Azure Virtual Desktop (AVD) is a desktop and application virtualization service that runs on Azure. It provides multi-session Windows desktops and published applications with simplified management and scaling.
The service architecture is similar to Windows Server Remote Desktop Services (RDS). However, unlike traditional RDS, Microsoft manages the infrastructure and brokering components while customers manage their own desktop host VMs, data, and clients.
Cloud Architecture
Create cloud architecture diagrams for AWS, Azure, GCP, and more. Design scalable infrastructure with professional cloud icons.
Complete guide to Azure Virtual Desktop architecture diagrams—control plane, host pools, FSLogix, hub-spoke, landing zones, BCDR, and tools.
Click Cloud Architecture to open AI Line Studio and generate diagrams from natural language in seconds.
The Azure Virtual Desktop service comprises many components that connect users to their desktops and apps. Most components are Microsoft-managed, but some are customer-managed.
| Component | Purpose |
|---|---|
| Web service | User-facing website and endpoint that returns connection information to the user's device |
| Broker service | Orchestrates incoming connections |
| Gateway service | A WebSocket service that provides Remote Desktop Protocol (RDP) connectivity from any device to session hosts |
| Resource directory | Instructs the web service which geographical database holds the connection information for each user |
| Geographical database | Contains connection files (.rdp) and icons for every resource a user has been provisioned |
| Diagnostics and extensibility | REST APIs and diagnostic components |
Additionally, Azure Virtual Desktop uses global Azure services such as Azure Traffic Manager and Azure Front Door to direct users to their closest entry points.
Customers manage:
You can use other Azure services to meet your requirements:
| Service | Use Case |
|---|---|
| Azure Availability Zones | Distribute session hosts across physically separate datacenters within an Azure region |
| Azure Backup | Back up and restore session hosts |
| Azure Site Recovery | Replicate session hosts to another Azure region |
| Azure Advisor | Optimize Azure resources |
Beyond the service components, Azure Virtual Desktop includes several logical constructs that customers manage.
A host pool is a collection of session hosts (Azure VMs) that provide desktops and applications to users. Host pools can be:
Workspaces are logical containers that group application groups. Users see workspaces in their feed, providing access to the desktops and applications published to them.
Application groups define which desktops or applications are available to which users. Application groups can contain:
A typical architectural setup for Azure Virtual Desktop follows a baseline implementation.
Download a Visio file of this architecture: virtual-desktop-get-started-diagram.vsdx
Key components:
The application endpoints are in the customer's on-premises network. Azure ExpressRoute extends the on-premises network into Azure, and Microsoft Entra Connect integrates AD DS with Microsoft Entra ID.
For enterprise-scale deployments, organizations typically use a hub-spoke architecture with multiple Azure subscriptions.
Layout:
┌─────────────────────────────────────────────────────────────────────────────┐
│ Hub VNet (Central Services) │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Azure │ │ Azure │ │ Azure │ │
│ │ Firewall │ │ Bastion │ │ VPN/ │ │
│ │ │ │ │ │ ExpressRoute│ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└─────────────────────────────────────────────────────────────────────────────┘
│ │ │
▼ ▼ ▼
┌───────────────┐ ┌───────────────┐ ┌───────────────┐
│ Spoke VNet │ │ Spoke VNet │ │ Spoke VNet │
│ (Production) │ │ (Staging) │ │ (Development)│
│ ┌─────────┐ │ │ ┌─────────┐ │ │ ┌─────────┐ │
│ │ Session │ │ │ │ Session │ │ │ │ Session │ │
│ │ Hosts │ │ │ │ Hosts │ │ │ │ Hosts │ │
│ └─────────┘ │ │ └─────────┘ │ │ └─────────┘ │
│ ┌─────────┐ │ │ ┌─────────┐ │ │ ┌─────────┐ │
│ │ FSLogix │ │ │ │ FSLogix │ │ │ │ FSLogix │ │
│ │ Storage │ │ │ │ Storage │ │ │ │ Storage │ │
│ └─────────┘ │ │ └─────────┘ │ │ └─────────┘ │
└───────────────┘ └───────────────┘ └───────────────┘
Why this works:
To increase capacity, enterprise customers use two Azure subscriptions in a hub-spoke architecture and connect them via virtual network peering.
The Azure Virtual Desktop landing zone accelerator provides a specific architectural approach and reference implementation for enterprise deployments.
Download a Visio file of this architecture: avd-accelerator-enterprise-scale-alz-architecture.vsdx
Key design areas:
| Design Area | Focus |
|---|---|
| Identity | Microsoft Entra ID, AD DS integration, hybrid identity |
| Network topology | Hub-spoke, connectivity to on-premises, private endpoints |
| Security | Azure Firewall, network security groups, Microsoft Defender for Cloud |
| Management | Azure Monitor, Log Analytics, Azure Automation |
| Governance | Azure Policy, role-based access control (RBAC) |
| Platform automation | Infrastructure as Code (Bicep, Terraform), CI/CD |
| Storage | FSLogix profiles, Azure Files, Azure NetApp Files |
| Scale | Multi-region expansion, capacity planning |
For organizations requiring high availability across regions, the multi-region BCDR architecture provides guidance for deploying Azure Virtual Desktop with business continuity and disaster recovery.
Key considerations:
FSLogix stores user profiles in virtual hard disk (VHD) containers. Cloud Cache can replicate profiles across regions for disaster recovery.
For hybrid and edge scenarios, Azure Virtual Desktop can be deployed on Azure Local (formerly Azure Stack HCI).
High-level architecture:
FSLogix is the recommended user profile solution for Azure Virtual Desktop. It is designed to roam profiles in remote computing environments.
FSLogix containers redirect user profiles to a network location:
| Storage Option | Best For |
|---|---|
| Azure Files | Most common option, fully managed SMB file shares |
| Azure NetApp Files | High performance, enterprise-grade file storage |
When a user wants to access their desktops and apps, there are two separate sequences:
The feed is the list of desktops and apps available to the user:
After feed discovery, the user establishes an RDP connection to a session host.
Key recommendations:
Key recommendations:
Key recommendations:
Key recommendations:
Key recommendations:
| Resource | Description |
|---|---|
| Azure Architecture Center | Primary source for reference architectures and downloadable Visio files |
| Enterprise-scale Visio file | avd-accelerator-enterprise-scale-alz-architecture.vsdx |
| Baseline Visio file | virtual-desktop-get-started-diagram.vsdx |
| Enterprise Visio file | wvdatscale.vsdx |
| Landing zone Visio file | avd-accelerator-enterprise-scale-alz-architecture.vsdx |
AI-powered tools are transforming how architects create Azure Virtual Desktop architecture diagrams. Instead of manually dragging boxes, you describe your VDI architecture in natural language, and the tool generates a professional diagram.
AI Line Studio: Generates Azure architecture diagrams from natural language descriptions in seconds. Describe a VDI architecture—"a secure Azure Virtual Desktop deployment with host pools, FSLogix profiles, hub-spoke networking, and multi-region disaster recovery"—and it produces a structured diagram with official Azure icons. For Azure-specific workflows, use the dedicated AI cloud diagram generator.
Visual Paradigm AI Cloud Architecture Studio: A browser-based AI tool that aligns your infrastructure with Azure Well-Architected Framework and enterprise best practices.
GenAI-DrawIO-Creator: An AI-powered diagram generation tool that creates, modifies, and enhances diagrams through natural language commands with support for Azure, AWS, GCP, and Kubernetes.
Draw.io (diagrams.net): A free, browser-based tool with a built-in Azure shape library. Enables you to create professional Azure Virtual Desktop architecture diagrams with official Azure icons.
Microsoft Visio: The recommended tool for creating Azure architecture diagrams. Reference architectures in the Azure Architecture Center include downloadable Visio files.
| Component | Responsibility | Purpose |
|---|---|---|
| Web service | Microsoft | User-facing website and endpoint |
| Broker service | Microsoft | Orchestrates incoming connections |
| Gateway service | Microsoft | Provides RDP connectivity |
| Resource directory | Microsoft | Routes users to the right geographical database |
| Session hosts | Customer | VMs providing desktops and apps |
| Host pools | Customer | Collection of session hosts |
| Workspaces | Customer | Logical containers for application groups |
| FSLogix profiles | Customer | User profile containers |
Key takeaways:
To start building your own Azure Virtual Desktop architecture diagrams, explore the Azure architecture diagram tool for templates and examples. For automated diagram generation, try the AI cloud diagram generator to turn a VDI description into a visual instantly.