Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Overview
When you provision Cloud PCs with Windows 365, you select the operating system image that provides the starting point for each Cloud PC in a provisioning policy.
- Gallery images — recommended deployment option. Microsoft-built and maintained images designed for a cloud-native, low-touch deployment.
- Custom images — for legacy or specialized requirements. Organization-built and maintained images used when a gallery image can't meet a specific requirement.
At a glance: Gallery images reduce management effort and speed up deployment, while custom images provide greater control but require your organization to manage the entire image lifecycle.
Gallery images: recommended deployment option
We recommend starting with a gallery image when deploying Cloud PCs, for a cloud-native, low-touch approach to image management. Only revert to a custom image after first validating that a gallery image won't meet your organization's needs.
Gallery images are built and maintained by Microsoft and updated each month with the latest Windows quality updates. They include the Windows 365 optimizations needed for a high-quality Cloud PC experience, such as Microsoft Teams optimization and multimedia redirection (MMR), and are available with Microsoft 365 Apps preinstalled. A Developer Configuration option is also available, which provides a consistent, ready-to-code developer environment by preinstalling essential development tools and applying the required configurations across Windows and Windows Subsystem for Linux (WSL).
Organization-specific customizations such as line-of-business applications, configuration, branding, and security baselines are applied to the Cloud PC after provisioning through Microsoft Intune. This separates the operating system image from your app and policy configuration, which is the cloud-native pattern recommended for Windows 365.
Why Microsoft recommends gallery images
Gallery images shift image build and maintenance to Microsoft, while organization-specific applications, configuration, and policy are still applied through Intune.
- No image build pipeline required — Microsoft maintains the gallery image, including monthly updates and image versioning, so no image build pipeline is required. You can deploy a pilot or a production provisioning policy directly from a gallery image without first capturing, uploading, or validating a custom image.
- Microsoft 365 Apps included — gallery image variants are available with Microsoft 365 Apps preinstalled, so the apps are present at first sign-in.
- Windows 365 optimizations included — Microsoft Teams optimizations and multimedia redirection (MMR) are present and kept current in the gallery images with Microsoft 365 Apps preinstalled.
- Supports scale-out scenarios — automatic patching, consistent image versioning, and a known-good baseline support scenarios such as Windows 365 Flex in Shared mode, Windows 365 Reserve, and seasonal capacity.
- No additional cost — there are no Azure Compute Gallery storage costs for image artifacts because the images are hosted by the service.
- Aligned with cloud-native, Intune-led management — keeping the base image generic and layering apps, configuration, and security policies through Intune is the recommended Windows 365 deployment pattern.
Custom images: traditional approach
Custom images allow organizations to create and maintain their own Windows image within Azure Compute Gallery and use that image as the starting point for Cloud PC provisioning. If you choose a custom image, your IT team builds and maintains a Windows image in an Azure Compute Gallery, and Windows 365 uses that image as the base for new Cloud PCs in the provisioning policy. This mirrors the traditional VDI-style "golden image" model and gives you deep control over things like the operating system, regional settings, applications, configurations, drivers, and customizations included before the Cloud PC is provisioned.
Your organization owns the full image lifecycle, including the build pipeline, capture process, version control, governance, and rollback. Custom images aren't refreshed by Microsoft and don't automatically include monthly Windows updates.
Important
Where an alternative may be required, aim to limit its scope only to the affected users or scenarios. The decision should be documented along with the affected users or workloads, the business or technical requirement being addressed, the associated trade-offs, and any future opportunities to move toward the recommended cloud-native model.
Organizations should seek to minimize the scope of exceptions wherever possible. This ensures that the broader deployment can retain the benefits of a cloud-native, Zero Trust approach.
When should you consider it?
Custom images should only be considered where a documented business, technical, security, regulatory, application, or operational requirement can't be met using a gallery image and Intune-based application and policy deployment. Examples include:
- Preinstalled applications that can't be deployed using Intune.
- Regulatory or operational requirements for a prebuilt image.
- Specialized line-of-business applications requiring image-level integration.
- Transitional migration scenarios from existing VDI platforms.
Trade-offs and considerations
Significant overhead to create and maintain images — your IT team owns everything, including patching, re-capture, and version control.
Slower image creation, because each new image version requires a build, capture, upload, and validation cycle before it can be referenced from a provisioning policy.
Risk of configuration drift between the base image and the configuration your devices receive through Intune, especially when applications, drivers, and security baselines are duplicated in both places.
Additional operational cost and overhead, including Azure storage and management costs for each image created.
Not supported with Windows 365 Reserve, which uses a service-managed gallery image.
Important
Where custom images may be required, limit it to the affected users or scenarios. Document the workloads involved, the requirement being met, the trade-offs accepted, and the plan to move to the cloud-native model later. Keeping exceptions narrow lets the rest of the deployment retain the benefits of a cloud-native, Zero Trust approach.
Comparison
| Capability or requirement | Gallery images | Custom images |
|---|---|---|
| Recommended use case | Default and preferred option | For traditional or specific use cases |
| Image build and maintenance | Microsoft Managed | Customer Managed |
| Patching and updates | Microsoft Managed | Customer Managed |
| Microsoft 365 Apps | Microsoft Managed | Customer Managed |
| Version and lifecycle management | Microsoft Managed | Manual — IT owns version control and rollback |
Adoption path
Deploying your Cloud PCs with a gallery image requires minimal or no configuration. This allows you to quickly validate that the experience for your users and the applications they need works as expected, before considering whether a custom image is justified.
- Start with a gallery image. In the Windows 365 provisioning policy, select a gallery image — the variant with Microsoft 365 Apps preinstalled is a good default for most knowledge-worker scenarios. This lets you rapidly deploy Cloud PCs without standing up an image build pipeline.
- Layer apps, configuration, and security through Intune. Use Intune to deploy your line-of-business applications (Win32, Microsoft Store, Enterprise App Catalog), configuration policies, and the Windows 365 security baseline. This is identical to the approach you might use with a physical PC.
- Validate the user experience. Provision Cloud PCs for a pilot group and confirm that your business-critical applications all behave as expected. Gallery images include the current Windows 365 optimizations, so most validation focuses on your own apps and policies rather than the base OS.
- Use Windows Autopatch and hotpatch to keep Cloud PCs current. Because the gallery image is already up to date at provisioning time, your day-two patching strategy is Intune-driven Windows Autopatch and hotpatch — not a re-capture of the image.
Related content
- Windows 365 device images overview
- Add custom device images for Windows 365
- Create a Windows 365 provisioning policy
- Windows 365 security baseline
- Use Microsoft Teams on a Cloud PC media optimization
- Windows Autopatch documentation
- Updates: Windows Autopatch for Cloud PCs
- Hotpatch updates
Next steps
With the image decided, choose how Windows and Microsoft applications are kept current on the Cloud PCs you provision.