OSDeploy | Sune Thomsen
TwitterLinkedInWindows 365 CommunityMVP ProfileGitHub
  • Home
  • Blog
    • Microsoft Intune
      • How to migrate BitLocker key(s) from all fixed drives to Microsoft Entra ID.
      • Migrate Bitlocker Recovery Key(s) to Azure AD with Proactive Remediation
      • Migrate imported GPOs to Intune with Group Policy analytics (preview)
      • Group Policy analytics (preview) made a bit easier with PowerShell
      • Analyze on-premises GPOs with MEM Group Policy Analytics (preview)
    • Virtual Machine
      • Fix the Hyper-V virtual switches after updating to Windows 11 (22H2)
    • 🆕Windows 365
      • 🆕Windows 365 Boot: Why User-Driven Mode?
      • 🆕Enhancing Security With Intune MAM (preview) for Windows 365
      • The Concept of Windows 365 Switch
      • The Concept of Windows 365 Boot
      • The Concept of Windows 365 Frontline
      • Move Cloud PCs to a new Azure Region or Azure Network Connection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 4. Windows 365 app and Cloud PC reporting
      • Windows 365 End-User Experience (Tips & Tricks) – Part 3. Multimedia Redirection
      • Windows 365 End-User Experience (Tips & Tricks) – Part 2. Teams Optimization, SSO, and Localization
      • Windows 365 End-User Experience (Tips & Tricks) – Part 1. Connection experience
      • How to Configure Windows 365 Azure AD Join Single Sign-on (SSO)
      • Keep Windows 365 current and stay current with Windows Autopatch
      • Provide the end-users with a localized Windows 365 Cloud PC experience
      • How to configure Windows 365 Enterprise Azure AD join
      • How to secure Windows 365 using a FIDO2 security key
      • Prevent sensitive information from being captured on Windows 365 CPCs
      • Manage local administrator rights on Windows 365 Cloud PCs.
      • How to create a custom image for Windows 365 Enterprise Cloud PCs
      • How to reprovision existing Cloud PC (Windows 365) to Windows 11
      • How to configure Windows 365 Enterprise in Microsoft Endpoint Manager
  • Archive
    • Deployment
      • OSDCloud: The ZTI Way
      • OSDBuilder: WinPE Customization
    • Microsoft Configuration Manager
      • ConfigMgr: Run "All" Client Actions During OSD
      • ConfigMgr: WIM Your Applications Like a Boss
      • ConfigMgr: Deploy UWP Applications During OSD
      • ConfigMgr: Building a Basic LAB Environment
        • Part 1 - Installing Windows 10 (1909) on the Host
        • Part 2 - The Host and Hyper-V Configuration
        • Part 3 - Setting up the Domain Controller
          • Active Directory
          • DHCP
          • DNS
        • Part 4 - Setting up Microsoft Endpoint Configuration Manager
          • Prerequisites
          • SQL
        • Part 5 - Setting up Discovery Methods and Boundaries
        • Part 6 - Setting up Software Update Point
      • ConfigMgr: Splash Screen for Driver and BIOS Update
      • ConfigMgr: Global Conditions for Dell WD15 Dock Detection
    • Microsoft Intune
      • Block personally owned devices in Intune with enrollment restrictions
      • Remove Windows 10 built-in apps with Intune & Microsoft Store for Business Apps
    • Windows
      • Win10: Multi-Language Toast Notifications
        • Toast Notification: Low Disk Space
  • Links
    • Blogs
    • Microsoft
    • Scripts
Powered by GitBook
On this page
  • BEFORE YOU BEGIN
  • Prerequisites and Requirements
  • Licensing Requirements
  • What is Windows 365 Frontline?
  • Power On and Power Off
  • Windows Update Optimizations for Frontline Cloud PCs
  • Management and Accessibility
  • The Windows 365 Enterprise License Model
  • The Windows 365 Frontline License Model
  • The Use Cases of Windows 365 Frontline
  • How to Configure Windows 365 Frontline Cloud PCs
  • Monitor Concurrent Frontline Cloud PC Connections
  • How to Time Limit the Session on Frontline Cloud PCs
  • Verification
  • Summary

Was this helpful?

  1. Blog
  2. Windows 365

The Concept of Windows 365 Frontline

18-12-2023 12:55 PM

PreviousThe Concept of Windows 365 BootNextMove Cloud PCs to a new Azure Region or Azure Network Connection

Last updated 9 months ago

Was this helpful?

BEFORE YOU BEGIN

Disclaimer: All information and content in this blog post is provided without any warranty whatsoever. The entire risk of using this information or executing the provided content remains with you. Under no circumstances should the mentioned persons or vendors, the author, or anyone else involved in creating these blog posts be held liable for any damage or data loss.

In this blog post, I will explore the concept of Windows 365 Frontline. Windows 365 Frontline became generally available (GA) in July 2023, and it should not be confused with the Microsoft 365 F1 or F3 licenses.

So, buckle up and join me as I explore this “new” license model from Microsoft, where a single Windows 365 Frontline license supports up to three personal Cloud PCs. Also, let’s look at use cases and who would benefit from the Windows 365 Frontline license model.

In this post, I’ll cover the following topics.

Prerequisites and Requirements

  • You must have a valid and working Microsoft Entra and Intune tenant.

  • You must have Windows 365 Enterprise or Frontline licenses to manage Cloud PC configurations.

  • You must use Microsoft Intune to manage your Cloud PCs.

  • To configure and provision Cloud PCs, you must have the Cloud PC Administrator role in Microsoft Intune or one of the following roles in Microsoft Entra ID:

    • Global Administrator

    • Intune Administrator

    • Windows 365 Administrator

Licensing Requirements

  • Windows 10 Enterprise or Windows 11 Enterprise

  • Microsoft Entra ID P1

  • Microsoft Intune

Windows 10/11 Enterprise, Microsoft Entra ID, and Microsoft Intune licenses are included in: Microsoft 365 E3, Microsoft 365 E5, Microsoft 365 F3, Microsoft 365 A3, Microsoft 365 A5, Microsoft 365 Business Premium, and Microsoft 365 Education Student Use Benefit subscriptions.

What is Windows 365 Frontline?

Windows 365 Frontline is a version of Windows 365 Enterprise (they share the same capabilities) designed for employees who do not require constant access to their personal Cloud PCs.

Frontline Cloud PCs can be helpful for employees who are:

  • On a rotating shift schedule.

  • Working across time zones and regions (for example, the follow-the-sun model).

  • Part-time workers.

  • Contingent staff (for example, consultants and freelancers).

Unlike other licenses, the licensing structure of Windows 365 Frontline is based on pooled licenses applied at the tenant level rather than directly to individual users. But how do we then keep track of license usage, you might ask? License usage is tracked via the Frontline Cloud PC provisioning policy, where the licenses are assigned, and the Concurrent Frontline Cloud PC connections report can also be used as an indicator for license usage (see the screenshots below).

Power On and Power Off

When employees log on, the Frontline Cloud PC is powered on, and a license is taken from the shared license pool (if any licenses are available). As they log off, their Frontline Cloud PC is powered off, and the license is returned to the shared license pool, making it available for other users to start their Frontline Cloud PC.

But what happens if an employee forgets to log off or disconnect? By default, Windows 365 Frontline detects user inactivity and automatically disconnects after two hours. Well, that’s great! But we can all agree that it’s not ideal for employees to wait two hours for a license to become available, right?

So what can you do about it? We’ll look at that later in this post, where I’ll create a policy to enforce an idle session time limit and configure it to disconnect after 15 minutes – although that might be a bit too aggressive!

Note: IT Admins can Power on and Power off a Frontline Cloud PC via remote actions, along with the ability to view the power state of a Frontline Cloud PC in Microsoft Intune.

Windows Update Optimizations for Frontline Cloud PCs

This feature works together with Windows Update for Business (WUfB) to apply OS reboots outside of work hours when the user disconnects, increasing productivity and minimizing disruption.

Management and Accessibility

Management of Windows 365 Frontline Cloud PCs happens through Microsoft Intune, providing you centralized control over these Cloud PCs and other devices within your tenant.

Users can access their Windows 365 Frontline Cloud PC directly via a physical Windows 365 Boot device, the Windows 365 Web Client, or the new Windows App (formerly known as the Windows 365 App). The Windows App is available on Windows, macOS, iOS, iPadOS, and web browsers.

Note: Windows 365 Boot supports Windows 365 Frontline Cloud PCs after it became generally available (GA) in September 2023. Windows 365 Boot makes it easier for people to log on to their Windows 11 experience on their Frontline Cloud PC, helping Frontline, Shift, and Part-time workers become productive from the moment they log on.

The Windows 365 Enterprise License Model

The traditional Windows 365 Enterprise license model is based on every user having a Windows 365 license, which gives them their own personal PC in the cloud that’s available 24/7.

In the example below, we have three shifts with 10 employees on each shift. This gives us 30 employees in total, so 30 traditional Windows 365 licenses are needed! Let’s say that each license SKU costs approx. 75€ per user/month. That’s 2.250€ per month! – Pretty expensive, huh?

But organizations that operate with shift workers don’t necessarily need Cloud PCs that are available 24/7. They may only need to be available during the employee’s shift and can be offline the rest of the time.

The Windows 365 Frontline License Model

So, with Windows 365 Frontline, Microsoft has introduced a license model where a single Windows 365 Frontline license supports up to three personal Cloud PCs, which can be used by any employee if only one employee per license is active at any given time.

– Or told in another way, you can have ten concurrent connections with 10 x Windows 365 Frontline licenses.

Using the previous example, we can now settle for 10 x Windows 365 Frontline licenses; each equivalent license SKU costs approx. 113€ per license/month. That’s 1.130€ per month, which is much more affordable than the traditional licenses!

The Use Cases of Windows 365 Frontline

But who would benefit from the Windows 365 Frontline license model? Well, I could see this as an ideal solution for hospitals or call centers that operate with shift workers or part-time employees, or how about employees that need more than one Cloud PC of the same SKU size – interesting thought, huh?

How to Configure Windows 365 Frontline Cloud PCs

Now that you know everything about Windows 365 Frontline let me show you how to set this up in Microsoft Intune. We start by creating a security group for our Windows 365 Frontline users. Next, we’ll create a provisioning policy for Frontline Cloud PCs and assign the Windows 365 Frontline licenses.

Create a new Microsoft Entra ID security group for the Windows 365 Frontline users. I have created a group and added four members. – The group can be based on direct or dynamic membership.

Next, select Devices | Windows 365 (under Provisioning) | Provisioning policies to create a provisioning policy for Frontline Cloud PCs.

Fill in the required Name field on the General page and select Frontline as the License type. Next, choose the European Union under the Microsoft Hosted Network. Click Next.

Keep the Image type as is and click Next.

Define a Cloud PC naming convention and click Next. – I’ve added FLW to the naming for some traceability.

Next, we’ll select my newly created Windows 365 Frontline security group to be assigned to this policy. You then need to choose a Cloud PC license SKU size. Click Select and Next.

Note: You will see a warning if there are fewer Frontline Cloud PCs for the selected SKU size than members in the security group. – If you continue, some members won’t receive a Cloud PC.

Review that everything is correct and click Create.

If you added more users than available Frontline Cloud PC licenses, the members who won’t receive a Cloud PC will be listed under User preview in the provisioning policy.

Monitor Concurrent Frontline Cloud PC Connections

Now, let me show you where to monitor the concurrent Frontline Cloud PC connections in Microsoft Intune.

Reviewing the maximum concurrent Frontline Cloud PC connections lets you decide if you need to purchase more licenses to ensure your end users aren’t blocked from using their Windows 365 Frontline Cloud PCs.

IT admins can monitor the concurrent Frontline Cloud PC connections from this report.

How to Time Limit the Session on Frontline Cloud PCs

As mentioned earlier in this post, Windows 365 Frontline detects user inactivity and automatically disconnects the session after two hours by default. Now, let me show you how we can prevent users from blocking a license for two hours for another user by creating a policy to enforce idle session time limits.

Fill in the required Name field on the Basics page.

Tip: Although the Description field is optional, I recommend filling it out. Leaving some breadcrumbs is always a great idea so others know precisely why someone created the configuration profile.

Click + Add settings on the Configuration settings page. In the Settings picker, search for Session Time Limit.

Choose Windows Components\Remote Desktop Services\Remote Desktop Session Host\Session Time Limits and select the following two settings:

  • End session when time limits are reached

  • Set time limit for active but idle Remote Desktop Services sessions

Close the Settings picker.

Enable both settings and set the Idle session limit: (Device) to a value of your choice. Click Next.

Select Scope tags if needed and click Next.

On the Assignments page, add a security group containing Frontline Cloud PCs to be assigned to this policy. Click Next.

Review that everything is correct and click Create.

Verification

End users will encounter these dialog boxes when a Windows 365 Frontline session is ended due to inactivity.

Summary

In this blog post, you learned about the concept of Windows 365 Frontline and how it differs from the Enterprise edition. I shared my view on use cases, knowledge about how to set up a provisioning policy for Frontline Cloud PCs, and a few ways to track license usage.

In addition, I also showed you how to prevent users from blocking a license for two hours for another user by enforcing an idle session time limit policy.

That’s it, folks. Happy testing, and have fun exploring 🤓 If you have any questions regarding this topic, please feel free to reach out to me.

Go to In the left pane, select Groups.

Note: This report is specific to Windows 365 Frontline and doesn’t apply to other Windows 365 plans. The report will show no results if no Frontline licenses have been purchased on your tenant. To learn more, see

Go to Select Devices | Cloud PC performance (preview) Click View report under Connected Frontline Cloud PCs (preview).

Go to Select Devices | Windows (under By platform) | Configuration profiles Click + New Policy, choose Windows 10 and later, and the Settings catalog, and click Create.

https://intune.microsoft.com
Connected Frontline Cloud PCs report (preview)
https://intune.microsoft.com
https://intune.microsoft.com

Windows 365 Enterprise

For organizations that want to manage Cloud PCs through Microsoft Intune and take advantage of integrations with other Microsoft services.

  • Dedicated, all-day Cloud PC access

  • Personalized, full Windows experience

  • Predictable monthly pricing

Windows 365 Frontline

For organizations of any size that employ shift and part-time workers who only need access to corporate data, apps, and resources during their shift.

  • Cloud PC access only when they need it (for example, during their shift)

  • Personalized, full Windows experience

  • Predictable monthly pricing

Prerequisites and Requirements
What is Windows 365 Frontline?
The Windows 365 Enterprise License Model
The Windows 365 Frontline License Model
The Use Cases of Windows 365 Frontline
How to Configure Windows 365 Frontline Cloud PCs
Monitor Concurrent Frontline Cloud PC Connections
How to Time Limit the Session on Frontline Cloud PCs
Summary

🆕

Source:

Read more >
Read more >
Microsoft Designer
Page cover image
To learn more, see .
To learn more about Windows App, see
Configure Windows Update for Windows 365 Frontline Cloud PCs
What is Windows App?