Requirements for Windows 365

Important

Windows 365 Frontline is now Windows 365 Flex. The product name in the Microsoft Intune admin center is being updated and may still appear as Frontline in some places. This article reflects those existing references where updates are still in progress. For more information about the rebrand, see Expanding access to Windows 365.

To use Cloud PCs, you must meet the following requirements:

Azure requirements

None, if you plan on provisioning Microsoft Entra joined Cloud PCs on a Microsoft hosted network.

If you choose to provision Cloud PCs on your own network, an active Azure subscription with the following configurations is required:

  • Sufficient permissions to grant Windows 365:
    • A reader role on the Azure subscription.
    • Windows365 network interface contributor role on the specified resource group.
    • Windows365 network user role on the virtual network.

Microsoft Entra ID and Intune requirements

  • A valid and working Intune and Microsoft Entra tenant.
  • Intune default device type enrollment restrictions must be set to Allow Windows (MDM) platform for corporate enrollment. For more information, see Device Enrollment Restrictions Limitations.
  • Infrastructure configuration: If you plan on provisioning Microsoft Entra hybrid joined Cloud PCs, you must configure your infrastructure to automatically Microsoft Entra hybrid join any devices that domain join to the on-premises Active Directory. This configuration lets them be recognized and managed in the cloud.
  • Microsoft Entra Domain Services isn't supported because it doesn't support Microsoft Entra hybrid join.

Domain requirements

None, if you plan on provisioning Microsoft Entra joined Cloud PCs on a Microsoft hosted network.

If you choose to provision Microsoft Entra hybrid joined Cloud PCs, then the following configurations on your domain are required:

  • If an organizational unit is specified, ensure it exists and is valid.
  • An Active Directory user account with sufficient permissions to join the computer into the specified organizational unit within the Active Directory domain. If you don't specify an organizational unit, the user account must have sufficient permissions to join the computer to the Active Directory domain.
  • User accounts that are assigned Cloud PCs must have a synced identity available in both Active Directory and Microsoft Entra ID.

Note

For the user account used to join the Cloud PCs to the Active Directory Domain Services, make sure to set up appropriate delegation following the instructions in Increase the computer account limit in the Organizational Unit.

Licensing requirements

  • You must have an Intune license to use Intune to manage the devices.
  • Windows 365 Enterprise: Users must have licenses for Windows E3, Intune, Microsoft Entra ID P1, and Windows 365 to use their Cloud PC.
  • Windows 365 Flex: Users must
    • Have licenses for Windows E3, Intune, Microsoft Entra ID P1.
    • Be added to the Microsoft Entra security group in the provisioning policy to use their Cloud PC.

Management requirements

  • You must use Microsoft Intune admin center to manage your Cloud PCs.
  • You must have a Windows 365 Enterprise or Windows 365 Flex license to manage Cloud PC configurations.

Role and identity requirements

Supported Azure regions for Cloud PC provisioning

Windows 365 Enterprise and Windows 365 Flex in Dedicated mode support multi-region selection model (Geography → Region Group → Region) to maximize resiliency and minimize provisioning failures.

Windows 365 Flex in Shared mode requires selection of one specific Azure region. Multi-region selection is not available for this SKU.

You can provision Windows 365 Enterprise and Windows 365 Flex Cloud PCs in the following Azure regions (categorized by geography):

Africa

Region Group Region
South Africa South Africa North

Asia

Region Group Region
Hong Kong SAR East Asia
Japan Japan East
Japan Japan West
South Korea Korea Central
Singapore Southeast Asia

Australia & New Zealand (ANZ)

Region Group Region
Australia Australia East
New Zealand New Zealand North

Canada

Region Group Region
Canada Canada Central

Mexico

Region Group Region
Mexico Mexico Central

Europe

Region Group Region
France (EU) France Central
Germany (EU) Germany West Central
Ireland (EU) North Europe
Italy (EU) Italy North
Netherlands (EU) West Europe
Norway Norway East
Poland (EU) Poland Central
Spain (EU) Spain Central
Sweden (EU) Sweden Central
Switzerland Switzerland North
United Kingdom UK South

India

Region Group Region
India India Central

Middle East

Region Group Region
Qatar Qatar Central (Restricted)
Israel Israel Central
UAE UAE North

South America

Region Group Region
Brazil Brazil South

US Central

Region Group Region
US Central Central US
US Central South Central US

US East

Region Group Region
US East East US
US East East US 2

US West

Region Group Region
US West West US 2 (Restricted)
US West West US 3

Alternate regions for Business Continuity and Disaster Recovery

A recommended region is an Azure region that supports availability zones and is the preferred location for Cloud PCs in a given geography. Alternate regions help to optimize latency and provide a second region for disaster recovery needs but don't support multiple availability zones. Alternate regions are only available for Cross-region Disaster Recovery (CRDR) and Disaster Recovery Plus (DR+). Because alternate regions only have one availability zone, there is no zonal resistance.

The following alternate regions are available:

Geography Recommended Region Alternate Region
Australasia Australia East Australia Southeast
India Central India South India
How to configure alternate regions

Alternate regions can be selected in Cloud PC configurations. When selecting regions for CRDR or DR+, alternate regions appear below recommended regions with an "Alternate region" label to distinguish them.

Microsoft Hosted Network (MHN)

When using a Microsoft Hosted Network (MHN), navigate to your Cloud PC configuration. After enabling Cross-Region Disaster Recovery or Disaster Recovery Plus, select Change selection under Region groups/regions. Alternate regions appear below the recommended region for the selected geography.

Azure Network Connection (ANC)

For ANC deployments, virtual networks in alternate regions appear under a separate Alternate Region section in the ANC dropdown. Select the appropriate virtual network for your disaster recovery configuration.

Important

Alternate regions are not considered when "Auto select new region groups" and "Auto select new regions" are selected. They must always be intentionally selected in a Cloud PC Configuration.

Considerations
  • No availability zone support: Alternate regions don't have multiple availability zones, so resources in an alternate region aren't protected from datacenter-level failures within that region. If the underlying datacenter experiences an outage, your backup Cloud PCs in the alternate region could be unavailable until the issue is resolved.

  • Disaster recovery only: Alternate regions are supported for CRDR and DR+ scenarios only. They are not supported for Cloud PC provisioning.

Next steps

Review network requirements