Below is each announcement, what it means for administrators, and where the limits are. The limits come from Microsoft Learn's Windows 365 "What's new" log and the related product documentation.
The fine print first
Microsoft's Windows 365 update log says monthly changes can take several weeks to roll out and may not reach every tenant right away. If a feature is missing from your Intune admin center today, your tenant probably isn't wrong. It may just not have the update yet.
The recap also doesn't cover every September entry in the service log. Microsoft Learn lists other late-September items that the blog post leaves out:
- Session State Retention is GA for eligible Windows 365 Flex Dedicated Cloud PCs. If a user stays disconnected past an idle period (two hours by default), the Cloud PC keeps the session open instead of powering off.
- Bulk deprovisioning is GA for eligible Enterprise and Flex Dedicated Cloud PCs in the seven-day grace period.
- Windows 11 26H2 Cloud PC gallery images are now listed.
The blog post is a curated highlight reel, not the full changelog.
Summary: Expect a staggered rollout. Read the Learn log alongside the recap.
User experience and connectivity
TWAIN scanner redirection (Public Preview)
A supported TWAIN scanner attached to a local Windows device can now be redirected into a Cloud PC using high-level redirection. Microsoft says this works better than generic USB redirection.
This is a preview, and it doesn't cover every scanner. Microsoft Learn's scanner-redirection guidance requires three things:
- the scanner driver installed on the local device
- a supported client and platform
- the feature turned on at the remote host, with the local device configured too
If your users in claims processing or medical records have been fighting USB passthrough, this is worth testing in a pilot group.
User provisioning for Windows 365 Reserve (GA)
Windows 365 Reserve is the edition for when someone's laptop dies, gets lost or is stuck in a repair queue. With this change, eligible users can start provisioning their own Reserve Cloud PC from Windows App instead of filing a ticket.
It isn't open self-service. Microsoft's documentation from the preview phase said the capability is off by default and controlled by IT. Admins turn it on through Windows App settings for Windows 365 in Intune and limit it to specific Microsoft Entra ID groups. Licensing and policy stay with IT.
RDP Multipath and Shortpath in Azure Government
Government tenants get two connectivity upgrades:
- RDP Multipath: redundant UDP transport paths are GA for Windows 365 in Azure Government. Redundant TCP paths are in a phased GA rollout, so they may not appear on every Cloud PC yet.
- RDP Shortpath with TURN: this is also in a phased GA rollout. TURN relays UDP traffic when a direct connection can't be made.
Network teams should note that the Learn entry gives Azure Government a dedicated STUN/TURN range, 20.140.236.0/22. That's separate from the global commercial TURN range, which Microsoft moved to 51.5.0.0/16 earlier this year. Check the current endpoint and port requirements before you change firewall rules. Don't copy a range from a commercial tenant into a GCC High firewall policy.
Windows App for macOS beta gets Shortpath and Multipath
Windows App for macOS Beta version 11.3.8 (3048) adds RDP Shortpath for public networks and RDP Multipath with UDP, for both Windows 365 and AVD. Mac users who've had dropped sessions on hotel Wi-Fi should see more resilient connections. It's a beta build, though, so don't push it to your whole Mac fleet as if it were a production release.
External identities on macOS and iOS
Invited users from outside the organization can now connect through Windows App without IT creating a full user account for each one. This is GA on macOS and in Preview on iOS. Your tenant still has to be set up for external identities.
Summary: Reserve self-provisioning is the biggest change for day-to-day work. The connectivity items mostly matter to Mac users and government tenants.
Security, recovery and resilience
Business continuity and disaster recovery in one place (GA)
Point-in-time restore, cross-region disaster recovery (CRDR) and Disaster Recovery Plus (DR+) can now all be configured from a single Cloud PC configuration in Cloud PC Settings. This makes setup easier, but it doesn't turn recovery on for you. You still have to configure and assign it.
Alternate recovery regions (GA)
Alternate regions for CRDR and DR+ have moved from preview to GA, and the list has grown. In the public preview, Microsoft named Australia Southeast and South India. The GA list adds Canada East and West US.
Microsoft Learn is clear that these regions are for disaster recovery only and can't be used for Cloud PC provisioning. They're meant for organizations in geographies with only one Windows 365-supported region. They give your backups somewhere in-country to go, but they don't become new places to provision Cloud PCs.
Cloud PC recovery for Windows 365 Government (GA)
Windows 365 Enterprise admins in GCC and GCCH can now recover eligible Cloud PCs that were deprovisioned after a license expired. You reprovision the Cloud PC, then use the Restore action. Commercial tenants already had this. Only eligible Cloud PCs qualify, so don't treat it as unlimited protection against licensing mistakes.
In-session passwordless on iOS (Preview)
On iOS, Windows App can now answer supported Entra ID sign-in prompts inside the Cloud PC session with passkeys instead of a password. That includes physical security keys and the QR-code flow.
The Android preview shipped last month and works differently. It only supports passkeys stored on the device, such as in Microsoft Authenticator. Security keys and QR codes from other devices aren't supported there. The two mobile previews don't behave the same way, which matters if your help desk writes one set of instructions for both.
Display Protection (Public Preview)
Display Protection has the most to unpack this month. Microsoft Learn says it encrypts the display stream from the Cloud PC to the endpoint. The stream is decrypted only inside a trusted path: in the GPU when compatible hardware is present, and in protected software rendering otherwise. The goal is to block screen capture and recording by malware or tools running on the endpoint.
Client support is narrow:
| Requirement | Detail (per Microsoft Learn) |
|---|---|
| Supported client | Windows App on a physical Windows 11 device, version 2.0.1236.0 or newer |
| Not supported | Virtual machines as endpoints, macOS, iOS, Android, web browsers, Windows 365 Link |
| Displays | No DisplayLink or USB graphics adapters; HDCP needed when enforced |
| Max resolution | 4K (3840 x 2160) |
To turn it on for Windows 365:
- Sign in to the Microsoft Intune admin center.
- Go to Devices > Manage Windows 365 Cloud PCs > Cloud PC Settings.
- Under IO Protection, pick a Display Protection level. The options are "Hardware or software enforcement" (falls back to software when hardware isn't available) or "Hardware enforcement required" (blocks endpoints that can't meet it).
To check that it works:
- Connect from a physical Windows 11 endpoint running a supported Windows App build.
- Try a screen capture tool while the session is active. The remote session should be blocked or show up blank.
Common failures and fixes:
- 0x204 / 0x11f5 (incompatible client): the user is on iOS, macOS or Android, or on an older Windows App. It also happens when the setting changed recently and hasn't reached the device yet. Select Refresh in Windows App, or wait up to eight hours for the change to propagate.
- 0x204 / 0x11f6 (policy not met): usually hardware-only enforcement on an endpoint without proper GPU support.
- 0x110 (HDCP): old docks, DisplayLink adapters, VGA cables or non-HDCP monitors.
Want to know how many "connection failed" calls you'll get after enabling this for the finance team? Count how many of them use DisplayLink docks.
AVD regional host pools: a status conflict
The recap says regional host pools are GA in East US 2 and Central US, for better resiliency and data sovereignty. When last checked, Microsoft Learn's regional host pools page (last updated August 29) still called the feature preview. It also said a gradual rollout to more regions would start once GA arrives.
The architecture is the same either way. Regional host pools store their metadata on separate backend infrastructure with fewer cross-region dependencies. Regional and geographical objects can't be mixed: a regional application group can't join a geographical workspace. Check the status in your portal before you write a production architecture around it.
Summary: The disaster recovery changes are straightforward GA wins. Display Protection is a serious control, but only for Windows 11 endpoints, so plan which users get it.
Manageability
Admin Insights (GA)
Admin Insights shows prioritized, service-generated issues and optimization opportunities on the Cloud PC Overview page in Intune. Where available, they link to the related reports or device views. You can't set your own thresholds, because Microsoft generates the signals. It's a to-do list that adds to your monitoring and alerting rather than replacing it.
Local admin through Cloud PC configurations (Public Preview)
The existing Enable local admin setting can now be found under Devices > Cloud PC Settings > Create > Cloud PC configurations in Intune. Admins can use it to give selected users local administrator rights on their own Cloud PCs. Developers who need to install toolchains will like it. Security teams should treat it like any other privilege grant: keep the group small and review it regularly.
Developer Configuration image with Microsoft 365 Apps (GA)
Microsoft previewed a developer-optimized Windows 11 image in June. The GA version comes with Microsoft 365 Apps preinstalled, along with development tools and configurations. It's available for Windows 365 Enterprise and Flex Dedicated mode. Test it against your actual toolchain before you replace your custom image.
Multiple Flex Dedicated Cloud PCs per user (GA)
Admins can assign several Windows 365 Flex Dedicated Cloud PCs to one user, with the same or different configurations. That covers separate projects or security boundaries.
Microsoft's Windows 365 service description explains the licensing. In Flex Dedicated mode, each license supports up to three Cloud PCs, but only one can be active at a time per license. Having several environments assigned doesn't mean you can run them all at once without more licenses.
Summary: Admin Insights and the developer image are low-risk to adopt. Local admin needs a governance plan before you use it.
Azure Virtual Desktop Hybrid reaches GA
This is the biggest structural change in the recap, and Microsoft actually announced it before the roundup. Microsoft's AVD blog announced GA on September 1, 2026. The service runs session hosts in your own datacenter, on your own hypervisor, using Azure Arc, while the AVD control plane stays in Azure. All communication is outbound over HTTPS, reducing network complexity and eliminating the need for inbound connectivity. According to Microsoft's AVD "What's new" page, Azure Arc connects the session hosts to Azure, and the Azure Virtual Desktop Arc extension installs the required components and registers the device with a host pool.
The recap leaves out some limits that other sources cover:
- Microsoft's AVD pricing page says AVD Hybrid does not support Windows 11 multisession.
- InfoQ reported that the Hybrid service license was unpriced at launch and that Windows Server support requires RDS CALs with Software Assurance, and multi-session Windows is not supported at all.
- Microsoft describes a per-user pricing model that requires OS user entitlement licensing, and compute, storage and networking costs stay with you.
The pitch is that you can modernize without new hardware or a new hypervisor. If your current VDI estate relies on pooled multisession desktops, though, check that limit before anything else.
Partner news
These are partner products, not Microsoft features:
- Hydra by Login VSI manages AVD across Azure and on-premises Hyper-V. It covers image management, session host lifecycle automation and monitoring.
- Nerdio Manager for Enterprise adds AVD Hybrid support on Nutanix AHV.
- Nutanix AHV now supports on-premises AVD Hybrid session hosts using the AVD cloud control plane.
- Nerdio Compass (Public Preview) is a VDI assessment tool for planning a move to Windows 365 or AVD.
Documentation updates
Microsoft also published two pieces of guidance:
- Cloud-native, Zero Trust deployment guidance for Windows 365: recommended choices for identity, networking, images, updates, management, user data and clients, collected into one blueprint.
- A companion article on operational benefits: Microsoft says cloud-native deployments lead to fewer issues, more problems solved by admins themselves, and faster support cases. No independently measured results were provided, so treat those as Microsoft's claims.
The bottom line
September has something for most Cloud PC administrators:
- Government tenants get Cloud PC recovery and better connectivity.
- Mac users get beta resilience improvements.
- Security teams get Display Protection, a meaningful anti-capture control that only works on physical Windows 11 endpoints for now.
- Datacenter holdouts get AVD Hybrid as a supported path, with the multisession limit noted above.
My advice, from long experience: start with the GA items (Reserve self-provisioning, consolidated disaster recovery settings, Admin Insights). Pilot the previews with a small group. Check regional host pools against the live portal before you design around them. A monthly recap is helpful, but your tenant's actual rollout status is what counts.
References
- What’s new in Windows 365: September 2026 recap Windows IT Pro Blog · Thu, 01 Oct 2026 22:06:10 GMT
- Azure Virtual Desktop Hybrid Reaches GA with Licensing Details Unpublished - InfoQ infoq.com
- Azure Virtual Desktop Pricing azure.microsoft.com