Enterprise

Enterprise EUC team and a 24-hour service desk

An EUC team wanted scoped session actions for a 24-hour service desk and for department owners, without Azure roles on every person.

Example setup for this sector. Not a named customer, and not a results claim.

The estate

Personal and pooled host pools for a UK head office and two regional sites.

The problem

Out-of-hours staff used a shared privileged account in the Azure Portal. Business teams logged tickets for idle sessions that they could have cleared themselves. Nobody could show who sent a log-off during a change freeze.

What they set up

  1. 1

    Stand up AvdControl. The AVD data plane stays in the customer subscription.

  2. 2

    Map service desk to help desk across the shared pools. Give a department owner help desk on their own host pool so they do not log a ticket.

  3. 3

    Map EUC to session admin for log off. Turn on MFA for owner and admin.

  4. 4

    Use session state filters (active, idle, disconnected) on the night shift.

What that gives them

  • No shared Azure admin account for session actions.
  • A business owner can message or disconnect on their pool without a ticket.
  • Change-freeze reviews use the tenant audit list, not Portal activity logs.