Windows 11 is entering the conversation for physical PCs and, inevitably, for Azure Virtual Desktop and VDI images. September 2021 is early for mass production flips. This post is what we are testing, what we are not promising, and how image strategy should work for estates still stabilizing on Windows 10 multi-session.
Physical vs session host are different clocks
Hardware TPM and CPU lists constrain physical refresh. AVD session hosts follow Azure marketplace images and your golden image pipeline — different blockers. Do not slip a VDI program because a laptop vendor is late on drivers unless they share an image.
What we test in the lab
- Golden image build on Windows 11 where media allows
- FSLogix behavior and login duration vs Win10 baseline
- Office and Teams in-session
- Printer and peripheral redirection policies
- GPU scenarios if you have them
- FSLogix + OneDrive known-folder interactions
Production posture
Default: keep production AVD/WVD pools on validated Windows 10 multi-session until pilot metrics beat baseline.
Pilot: one IT or friendly pool on Windows 11.
Broad: only after P95 login and ticket rates are acceptable.
App compatibility
The usual LOB suspects will lag. VDI is sometimes the containment strategy for apps that will not certify on Windows 11 endpoints quickly — same pattern as Windows 7 exceptions years ago.
Communication
Users do not care about multi-session kernel details. They care if Outlook search works. Publish pilot criteria in plain language.
Image pipeline changes
Windows 11 images need the same sealing discipline as Windows 10: updates, agents, FSLogix, Office, security tools, then sysprep or seal process appropriate to AVD. Document versions. Store images in a gallery with tags. Rollback is a tagged previous image, not a prayer.
Driver and agent matrix
Security agents and monitoring tools lag OS releases. Maintain a matrix: agent version, supported OS, known issues. Block broad deploy when a critical agent is unsupported — even if the desktop “looks fine” in a smoke test.
User communication for pilots
Pilot users get a one-pager: what might break, how to report, how to fall back to Windows 10 pool if you provide one. Heroes who suffer silently poison metrics.
Cost note
New OS images do not inherently cost more in Azure, but failed rollouts do — emergency dual pools, helpdesk surge, rolled-back hosts. Budget pilot capacity explicitly.
Decision gate
Promote Windows 11 multi-session only when: P95 login less or equal to baseline, critical apps certified or mitigated, agents supported, and rollback tested once for real.
Scenario walkthrough
Consider a mid-size organization with hybrid identity, mixed desktop delivery, and a mandate to reduce risk without stopping the business. Week one is inventory and sponsor alignment. Week two is a written target state with two options and explicit out-of-scope items. Weeks three and four are pilot build and measurement. Only then does broad change begin. Compressing that sequence into a single weekend is how outages are born.
Along the way, three conversations dominate: who owns identity decisions, who pays for platform capacity, and what residual risk leadership accepts in writing. When those conversations are avoided, engineers improvise under pressure and the organization inherits accidental architecture.
We keep a living risk register with severity, mitigation, residual risk, and owner. The register is reviewed in the same meeting as the delivery burn-down. Risks that never move owners are the ones that become incidents.
If you're facing this
If leadership wants “all AVD on Windows 11 by year-end,” counter with a pilot gate. We test and productionize AVD images with FSLogix — bring current login metrics and app certification constraints.