM template
- AES-256-GCM secrets
- Five practical roles
One clear operating path
Four steps. One controlled boundary.
AvdControl keeps Azure administration separate from everyday support. Your team decides what is connected, who can see it and which actions they can take.
Choose exact host pools.
Assign practical roles.
Act with a full audit trail.
Connect Azure
Check the app before anything is stored.
Create an Entra app, grant the required Desktop Virtualization roles and paste the IDs. AvdControl lists subscriptions first, so you know the connection works before the secret is encrypted.
- Validate credentials before storage
- Rotate secrets without rebuilding
- Never reveal the secret again
Pick host pools
Choose exactly what each person can see.
Include teaching or exams and leave research or finance out. Scope can follow an individual host pool, resource group, subscription or the whole connection.
- Start with least privilege
- Expand scope as responsibilities grow
- Keep unrelated pools invisible
Delegate safely
Give people the actions, not the Azure role.
Invite service desk, faculty owners or department leads and assign a role on only their pools. They act immediately in AvdControl without waiting on IT or entering the Azure portal.
- Practical roles for common responsibilities
- Role and scope evaluated together
- Change or revoke access centrally
Act and audit
Clear the session. Keep the evidence.
See active, idle and disconnected sessions together. Message and disconnect sit with help desk; logoff requires session admin. Every action records the actor, user and pool.
- Confirm destructive actions first
- Find the affected session quickly
- Review a complete Activity record
See the full workflow
Connect, scope, delegate and resolve.
Watch the complete product path in 50 seconds, from a new Azure connection to a recorded session action.
Role-based access
Every role has a clear ceiling.
Assign the closest role, then tighten it to the connection, subscription, resource group or host pool.
Viewer
See sessions and host pools in scope.
Help desk
Disconnect, send messages and view Activity. Cannot log people off.
Session admin
Everything help desk can do, plus log users off.
Admin
Manage day-to-day configuration and invitations, excluding SSO and SCIM.
Tenant owner
Manage billing, SSO, SCIM, Azure connections and every other setting.
Let the right people resolve the next session issue.
Self-serve signup will open shortly. Get in touch for early access while we finish launch.