Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Overview
Windows 365 network connectivity determines how Cloud PCs connect to the internet, Microsoft services, and organizational resources. There are two deployment options:
- Microsoft Hosted Network (MHN) — recommended deployment option. Microsoft manages the Cloud PC network, providing a simple, secure, and scalable default for most organizations.
- Azure Network Connection (ANC) — for traditional or specialized requirements. The organization manages the Azure network when direct access to existing corporate resources or legacy configurations is required.
At a glance: MHN offers the simplest and most modern approach because Microsoft manages the network. ANC provides greater control and direct corporate network connectivity, but requires more infrastructure, expertise, and ongoing management. Consider it only for a subset of users or scenarios.
Microsoft Hosted Network: recommended deployment option
We recommend starting with the Microsoft Hosted Network (MHN) option when deploying Cloud PCs, for a cloud-native approach built on Zero Trust principles. Only revert to ANC deployments after first validating that MHN won't meet your organization's needs.
Microsoft Hosted Network is a fully managed option where Microsoft configures and manages the underlying network for your Cloud PCs. In this model, Windows 365 is consumed as a complete SaaS deployment. There's no customer-managed network to design, secure, scale, or pay for.
When you choose Microsoft Hosted Network, the only infrastructure setup required is the choice of region for deployment. Microsoft handles the remaining configuration, management, and maintenance.
Why Microsoft recommends Microsoft Hosted Network
Microsoft Hosted Network reduces the number of customer-managed components in a Windows 365 deployment. The following sections describe the effect on security, operations, cost, reliability, and scale.
Security
- Outbound-only connectivity. Only outbound connections are allowed, with no inbound connections or lateral connectivity between Cloud PCs possible. Apply your standard VPN or secure web gateway (SWG) on the device, just as you would on a managed laptop.
- Zero Trust alignment. Access is based on identity, device, workload, and data signals rather than network location. Modern secure web gateway (SWG) and private access tools on the device integrate well with this model.
Simplicity and operations
- Minimal network configuration. No customer-managed Azure virtual network, firewalls, user-defined routes (UDRs), NAT gateways, or firewall rules to build and maintain. All you need is choose a region to deploy to; for best provisioning success, select Automatic.
- Lower operational overhead. No dedicated Azure networking expertise is needed to configure or maintain the environment. Troubleshooting is more straightforward and aligns with modern endpoint management through Intune policies, security controls, and built-in reporting.
Cost efficiency
- Lower infrastructure cost. You don't pay to run the network — network virtual appliances, bandwidth, and NAT gateways for your Cloud PCs don't incur any costs. Microsoft operates the underlying network on your behalf.
- No Azure subscription required. Microsoft supplies and manages all the Azure infrastructure that Cloud PCs need to operate, removing a common procurement and billing dependency.
Enhanced reliability
- Reduced misconfiguration risk. A managed, standardized network reduces the risk of misconfiguration and improves overall Cloud PC reliability.
- High-throughput connectivity. Cloud PCs have high-speed internet connectivity and direct entry onto Microsoft's global network for services like Microsoft 365.
Enhanced scalability
- Fewer deployment dependencies. Minimal dependencies on customer network elements mean Cloud PCs can be deployed quickly and at scale.
- Elastic capacity. Microsoft manages scale, so you can add large numbers of Cloud PCs on demand without first expanding network infrastructure. Cross-region disaster recovery, for example, doesn't require pre-provisioned networking when Microsoft Hosted Network is chosen.
Learn more: Microsoft-hosted network
Azure Network Connection: traditional approach
Azure Network Connection (ANC) allows Cloud PCs to be deployed into a customer-managed Azure network. This model provides direct integration with existing network architecture, including on-premises connectivity through site-to-site VPNs, ExpressRoute, firewalls, proxies, network virtual appliances, and other networking requirements.
Learn more: Azure Network Connection
When should you consider it?
ANC should only be considered where a documented business, technical, regulatory, security, application, networking, or operational requirement can't be met through Microsoft Hosted Network. Examples include:
- Applications that require direct network-level access to corporate resources.
- Existing networking architectures that depend on specific IP addressing, routing, segmentation, or security controls.
- Requirements for customer-controlled inspection of Cloud PC network traffic (excluding RDP traffic, which should bypass inspection for performance reasons).
- Regulatory or operational requirements that necessitate Cloud PCs being deployed directly into customer-managed Azure networks.
- Transitional scenarios where organizations are modernizing toward a cloud-native model but still rely on existing network dependencies.
Trade-offs and considerations
While ANC may address these requirements, organizations should understand the additional complexity and operational overhead involved:
Requires an Azure subscription and a customer-designed, deployed, and maintained networking stack, including virtual networks, network security groups (NSGs), firewalls, proxies, and network virtual appliances (NVAs).
Unoptimized connectivity (lag, high latency, RDP disconnects) can increase troubleshooting complexity, provisioning complexity, and deployment timelines.
Direct attachment to a corporate network introduces additional dependencies and management overhead; evaluate whether these are genuinely required for the workloads being delivered.
May incur additional Azure networking, egress, and operational costs.
Important
Where Azure Network Connection (ANC) may be required, limit it to the affected users or scenarios. Document the workloads involved, the requirement being met, the trade-offs accepted, and the plan to move to the cloud-native model later. Keeping exceptions narrow lets the rest of the deployment retain the benefits of a cloud-native, Zero Trust approach.
Comparison
| Category | Microsoft Hosted Network | Azure Network Connection (ANC) |
|---|---|---|
| Recommended use case | Default and recommended | For traditional or specific use cases |
| Network infrastructure management | Fully managed by Microsoft | Customer managed |
| Azure subscription required | No | Yes |
| Deployment complexity | Low | Moderate — requires configuration of virtual networks, firewalls, routing, and more |
| Scalability | Automatic and flexible | Depends on customer-managed infrastructure |
| Security model | Cloud-native and Zero Trust aligned by default | Supports Zero Trust architectures but requires additional customer design and configuration |
| Connectivity to on-premises | Requires VPN or SWG | Direct line of sight via site-to-site VPN or ExpressRoute, or point-to-site VPN/SWG |
| Cost implications | No additional network infrastructure or management costs | Additional Costs incurred for infrastructure, egress, and network management |
| Troubleshooting and reliability | Easier and more reliable due to managed setup | More complex and prone to misconfiguration |
Adoption path
Deploying your Cloud PCs with Microsoft Hosted Network requires minimal or no networking configuration. This allows you to quickly validate application access, security controls, and user experience before introducing additional networking complexity.
Start with Microsoft Hosted Network and select automatic region placement. Rather than manually choosing a single Azure region, allow Windows 365 to automatically select the most appropriate region within your chosen geography. Automatic region placement evaluates region health and availability during provisioning and can distribute Cloud PCs across multiple regions to improve provisioning success, resiliency, and operational flexibility.
Validate how users access organizational resources today. Most organizations already have a secure method for remote users to access internal applications and resources from laptops, such as a VPN, secure web gateway (SWG), Microsoft Entra Private Access, or another Zero Trust Network Access (ZTNA) solution. Deploy the same access technology to Cloud PCs rather than assuming a dedicated Azure network is required.
Verify access to internal applications and resources. Validate access to file shares, intranet applications, legacy applications, and any other internal resources that users need. In many cases, the same connectivity solution used on physical devices can provide the required line of sight from Cloud PCs without introducing an Azure Network Connection.
Ensure Microsoft endpoints and RDP traffic are optimized. If your organization deploys VPNs, SWGs, firewalls, or other network inspection technologies, ensure required Windows 365 and Microsoft service endpoints are reachable and that RDP traffic is appropriately excluded or optimized to avoid unnecessary latency, disconnects, or performance degradation.
Important
Validate endpoint accessibility, local egress, and RDP optimization as part of every Windows 365 deployment. VPNs, secure web gateways, proxies, firewalls, and TLS inspection can degrade Cloud PC performance and reliability when RDP traffic isn't excluded, routed, or optimized — whether you use Microsoft Hosted Network or an Azure Network Connection.
Related content
- Deployment options for Windows 365
- Connectivity overview
- Optimization of RDP traffic
- Optimizing RDP connectivity for Windows 365
- Clients: modern connectivity to Cloud PCs
Next steps
With connectivity decided, choose the operating system image that Cloud PCs are provisioned from.