Choosing between desktop technologies while double paying for Windows rights optimises the wrong invoice
Three decisions govern remote work licensing, and they are usually treated as peers. They are not. Mapping the entitlements you already hold costs nothing and removes cost immediately. Fixing external worker coverage is a risk decision rather than a cost one. Only the third, the desktop technology choice, is genuine optimisation, and it is the one most estates start with.
Prepared by Redress Compliance · August 10, 2026 · Microsoft advisory. Based on 25 to 35 estates with significant remote work and VDI footprints, 2024 to 2025.
Executive summary
Roughly half the estates were double licensed for rights their subscription already granted.
Enterprise subscriptions at E3 and E5 carry Windows Enterprise per user rights that cover virtual desktop access and qualify users for the packaged desktop service, yet procurement bought device access subscriptions or virtual desktop bundles anyway.
In different budget cycles and by different teams.
At least one population in half the estates carried two overlapping rights for the same access. Nothing is negotiated to fix this; it is an inventory exercise that pays immediately.
External worker coverage was wrong in 4 of 10 estates and anchored most of the audit exposure.
Contractors, outsourcers, and offshore staff accessing your virtual desktops need licences through your agreements or verified coverage through their employer's, and assuming the supplier handles it is the single most common finding in remote work estates.
Read alongside our audit defence work, where unmanaged cloud consumption drove 30 to 50 percent of disputed amounts, external identities on your tenant are cloud sprawl with a compliance tail attached.
Estates that modelled the two desktop services against real usage profiles cut virtual desktop cost 20 to 35 percent. The packaged service prices per user per month at fixed sizes, which is a subscription you can forecast. The consumption service prices as cloud usage you optimise.
In our models the curves crossed around three users per vCPU equivalent with scheduled scaling: above that pooling ratio the consumption route won, below it the flat subscription did. Most estates landed on a mix rather than one or the other.
The same estate usually needs three licensing models at once, and defaulting to one across the whole population is the error. A hybrid worker with three devices is one user licence or three device licences. A shift population sharing kiosks is the reverse.
Thin clients without qualifying Windows need device access subscriptions regardless. Session host architectures still need the server access licences that cloud narratives quietly omit. Segment the populations, then license each by its usage shape.
Which model fits which population
| Scenario | Cheaper model | Why |
|---|---|---|
| Hybrid knowledge worker, three devices | Per user | One licence covers every device they use |
| Shift workers sharing kiosks | Per device | Many users, one machine |
| Call centre on dedicated thin clients | Per device plus device access subscription | The devices lack qualifying Windows |
| Contractors on personal devices | Per user, scoped | Device ownership is irrelevant to the obligation |
Hybrid work inverted the arithmetic and most estates never revisited the default they set before it. Per device licensing made sense when headcount exceeded devices, which was the normal shape of an office estate: shared workstations, one machine per desk, fewer machines than people.
A knowledge worker with a laptop, a home desktop, and a tablet is now three device licences or one user licence, so the same policy that was efficient in 2019 is expensive today without anybody changing it.
The corollary matters as much: per device remains correct where headcount still exceeds devices, on manufacturing floors, clinical workstations, and retail kiosks, so the answer is segmentation rather than a new estate wide default. The suite side sits in the Microsoft 365 licensing pillar.
The order that decides the saving
- Map existing entitlements first, because half the estates already owned the virtual desktop rights they were separately buying, and this step costs nothing and requires no negotiation.
- Fix external worker coverage second, since it is a risk decision rather than a cost one: it anchored most of the audit exposure in our file and it churns faster than employee headcount does.
- Segment the populations third, assigning per user, per device, and device access subscriptions by usage shape rather than letting one model default across the whole estate.
- Model the two desktop services last, against real usage profiles, which cut cost 20 to 35 percent against defaulting to either one.
- Check for the server access licences that session host architectures still require, because cloud framing tends to omit them and they surface in audit rather than in the design review.
The Microsoft EA renewal playbook
The renewal framework, the suite structure, and where virtual desktop rights sit inside the subscriptions you already hold.
Get the white paper →Where the two desktop services actually cross
The technology comparison is usually framed as an architecture decision for the platform team, and framed that way it produces the wrong answer for a commercial reason.
The packaged desktop service is a flat per user subscription at fixed sizes, so it is predictable and it does not reward operational discipline. The consumption service is cloud usage you optimise, so it is unpredictable and it rewards discipline heavily.
That means the honest question is not which is cheaper but whether your organisation has the operating capability to earn the discount the consumption model offers. Unoptimised, it routinely costs more than the flat subscription.
Optimised on pooled workloads it routinely costs less, and the optimisation is specific rather than general: auto scaling host pools, right sized machine families, reserved capacity or savings plans on the base load, and profile storage tiering.
In our models the curves crossed around three users per vCPU equivalent with scheduled scaling in place, which is a useful planning number precisely because it is a density threshold rather than a headcount one. Above it, pooling and scheduling earn enough to beat the flat rate.
Below it, they cannot. The practical consequence is that most estates should stop looking for a single answer: stable full day populations sit better on the flat subscription, pooled and bursty ones on consumption, and the mixed estate outperformed both defaults in our file.
Decide it by population, the same way the licensing model is decided, and decide it after the entitlement and external worker work rather than before. The optimizer sits at M365 license optimizer.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across remote work licensing reviews, 2024 to 2025
The standard advice frames the desktop technology choice as a decision for architects to settle. We disagree, because across roughly 25 to 35 estates the architecture mattered less than two commercial facts that precede it:
Estates carrying two overlapping rights for the same virtual desktop access, bought in different budget cycles by different teams.
Estates where contractor, outsourcer, and offshore access was incorrectly licensed, which anchored most of the actual audit exposure.
Three patterns recurred: double licensing in roughly half the estates, where virtual desktop rights were bought separately despite the subscription already covering them; external worker access incorrectly licensed in 4 of 10 estates.
And estates that modelled the two desktop services against real usage profiles cutting cost 20 to 35 percent against defaulting to either.
The buyer side move is to map existing entitlements and fix external populations before comparing desktop technologies at all, then segment the estate by usage shape rather than applying one licensing model across it. The wider library sits in the Microsoft practice.
Your first five moves
- Map what your existing subscriptions already grant before buying anything for virtual desktops, since half the estates we reviewed were paying twice for the same access rights.
- Inventory every external population with virtual desktop or suite access, then decide the path per population, your tenancy or verified supplier coverage, and paper who licenses, who proves it, and who pays findings.
- Segment by usage shape rather than applying one model estate wide, because the same organisation usually needs per user, per device, and device access coverage across different worker groups.
- Model both desktop services against real usage profiles, using the density threshold of roughly three users per vCPU equivalent with scheduled scaling as the crossover test.
- Review external populations quarterly, since they churn faster than employee headcount and the licensing obligation follows your tenant regardless of where the person sits. The Microsoft practice runs the mapping with you.
Frequently asked questions
Do our existing subscriptions already cover virtual desktop access?
Usually. Enterprise subscriptions at E3 and E5 include Windows Enterprise per user rights covering virtual desktop access and qualifying users for the packaged desktop service.
In roughly half the estates we reviewed, at least one population carried separately purchased rights on top of that, bought in different budget cycles by different teams. Map before buying.
When does per user licensing beat per device?
Whenever the worker uses more devices than the device uses workers. A hybrid knowledge worker with a laptop, a home desktop, and a tablet is three device licences or one user licence.
Per device remains correct where headcount exceeds devices, on manufacturing floors, clinical workstations, and retail kiosks, so the answer is segmentation.
How should external and offshore workers be licensed?
Through your agreements or with verified coverage through their employer's, decided deliberately per population rather than assumed. Assuming the supplier handles it is the single most common finding in remote work estates, and it was wrong in 4 of 10 of ours.
Paper who licenses, who proves it, and who pays any finding.
Does geography change the licensing obligation?
No. Multi region access affects data residency and sometimes programme eligibility, but the licensing obligation follows the tenant and the user rather than the desk.
Offshore staff working on your tenant are your licensing responsibility wherever they physically sit, which is why the population inventory matters more than the org chart.
Which desktop service is cheaper?
It depends on density and on operating discipline. The packaged service is a flat per user subscription that does not reward optimisation; the consumption service rewards it heavily and punishes its absence.
In our models the curves crossed around three users per vCPU equivalent with scheduled scaling: above that the consumption route won, below it the flat subscription did.
What does optimising the consumption route actually require?
Auto scaling host pools, right sized machine families, reserved capacity or savings plans on the base load, and profile storage tiering. Unoptimised it routinely costs more than the flat subscription.
That is why the choice is really a question about operating capability rather than about architecture, and why most estates land on a mix.
What do cloud narratives usually omit?
The server access licences that session host architectures still require.
They are easy to overlook in a design conversation framed around cloud desktops, and they tend to surface during an audit rather than during the review, which is the most expensive moment to discover a licence class nobody budgeted for.
The Microsoft EA Preparation Playbook: The Work That Wins the Renewal
Five workstreams in order: the license position, the usage file, the demand forecast, the benchmark and alternatives files, and the ask list drafted before Microsoft drafts theirs, with the executives aligned before the first meeting.