Windows 365 Reserve: Secure On-Demand Cloud PCs for Business Continuity
Logan Silliman explains Windows 365 Reserve, Microsoft’s new solution for providing secure, on-demand Cloud PCs during device outages. The post covers admin management in Intune, security design, and end-user experience.
Windows 365 Reserve: Secure On-Demand Cloud PCs for Business Continuity
Author: Logan Silliman
Updated: Aug 08, 2025
Overview
Windows 365 Reserve is a new standalone Windows 365 feature providing organizations with the ability to grant employees secure, temporary Cloud PC access (up to 10 days/year) when primary devices are unavailable. Designed for fast recovery from device failures or incidents like malware and theft, this solution ensures workforce productivity and operational resiliency.
Key Features and Benefits
- Rapid Cloud PC Deployment: Admins can quickly provision pre-configured Cloud PCs with all the necessary apps and security for users whose physical devices are lost or under repair.
- Centralized IT Management: Provision and manage these temporary Cloud PCs within Microsoft Intune using organization-wide policies.
- Secure by Design: Integrates Zero Trust principles—access is managed, can be revoked at any time, and inherits organization security baselines.
- Flexible Access: Employees use any secondary device to connect—managed or personal—via web or the Windows App, supporting remote and hybrid work needs.
- Operational Control: Licenses allow up to 10 days of Cloud PC use per user/year, consumable in multiple sessions. Timely notifications help admins and users manage and preserve allotted time efficiently.
Admin Experience
- Simple Setup: After purchasing licenses, setup is done within Intune. Admins create provisioning policies specifying:
- Cloud PC geography
- Microsoft Entra user groups for coverage
- (Optionally) Gallery image version, language, and scope tags
- Default Selections: To simplify rapid deployment, some configuration (Cloud PC size, region, and network) is managed automatically.
- Intune Integration: Deployment, access, and security control are unified in Microsoft Intune, minimizing IT overhead during disruptions.
- Provisioning Delay: Policies and group assignments must be in place seven days before distributing Cloud PCs.
- Usage and Deprovisioning: When issues are resolved, Cloud PCs can be deprovisioned to save unused access days. Deprovisioning is handled through Intune.
End-User Experience
- Accessible from Anywhere: Users connect to their temporary Cloud PC from any device using the web or the Windows App.
- Clear Guidance: Users are informed of expiration dates and receive prompts to deprovision when their primary device is restored.
- Security Maintained: All access occurs within organization’s compliance and security policies.
Security and Compliance
- Zero Trust Principles: All provisioning and deprovisioning actions are under admin control. Access can be revoked at any time.
- Network and Capacity: Requires network connectivity and may face Azure regional capacity constraints.
- Audit and Reporting: Use Intune reporting for access management and incident tracking.
How to Join the Preview
Windows 365 Reserve is in a gated public preview. To participate:
- Complete this form
- Or reach out to your Microsoft account team
Additional Resources
- Original disclosure
- Windows Tech Community
- Windows App on all major platforms
- Support: Windows on Microsoft Q&A
Note: Windows 365 Reserve is a preview feature. Details and features may change before general availability.
This post appeared first on “Microsoft Tech Community”. Read the entire article here