Acceptable Use Policy
This Acceptable Use Policy (the "AUP") forms part of the Terms of Service and applies to your organisation, your Authorised Users, and anyone who accesses AvdControl through your credentials. Capitalised terms have the meaning given in the Terms.
The AUP exists to keep the service safe for every customer. It is written broadly on purpose: if conduct is not listed but is harmful, deceptive or unlawful, we may still treat it as a breach.
2. Prohibited conduct
You must not use the service, or allow it to be used, to:
- break any applicable law or regulation, or infringe anyone's intellectual property, privacy, publicity or contractual rights;
- store, transmit or process malware, ransomware, exploit code, or any material that is unlawful, defamatory, obscene, or that depicts the exploitation of children;
- send unsolicited bulk messages, phishing content or deceptive messages, including through the session-message feature;
- impersonate another person or organisation, or misrepresent your affiliation with anyone;
- interfere with or disrupt the service, its infrastructure, or any other customer's tenant, including by excessive load, denial-of-service traffic, or abuse of retries;
- probe, scan or test the vulnerability of the service, or breach or circumvent any authentication, rate limit, seat limit, tenant isolation or other security or access control measure, other than under an authorised test we have agreed in writing;
- access or attempt to access any data, tenant, account or environment that is not yours, or aggregate or correlate data across tenants;
- reverse engineer, copy, resell, sublicense, white-label or benchmark the service, or use it to build or improve a competing product, except as permitted by the Terms;
- scrape, crawl or bulk-extract data or content other than through a published API within its documented limits;
- use the service in a sanctioned or embargoed territory, or in breach of export control or sanctions law; or
- conceal your identity or the origin of your traffic in order to evade this policy or any enforcement action.
3. What you should not put into the service
AvdControl is an operational console for Azure Virtual Desktop. Do not use it as a general document store, and do not submit — in organisation names, ticket text, help attachments, notes or any other field — data that does not belong there. In particular, do not submit:
- special category personal data such as health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union membership, or data about sex life or sexual orientation;
- payment card numbers, bank credentials or other financial account details;
- government identity numbers, criminal record data, or children's data;
- credentials, private keys or secrets, other than in the fields designed to hold them; or
- data subject to specific regulatory regimes, such as regulated health or defence data, unless we have agreed it in writing.
Help-request attachments are limited to a small number of small image files and are intended for screenshots that help us support you. Do not use them to transfer datasets or documents.
4. Your accountability
You are responsible for what happens under your tenant. Keep your role assignments tight, remove leavers promptly, protect credentials and multi-factor devices, and use the audit trail to review privileged activity. If you become aware of a breach of this policy by one of your users, stop it and tell us.
5. Reporting abuse and vulnerabilities
Report suspected abuse to [email protected]. Report suspected security vulnerabilities to [email protected] with enough detail to reproduce the issue. Please give us a reasonable opportunity to fix an issue before disclosing it, do not access data that is not yours, and do not degrade the service while testing. We will not pursue action against good-faith research that follows those principles.
6. Enforcement
We may investigate suspected breaches, and may access tenant configuration and logs to the extent necessary to do so. Where we find a breach, or reasonably suspect one, we may remove content, disable a feature or integration, throttle activity, require you to remediate, or suspend or revoke your tenant under section 8 of the Terms of Service, with or without notice depending on the severity and risk. Serious or repeated breaches will result in termination without refund, and we may decline to serve you in the future.
Where required or appropriate, we may report conduct to law enforcement or a regulator, and cooperate with their investigations. We may update this policy from time to time; the current version always applies.